Skip to main content
Category: Controller & Processor Roles

Documented Instructions

Simply put

Documented instructions are the recorded directions a controller gives to a processor about how personal data may be handled on its behalf. Under the GDPR, a processor is generally expected to act only on these instructions, rather than deciding independently how to use the data. This helps ensure the controller, who determines the purposes of processing, retains control over what happens to the personal data.

Formal definition

Documented instructions are the recorded parameters set by a controller that govern a processor's handling of personal data on the controller's behalf. Article 28 GDPR requires, as a core element of the controller-processor arrangement, that the processor processes personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country (subject to any legal obligation exception). The requirement is typically operationalised through the processing terms in a Data Processing Agreement or equivalent binding instrument under Article 28, and the instructions ordinarily specify the subject matter, scope, and permitted operations of the processing. The precise form, level of detail, and permissible scope of such instructions are not exhaustively prescribed by the Regulation text and may be informed by regulatory guidance and national implementing law; readers should verify specific requirements against the current official text of Article 28 GDPR and applicable guidance.

Why it matters

Documented instructions are the mechanism through which a controller preserves accountability when it engages a processor to handle personal data on its behalf. Because the controller determines the purposes and means of processing, it needs a clear, recorded record of what the processor is permitted to do. Without documented instructions, the line between controller and processor can blur, and a processor that starts making independent decisions about the data may itself take on controller obligations for that processing.

The requirement also matters for transparency and enforceability. Article 28 GDPR frames processing on documented instructions as a core element of the controller-processor arrangement, including with regard to transfers of personal data to a third country, subject to any applicable legal obligation exception. Reducing instructions to a recorded form gives both parties, and potentially a supervisory authority, a reference point against which actual processing activity can be assessed. This supports the broader accountability principle by making it possible to demonstrate that data was handled within agreed parameters.

The precise form, level of detail, and permissible scope of instructions are not exhaustively prescribed by the Regulation text and may be informed by regulatory guidance and national implementing law. Organisations should therefore treat documented instructions as a living element of their compliance program rather than a one-off document, and verify specific requirements against the current official text of Article 28 GDPR and applicable guidance.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance functions rely on documented instructions to demonstrate that processors are acting within agreed parameters and that the controller retains control over the purposes of processing. They are typically involved in defining the subject matter, scope, and permitted operations recorded in the Article 28 arrangement, and in reviewing them as processing activities evolve.
Privacy and commercial lawyers
Lawyers drafting or negotiating Data Processing Agreements need to ensure the documented instructions are captured in a binding instrument under Article 28 and address the permitted scope of processing, including any transfers of personal data to a third country subject to the legal obligation exception. They should note that the Regulation does not fully prescribe the required detail and verify against current official text and guidance.
Processors and their operational teams
A processor is generally expected to process personal data only on the controller's documented instructions rather than deciding independently how to use the data. Operational teams executing the processing need a clear reference to the recorded instructions so that activities stay within the agreed subject matter, scope, and permitted operations, and so that any legal obligation exception is properly identified.
Controllers determining purposes of processing
Controllers, who determine the purposes of processing, use documented instructions to retain control over what happens to personal data handled on their behalf. Recording instructions supports their accountability by providing a reference point against which a processor's actual handling of the data can be assessed.

Inside Documented Instructions

Subject Matter and Duration of Processing
The instructions should identify what personal data is processed and over what period, aligning the processor's activities with the controller's purposes. This element typically forms part of the wider Article 28 arrangement between controller and processor.
Nature and Purpose of Processing
A description of the operations the processor is authorised to carry out and the reasons for them. The processor generally acts only on these documented instructions and not on its own determined purposes, which would otherwise risk recharacterising it as a controller.
Types of Personal Data and Categories of Data Subjects
Specification of the data involved and whose data it concerns. Where special category data under Article 9 is in scope, the instructions and the underlying processing should reflect that an additional Article 9 condition is required beyond the Article 6 legal basis identified by the controller.
Scope of Authorised Actions
The instructions delimit what the processor may and may not do, including any constraints on onward use, sub-processing, and international transfers. Instructions relating to transfers should be read alongside the applicable transfer mechanisms, which can evolve over time.
Form and Record of Instructions
Instructions are typically set out in writing, commonly within a Data Processing Agreement under Article 28, though they may also be given during the relationship. Maintaining a documented record supports accountability and demonstrability of the arrangement.
Escalation for Unlawful Instructions
A mechanism by which the processor informs the controller if, in the processor's view, an instruction appears to infringe applicable data protection law. This reflects the processor's duty to act on instructions while flagging concerns, subject to assessment of the specific circumstances.

Common questions

Answers to the questions practitioners most commonly ask about Documented Instructions.

