Skip to main content
Category: Controller & Processor Roles

Article 28 Contract

Also known as: Article 28 Processor Contract, Data Processing Agreement, DPA, Controller-Processor Contract, Data Processing Contract
Simply put

An Article 28 contract is a written agreement that a data controller puts in place with a processor that handles personal data on the controller's behalf. It sets out how the processor must handle that data and includes protections such as keeping the data confidential. It is generally required whenever an organisation outsources a processing activity to another party.

Formal definition

An Article 28 contract is the legally binding contract or other legal act, required under Article 28 of the GDPR (and the UK GDPR), that governs processing carried out by a processor on behalf of a controller. The controller must use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures, and the arrangement must be governed by a contract binding on the processor with regard to the controller. Article 28(3) prescribes the minimum provisions that must be included; for example, Article 28(3)(b) requires that persons authorised to process the personal data have committed to confidentiality. Practitioners should note that this instrument is distinct from other GDPR mechanisms (such as a Data Protection Impact Assessment under Article 35 or cross-border transfer tools), and that under the UK GDPR the contract may be governed by domestic law. Readers should verify the precise wording and full list of mandatory clauses against the current official text of Article 28, as national implementing law and regulator guidance may address certain details.

Why it matters

The Article 28 contract is a core accountability mechanism in the controller-processor relationship. Whenever an organisation outsources a processing activity to another party that will handle personal data on its behalf, the GDPR generally requires this arrangement to be governed by a binding contract or other legal act. Without it, the controller has no documented legal footing to demonstrate that its processor is bound to appropriate obligations, and the outsourcing arrangement itself may fall short of the Regulation's requirements.

The instrument matters because it operationalises the controller's duty to use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures. Article 28(3) prescribes the provisions that must, at a minimum, be included; for example, the contract must require that persons authorised to process the personal data have committed to confidentiality. These mandatory terms translate the controller's high-level accountability obligations into enforceable commitments the processor owes to the controller.

Practitioners should treat the Article 28 contract as distinct from other GDPR mechanisms it is sometimes confused with, such as a Data Protection Impact Assessment under Article 35 or cross-border transfer tools. Getting the instrument right is therefore both a compliance requirement and a governance safeguard, but the precise wording and full list of mandatory clauses should always be verified against the current official text, as national implementing law and regulator guidance may address certain details differently.

Who it's relevant to

Data controllers outsourcing processing
Organisations that engage a third party to process personal data on their behalf are generally required to put an Article 28 contract in place. Controllers must select only processors that provide sufficient guarantees regarding appropriate technical and organisational measures, and ensure the arrangement reflects the provisions prescribed by Article 28(3).
Processors
Parties that handle personal data on behalf of a controller are bound by the contract with regard to the controller. Processors should understand the confidentiality and other commitments Article 28(3) requires, including the obligation that authorised persons commit to confidentiality under Article 28(3)(b).
Data protection officers and compliance leads
Those responsible for accountability and governance rely on Article 28 contracts as documented evidence that outsourced processing is governed appropriately. They should verify that each contract contains the minimum provisions required and should distinguish this instrument from other GDPR mechanisms such as DPIAs or transfer tools.
Legal and contracting teams
Lawyers drafting or reviewing processor arrangements should map contract terms against the current official text of Article 28 and account for the position under the UK GDPR, where the contract may be governed by domestic law. They should also monitor relevant regulator guidance and national implementing law, which may address certain details.

Inside Article 28 Contract

Subject-matter, duration, nature and purpose of processing
A written description of what the processing involves, how long it will last, its nature (the operations performed) and its purpose, so that the processor's role is clearly bounded by the controller's instructions.
Type of personal data and categories of data subjects
Identification of the personal data being processed and the individuals to whom it relates, which frames the scope of the engagement and any special category data considerations that may require an additional Article 9 condition.
Obligations and rights of the controller
A statement of the controller's role, including that the processor acts on the controller's documented instructions, typically as required under GDPR provisions governing controller-processor relationships.
Processing only on documented instructions
A commitment that the processor processes personal data only on the controller's documented instructions, including in relation to transfers to third countries, unless required to do so by applicable law.
Confidentiality of authorised personnel
An obligation ensuring that persons authorised to process the personal data are bound by confidentiality or are under an appropriate statutory obligation of confidentiality.
Security measures
A requirement that the processor implement appropriate technical and organisational measures to secure the personal data, assessed against the risk of the processing rather than a fixed checklist.
Sub-processor conditions
Terms addressing the engagement of sub-processors, generally requiring the controller's prior authorisation (specific or general) and the flow-down of equivalent data protection obligations to any sub-processor.
Assistance with data subject rights
An obligation on the processor to assist the controller, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights.
Assistance with controller compliance obligations
Support for the controller's obligations relating to security, breach notification, and where relevant data protection impact assessments and prior consultation, taking into account the information available to the processor.
Return or deletion of data
A term requiring the processor, at the controller's choice, to delete or return the personal data at the end of the provision of services, and to delete existing copies unless retention is required by applicable law.
Audit and information rights
An obligation on the processor to make available information necessary to demonstrate compliance and to allow for and contribute to audits, including inspections, conducted by the controller or a mandated auditor.

