Article 28 Contract
An Article 28 contract is a written agreement that a data controller puts in place with a processor that handles personal data on the controller's behalf. It sets out how the processor must handle that data and includes protections such as keeping the data confidential. It is generally required whenever an organisation outsources a processing activity to another party.
An Article 28 contract is the legally binding contract or other legal act, required under Article 28 of the GDPR (and the UK GDPR), that governs processing carried out by a processor on behalf of a controller. The controller must use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures, and the arrangement must be governed by a contract binding on the processor with regard to the controller. Article 28(3) prescribes the minimum provisions that must be included; for example, Article 28(3)(b) requires that persons authorised to process the personal data have committed to confidentiality. Practitioners should note that this instrument is distinct from other GDPR mechanisms (such as a Data Protection Impact Assessment under Article 35 or cross-border transfer tools), and that under the UK GDPR the contract may be governed by domestic law. Readers should verify the precise wording and full list of mandatory clauses against the current official text of Article 28, as national implementing law and regulator guidance may address certain details.
Why it matters
The Article 28 contract is a core accountability mechanism in the controller-processor relationship. Whenever an organisation outsources a processing activity to another party that will handle personal data on its behalf, the GDPR generally requires this arrangement to be governed by a binding contract or other legal act. Without it, the controller has no documented legal footing to demonstrate that its processor is bound to appropriate obligations, and the outsourcing arrangement itself may fall short of the Regulation's requirements.
The instrument matters because it operationalises the controller's duty to use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures. Article 28(3) prescribes the provisions that must, at a minimum, be included; for example, the contract must require that persons authorised to process the personal data have committed to confidentiality. These mandatory terms translate the controller's high-level accountability obligations into enforceable commitments the processor owes to the controller.
Practitioners should treat the Article 28 contract as distinct from other GDPR mechanisms it is sometimes confused with, such as a Data Protection Impact Assessment under Article 35 or cross-border transfer tools. Getting the instrument right is therefore both a compliance requirement and a governance safeguard, but the precise wording and full list of mandatory clauses should always be verified against the current official text, as national implementing law and regulator guidance may address certain details differently.
Who it's relevant to
Inside Article 28 Contract
Common questions
Answers to the questions practitioners most commonly ask about Article 28 Contract.