Does a processor need documented instructions for every single processing operation, or is a general authorisation enough?
Under Article 28 of the GDPR, a processor generally processes personal data only on documented instructions from the controller. This does not necessarily require a separate instruction for each discrete operation; instructions are typically set out in the processing agreement and its schedules, which describe the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subjects. The key point is that the scope of permitted processing is defined and recorded, so the processor cannot lawfully process outside those parameters without a further instruction. Whether a given level of generality is sufficient is subject to assessment against the specific processing context.
Do documented instructions have to be a single formal contract, or can they take other forms?
The requirement is for instructions to be documented, not for them to sit in one particular type of document. In most cases the core instructions are captured in the Article 28 processing agreement, but instructions can also be recorded and evidenced through other written means, such as schedules, statements of work, configuration settings agreed in writing, or subsequent written communications from the controller. What matters is that the instruction is documented and attributable to the controller, so that both parties and, where relevant, a supervisory authority can identify what the processor was authorised to do. Purely oral instructions with no record would generally be difficult to reconcile with the documentation requirement.
Who is responsible for issuing documented instructions, the controller or the processor?
The controller determines the purposes and means of processing and is therefore the party that gives the instructions; the processor acts on them. In practice a processor often drafts template agreement terms, but the substantive instructions on what processing is authorised should reflect the controller's determination. A processor that goes beyond the controller's documented instructions and starts determining purposes and means for itself may, in respect of that processing, be treated as a controller. Allocation of responsibilities in specific arrangements should be assessed on the facts.
What should a processor do if it believes a controller's instruction infringes data protection law?
Article 28 addresses this situation by providing that the processor should inform the controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions. The Regulation frames this as a notification duty; national implementing law and member state derogations can affect the surrounding position, so the practical steps should be checked against the applicable law. Organisations typically build a written escalation and record-keeping process so that any such concern, and the controller's response, are documented and can be evidenced later.
How should changes to documented instructions be handled during the life of a contract?
Because instructions define the boundaries of what a processor may lawfully do, changes are generally managed through a documented change process rather than informal agreement. This typically means recording new or amended instructions in writing, for example through a change request, an amended schedule, or a formal variation to the processing agreement, so that the current scope of authorised processing remains clear and evidenced. Version control and dating of instructions help both parties demonstrate what was authorised at any given time. The appropriate mechanism should be assessed against the terms of the specific agreement.
How do documented instructions relate to sub-processing and the processor's use of sub-processors?
Instructions from the controller set the parameters within which the processor operates, and any sub-processor engaged by the processor is generally bound, through the onward contract, to equivalent obligations, including acting on the controller's documented instructions as passed down. This means the instruction framework typically needs to flow through the processing chain rather than stopping at the first processor. The precise arrangements for authorising and controlling sub-processors are governed by the relevant provisions of Article 28 and the terms agreed between the parties, and should be verified against the current official text and the specific contract.

Common misconceptions

Documented instructions are the same thing as a Data Processing Agreement.
The documented instructions are one component that typically sits within, and is given effect by, an Article 28 Data Processing Agreement. The Agreement is the broader instrument governing the controller-processor relationship, while the instructions describe the specific processing the processor is authorised to perform. They should not be conflated with a Data Protection Impact Assessment under Article 35, which serves a different purpose.
A processor can rely on documented instructions to justify any processing, including processing on its own initiative.
A processor generally must process only on the controller's documented instructions. If a processor begins determining its own purposes and means, it may be recharacterised as a controller for that activity, with the corresponding obligations. The instructions define, rather than expand, the processor's permitted scope.
Once instructions are documented, the processor must follow them without question.
While the processor generally acts on the controller's instructions, it is typically expected to inform the controller where an instruction appears to infringe applicable data protection law. Following instructions does not, in most cases, relieve the processor of its own responsibilities, and the position may vary depending on the circumstances and applicable national implementing law.

Best practices

Record the instructions in writing, generally within the Article 28 Data Processing Agreement, and keep them current as processing activities change.
Clearly specify the subject matter, duration, nature, purpose, types of personal data, and categories of data subjects so the processor's authorised scope is unambiguous.
Where special category data may be processed, confirm the controller has identified an Article 9 condition in addition to the Article 6 legal basis, and reflect any related constraints in the instructions.
Address sub-processing and international transfers explicitly, and review transfer-related instructions periodically since applicable transfer mechanisms and supplementary measures can evolve.
Include a documented escalation process for the processor to notify the controller of any instruction it considers potentially unlawful, subject to assessment.
Retain records demonstrating that processing is carried out on documented instructions to support accountability, and verify the position against the current official text and any applicable national implementing law.