Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Synthesis: Contractual Compliance & Lawfulness Checklist
Courses Guides Blog Resources News
Français English Nederlands
Fiche 30/54 Part 3 — Lawfulness & Key Actors Advanced Reviewed 2026-08-23

Synthesis: Contractual Compliance & Lawfulness Checklist

True lawful processing requires tripartite alignment: a valid Article 6 legal ground, robust Article 28 data processing agreements with vendors, and Chapter V safeguards for cross-border data flows. T

Open in interactive reader
🧪 Operational Checklist ⚖️ Tripartite Compliance Gate

Contractual Compliance & Lawfulness Checklist

⚡ In 30 seconden

Compliance cannot be established piecemeal. A processing pipeline is lawful only when all three contractual tiers are concurrently secured: Tier 1: Documented Article 6 ground → Tier 2: Executed Article 28 DPA → Tier 3: Valid Chapter V Transfer Mechanism (if external to the EEA).

Compliance Tier Verification Checkpoint Required Tangible Artifact
Tier 1: Upstream Lawfulness Is there an explicit Article 6 legal ground documented before collection? Article 30 register entry; recorded consent timestamp or written LIA balancing test.
Tier 2: Processor Chain Are all external vendors bound by signed Article 28(3) Data Processing Agreements? Countersigned DPA including all 10 statutory clauses and sub-processor authorization rules.
Tier 3: International Nexus Are servers and support desks located in the EEA or covered by SCCs/Adequacy? Transfer Impact Assessment (TIA); executed Standard Contractual Clauses (Decision 2021/914).
⚡ Key Takeaways
  • Contractual non-compliance breaks the chain of accountability across the entire processing chain.
  • Processors must maintain identical contractual pass-through terms with sub-processors.
  • Annual vendor audit reviews are required to preserve ongoing accountability.
⚠️ Common Pitfall

Assuming that purchasing a enterprise software license automatically includes a valid GDPR Article 28 DPA without executing the data protection addendum.

🛠️ In Practice

Incorporate this 3-tier validation checklist into standard corporate IT procurement procedures.

⚖️ Official Sources: Articles 6, 26, 28, 44–50 GDPR · EDPB Accountability Verification Framework ✓ Legal review: 23 August 2026

✓ Key takeaways

  • A documented legal ground justifies the existence of the processing at inception.
  • Article 26 and Article 28 agreements govern intra-European data circulation with partners.
  • Transfer instruments (SCCs, adequacy decisions) secure data flows extending beyond the EU.

⚠ Common pitfall: Having a rock-solid legal basis while neglecting to sign Article 28 DPAs with SaaS providers, rendering the entire processing operation unlawful.

→ Actionable practice: Systematically run through this tripartite checklist prior to onboarding any new software, cloud host, or marketing tool.

← Supervisory Authorities, One-Stop-Shop & EDPB (Art. 51–76) General Modalities for the Exercise of Rights (Art. 12) →