Common questions

Answers to the questions practitioners most commonly ask about Article 28 Contract.

Does having an Article 28 contract in place mean the controller has transferred its compliance responsibilities to the processor?
No. An Article 28 contract governs the relationship between a controller and a processor, but it does not transfer or discharge the controller's own accountability under the GDPR. The controller generally remains responsible for determining the purposes and means of processing and for ensuring the processing is lawful, while the processor takes on its own direct obligations. The contract allocates duties between the parties rather than shifting overarching responsibility away from the controller.
Is an Article 28 contract the same thing as, or a substitute for, a transfer mechanism such as Standard Contractual Clauses?
No, these address different issues and should not be conflated. An Article 28 contract (a data processing agreement) sets out the required terms governing processing carried out by a processor on behalf of a controller. A transfer tool such as Standard Contractual Clauses addresses the separate question of transfers of personal data to third countries. Where processing involves both a controller-processor relationship and an international transfer, both instruments may be needed; one generally does not replace the other. The applicable transfer tools and any supplementary measures can evolve, so the reader should verify the current position.
What terms does Article 28 generally require to be included in the contract?
Article 28 sets out a list of mandatory contractual terms governing processing by a processor. These generally include that the processor acts only on documented instructions from the controller, ensures confidentiality of personnel authorised to process the data, implements appropriate security measures, respects conditions for engaging sub-processors, assists the controller with data subject rights and with certain compliance obligations, deletes or returns the data at the end of the service, and makes available information to demonstrate compliance and allow audits. You should verify the precise wording against the current official text, as the exact formulation controls.
How should the contract handle the engagement of sub-processors?
Under Article 28, a processor generally may not engage another processor without prior authorisation from the controller, which may be specific or general. Where general authorisation is used, the processor is typically required to inform the controller of intended changes so the controller has an opportunity to object. The contract should also ensure that the same data protection obligations are imposed on sub-processors, and the processor generally remains liable to the controller for the sub-processor's performance. Practices around the notice and objection process can vary, so the mechanism should be set out clearly in the agreement.
Who is responsible for drafting the Article 28 contract, and can standard clauses be used?
Either party may propose or draft the terms; the Regulation specifies the required content but does not mandate who prepares the document. The obligation to have a compliant contract in place applies to both controller and processor. The GDPR also contemplates the use of standard contractual clauses adopted for this purpose, and processors commonly present their own template data processing agreements. Whichever route is used, the parties should confirm the terms meet the mandatory requirements and reflect the actual processing, rather than assuming a template is complete for their specific arrangement.
What audit and demonstration-of-compliance obligations typically arise from an Article 28 contract, and how are they implemented in practice?
Article 28 generally requires the processor to make available to the controller the information needed to demonstrate compliance with these obligations and to allow for and contribute to audits, including inspections. In practice, parties often address how this is operationalised in the contract, for example through the scope, frequency, and notice period for audits, the use of third-party audits or certifications, and confidentiality and cost arrangements. The specifics are subject to negotiation and assessment of the risk involved, and the contractual mechanism should not undercut the underlying obligation to enable the controller to verify compliance.

Common misconceptions

An Article 28 contract and a Data Protection Impact Assessment serve the same purpose.
They are distinct instruments. An Article 28 contract governs the controller-processor relationship and sets out required processing terms, whereas a Data Protection Impact Assessment (Article 35) is a risk assessment carried out for processing likely to result in a high risk to individuals. A processing contract may reference or support DPIA obligations, but it does not replace the assessment.
Signing an Article 28 contract makes the arrangement fully compliant.
The contract is a necessary component but not a guarantee of compliance. The parties must still identify an appropriate Article 6 legal basis (and an additional Article 9 condition for special category data), implement the security measures in practice, and manage international transfers with appropriate tools. Compliance is context and risk dependent, and the written terms must be reflected in actual operations.
An Article 28 contract by itself authorises transfers of personal data outside the EU.
A processing contract addresses the controller-processor relationship but is generally not a standalone transfer mechanism. Cross-border transfers typically require a separate lawful transfer tool, such as an adequacy decision or Standard Contractual Clauses, potentially with supplementary measures. Transfer mechanisms and adequacy positions evolve, so the current official text and guidance should be verified.

Best practices

Map each required element (instructions, confidentiality, security, sub-processors, assistance with data subject rights, breach and DPIA support, return or deletion, and audit rights) against your contract to confirm none is missing or diluted.
Specify the subject-matter, duration, nature, purpose, data types and categories of data subjects with enough particularity to bound the processor's permitted activities, rather than relying on generic boilerplate.
Define the sub-processor authorisation approach clearly, stating whether authorisation is specific or general, how changes are notified, how objections are handled, and how equivalent obligations flow down.
Treat the security clause as requiring measures appropriate to the risk, and align it with what the processor actually implements rather than an aspirational description.
Handle international transfers through a separate, current transfer mechanism where relevant, and review it periodically because adequacy decisions and transfer tools change over time.
Verify article references, national implementing variations and any regulator-specific expectations against the current official text and guidance before finalising, since member state derogations and divergence between EU and UK positions can affect the drafting.