Skip to main content
Processor Contracts That Actually Protect YouSecurity & Breach Notification
5 min readFor Data Protection Officers (DPOs)

Processor Contracts That Actually Protect You

When a third-party provider gets breached, you're still accountable under Article 28. Here's what your due diligence process should look like before you sign, and what you should audit after.

Scope

This guide covers your obligations when engaging processors under GDPR Article 28, focusing on:

  • Pre-contract security assessments
  • Required contractual protections
  • Ongoing oversight mechanisms
  • Personal data breach response coordination

You'll need this framework whether you're onboarding a new IT service provider, renewing existing agreements, or responding to a processor-side incident.

Key Concepts and Definitions

Processor: Any entity that processes personal data on your behalf under your instructions. IT service providers, cloud platforms, payroll administrators, and marketing automation vendors typically fall into this category.

Article 28 contract: The written agreement required between you and the processor that specifies processing instructions, security obligations, and breach notification procedures. Email exchanges and purchase orders don't satisfy this requirement.

Sub-processor: A processor engaged by your primary processor. You must either approve each sub-processor individually or establish general written authorization with an opportunity to object.

Personal data breach: A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. The breach at Lidl's IT provider fits this definition, even though the online shop system itself wasn't compromised.

Requirements Breakdown

Article 28(1): Processor Selection

You must use only processors that provide sufficient guarantees to implement appropriate technical and organizational measures. Although "sufficient guarantees" isn't defined in the regulation, supervisory authorities expect documented evidence that you evaluated:

  • The processor's security certifications (ISO 27001, SOC 2, or equivalent)
  • Their track record with similar data types
  • Their breach notification procedures
  • Their sub-processor management practices

Document your assessment. If your processor later suffers a breach, your supervisory authority will ask what due diligence you performed before engagement.

Article 28(3): Mandatory Contract Terms

Your processor contract must specify at minimum:

  • Subject matter and duration: What data gets processed, for what purpose, and how long
  • Nature and purpose: The business function the processing supports
  • Type of personal data: Names, contact details, purchase history, etc.
  • Categories of data subjects: Customers, employees, website visitors
  • Controller obligations and rights: Your instructions, audit rights, and termination procedures

The contract must also require the processor to:

  • Process only on documented instructions (Article 28(3)(a))
  • Ensure processing staff are under confidentiality obligations (Article 28(3)(b))
  • Implement appropriate technical and organizational measures per Article 32 (Article 28(3)(c))
  • Respect sub-processor conditions (Article 28(3)(d))
  • Assist with DSARs and other data subject rights (Article 28(3)(e))
  • Assist with your Article 32-35 obligations (breach response, impact assessments) (Article 28(3)(f))
  • Delete or return data at contract end (Article 28(3)(g))
  • Provide information demonstrating compliance and allow audits (Article 28(3)(h))

Article 33(2): Processor Breach Notification

Your processor must notify you "without undue delay" after becoming aware of a personal data breach. "Without undue delay" typically means within hours, not days. Lidl's IT provider reportedly "reacted immediately," but you need contractual clarity on notification timelines because your own 72-hour clock to notify your supervisory authority starts when you become aware of the breach.

Implementation Guidance

Before Contract Signature

Request a completed security questionnaire. Use standard frameworks like the Consensus Assessments Initiative Questionnaire (CAIQ) or your own template covering:

  • Data encryption (at rest and in transit)
  • Access controls and authentication
  • Logging and monitoring capabilities
  • Incident response procedures
  • Business continuity planning
  • Sub-processor vetting process

Review their standard contract against Article 28(3). Most SaaS providers offer standard data processing agreements, but they're not all compliant. You may need to negotiate additional terms.

Establish breach notification procedures. Specify the notification method (email to specific addresses, phone call, ticketing system), required content (affected data categories, approximate numbers, containment measures), and timeline. Don't accept "as soon as reasonably practicable", define it.

During the Relationship

Track sub-processor changes. If you've granted general authorization, your processor must inform you of additions or replacements with enough time to object. Set up a notification email address and calendar reminders to review quarterly.

Conduct periodic audits. Article 28(3)(h) gives you audit rights. Exercise them. Annual questionnaires for low-risk processors, on-site assessments for high-risk ones. Document everything.

Test breach notification. Run a tabletop exercise annually where your processor simulates a breach notification. Time how long it takes to escalate internally and confirm you'd meet your 72-hour window.

After a Breach

When your processor notifies you of a personal data breach:

  1. Assess notification obligations within hours. Article 33 requires you to notify your supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in a risk to rights and freedoms.

  2. Determine communication obligations. Article 34 requires direct communication to affected data subjects if the breach is likely to result in a high risk. Lidl warned customers in Germany, Belgium, and the Netherlands about potential phishing attempts, which aligns with this obligation.

  3. Document the breach. Article 33(5) requires you to document all personal data breaches, including facts, effects, and remedial action. Your processor's forensics report becomes part of your documentation.

  4. Review the processor relationship. A breach doesn't automatically mean you must terminate, but it should trigger a security reassessment. What failed? What's been fixed? Do you need additional contractual protections?

Common Pitfalls

Accepting "commercially reasonable" security. This phrase appears in many standard contracts but doesn't satisfy Article 28(3)(c). You need specific commitments to encryption, access controls, and monitoring.

Skipping sub-processor review. Your processor's sub-processors are your problem too. If a cloud provider's backup processor gets breached, you're still the controller facing notification obligations.

Treating breach notification as optional. Some processors bury breach notification in general "incident management" clauses without specific timelines. That won't work when you're counting hours to meet Article 33 deadlines.

Assuming certifications equal compliance. ISO 27001 and SOC 2 are useful signals, but they don't prove your processor will handle your specific data types appropriately. Review the scope of certification and ask about gaps.

Neglecting contract renewal. GDPR came into force in 2018. If you're still operating under pre-GDPR contracts with processors, those agreements likely don't include Article 28(3) terms. Renewal time is your opportunity to fix that.

Quick Reference Table

Requirement Article Your Action Timing
Processor provides sufficient guarantees 28(1) Document security assessment Pre-contract
Written contract with mandatory terms 28(3) Review and negotiate supervisory authority Pre-contract
Sub-processor authorization 28(2), 28(4) Approve list or establish objection process Pre-contract
Processor notifies you of breach 33(2) Specify notification method and timeline in contract Pre-contract
You notify supervisory authority 33(1) Assess and report within 72 hours of awareness Post-breach
You notify data subjects 34(1) Assess high risk and communicate directly Post-breach
Audit processor compliance 28(3)(h) Conduct questionnaires or on-site assessments Annual minimum
Document all breaches 33(5) Maintain breach register with processor incidents Ongoing

Your processor's security posture directly affects your compliance posture. The contract is your primary control mechanism. Make it specific, enforceable, and ensure you exercise your audit rights before a breach forces the question.

You Might Also Like