What Article 28 Contracts Must Contain

A signed data processing agreement proves very little on its own. The European Data Protection Board has said as much in terms nobody could misread. The processing agreement should not merely restate the provisions of the GDPR. It should instead give specific, concrete information on how the requirements will be met, and on the level of security the processing needs.

So the template that reproduces the eight subparagraphs of Article 28(3) and adds nothing is the template that fails.

What the contract has to set out

The EDPB guidelines on controller and processor work through the required content one subparagraph at a time. The processor processes only on documented instructions. Anyone authorised to process commits to confidentiality or falls under a statutory confidentiality duty. The processor takes the measures required by Article 32. It respects the conditions on engaging another processor.

Then four more. It assists the controller in responding to data subject rights requests. It assists with the obligations in Articles 32 to 36. On termination it deletes or returns the data at the controller’s choice, and deletes existing copies. It makes available the information needed to demonstrate compliance, and allows for and contributes to audits and inspections.

Form, and why the absence of a contract is itself a breach

The legal act has to be in writing, including in electronic form. Non-written arrangements do not meet Article 28, however thorough they are in practice. The EDPB recommends including signatures so the contract’s existence can be shown later.

Where no contract exists at all, that absence is itself an infringement. Both parties carry the duty to ensure one is in place, and a supervisory authority can fine either. Contracts predating the GDPR that were never updated infringe Article 28(3) for the same reason.

What happens before Article 28 applies

Article 28(1) comes first and gets skipped constantly. A controller may use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. That assessment happens before signature, not during it.

The guidelines describe what the controller weighs: the processor’s expert knowledge, its reliability and its resources, with market reputation as a further factor. In practice this means an exchange of documents. The EDPB names examples: the record of processing activities, the information security policy, external audit reports, and recognised certifications such as the ISO 27000 series.

The obligation does not stop at signature

Here is the detail candidates miss. The duty to use only processors providing sufficient guarantees is continuous. It does not end when the parties conclude the contract. The controller should verify the guarantees at appropriate intervals, including through audits and inspections where those are appropriate.

So the sequence runs: assess the guarantees, settle the binding instrument, then keep collecting evidence. Reversing the first two steps is a common design error, because a signed contract with an unassessed processor satisfies neither Article 28(1) nor accountability.

Where negotiating power does not help

A small controller signing a large provider’s standard terms often assumes the imbalance excuses the outcome. The EDPB rejects that directly. A weaker bargaining position is no justification for accepting clauses that fall short of data protection law, and it does not discharge the controller from its own obligations. Accept the terms, use the service, and you have accepted full responsibility for compliance.

The guidelines add a practical point about drafting. The Article 28 elements often sit inside a broader contract such as a service level agreement. Put them somewhere clearly identifiable, an annex for instance, so compliance can be shown without reading the whole document. Any change the processor proposes to standard processing terms has to reach the controller directly. Publishing the change on the processor’s website does not comply.

Article 28 in the CIPP/E exam

The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Vendor management and sharing with third parties sit in Domain II, alongside security of processing.

Ordering questions dominate this material. Guarantees, then instrument, then evidence, and a distractor that puts the contract first will look reasonable until you check it. A second trap treats a processor that starts setting its own purposes as still a processor. It becomes a controller for that processing and can be sanctioned for it. Our piece on Article 49 derogations covers the transfer question behind sub-processor chains. The recent piece on BYOD and the GDPR reaches the same vendor problem through a device.

Sequence questions reward drilling rather than reading. The CIPP/E Exam Question Masterclass at €195 spends its time on exactly that kind of item.

Similar Posts