Documented Instructions
Documented instructions are the recorded directions a controller gives to a processor about how personal data may be handled on its behalf. Under the GDPR, a processor is generally expected to act only on these instructions, rather than deciding independently how to use the data. This helps ensure the controller, who determines the purposes of processing, retains control over what happens to the personal data.
Documented instructions are the recorded parameters set by a controller that govern a processor's handling of personal data on the controller's behalf. Article 28 GDPR requires, as a core element of the controller-processor arrangement, that the processor processes personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country (subject to any legal obligation exception). The requirement is typically operationalised through the processing terms in a Data Processing Agreement or equivalent binding instrument under Article 28, and the instructions ordinarily specify the subject matter, scope, and permitted operations of the processing. The precise form, level of detail, and permissible scope of such instructions are not exhaustively prescribed by the Regulation text and may be informed by regulatory guidance and national implementing law; readers should verify specific requirements against the current official text of Article 28 GDPR and applicable guidance.
Why it matters
Documented instructions are the mechanism through which a controller preserves accountability when it engages a processor to handle personal data on its behalf. Because the controller determines the purposes and means of processing, it needs a clear, recorded record of what the processor is permitted to do. Without documented instructions, the line between controller and processor can blur, and a processor that starts making independent decisions about the data may itself take on controller obligations for that processing.
The requirement also matters for transparency and enforceability. Article 28 GDPR frames processing on documented instructions as a core element of the controller-processor arrangement, including with regard to transfers of personal data to a third country, subject to any applicable legal obligation exception. Reducing instructions to a recorded form gives both parties, and potentially a supervisory authority, a reference point against which actual processing activity can be assessed. This supports the broader accountability principle by making it possible to demonstrate that data was handled within agreed parameters.
The precise form, level of detail, and permissible scope of instructions are not exhaustively prescribed by the Regulation text and may be informed by regulatory guidance and national implementing law. Organisations should therefore treat documented instructions as a living element of their compliance program rather than a one-off document, and verify specific requirements against the current official text of Article 28 GDPR and applicable guidance.
Who it's relevant to
Inside Documented Instructions
Common questions
Answers to the questions practitioners most commonly ask about Documented Instructions.