Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 28 (Processor & DPA)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Reference Binding Legal Text (Art. 28)

Article 28 GDPR: Data Processing Agreement & Mandatory Clauses

Official EU Regulation (EU) 2016/679 legal analysis

⚡ In 30 seconds:

Under the GDPR, a data processor processes personal data on behalf of and under documented instructions from the controller. Engaging any processor legally requires a written Data Processing Agreement (DPA) fulfilling Article 28(3).

Operational Checklist of Mandatory DPA Clauses (Art. 28.3 GDPR)

The Data Processing Agreement (DPA) or equivalent legal act must be in writing (including electronic format) and be legally binding on the processor with regard to the controller. In accordance with Article 28(3) GDPR and EDPB Guidelines 07/2020, the contract must stipulate the following core terms:

  • Contractual framework (Art. 28.3 intro): Specify the subject-matter, duration, nature and purpose of processing, type of personal data, categories of data subjects, and the obligations and rights of the controller.
  • 1. Documented instructions (Art. 28.3.a): Process data only on documented instructions from the controller (including international transfers), unless required to do so by EU or Member State law.
  • 2. Staff confidentiality (Art. 28.3.b): Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation.
  • 3. Security measures (Art. 28.3.c & Art. 32): Take all technical and organisational measures necessary to ensure a level of security appropriate to the risk.
  • 4. Sub-processors (Art. 28.3.d): Adhere strictly to prior written authorization requirements (specific or general) and flow down identical mirror obligations into sub-processor contracts.
  • 5. Assisting with data subject rights (Art. 28.3.e): Assist the controller by appropriate technical and organisational measures in fulfilling the obligation to respond to requests for exercising data subject rights (Chapter III).
  • 6. Assisting with security, breach notification & DPIAs (Art. 28.3.f): Assist the controller with security compliance, notifying data breaches without undue delay (Art. 33.2), communication to data subjects, and DPIAs (Articles 35-36).
  • 7. Deletion or return of data (Art. 28.3.g): At the choice of the controller, delete or return all personal data upon end of provision of services, unless storage is required by law.
  • 8. Audits and immediate alert duty (Art. 28.3.h): Make available all information necessary to demonstrate compliance, allow for and contribute to audits/inspections, and immediately inform the controller if an instruction infringes EU or national data protection law.

Sufficient Guarantees & Sub-Processing (Art. 28.1 & 28.2)

Controllers must only use processors providing « sufficient guarantees » to implement appropriate technical and organisational measures. If a processor determines purposes or means independently outside controller instructions, it becomes a controller de facto under Article 28(10).

The European Commission's Standard Contractual Clauses (Decision EU 2021/915) offer an official non-mandatory template model for Article 28 compliance.

Verified Official Sources

⚖️ Binding EU Legal Act
Regulation (EU) 2016/679 (Official Journal of the European Union, EUR-Lex EN)

CELEX: 32016R0679 · Official English consolidated version

← ← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-31 Last modified: 2026-08-31

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice