Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Subcontracting & Data Processing Agreements (Art. 28)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 26/54 Part 3 — Lawfulness & Key Actors Advanced Reviewed 2026-08-23

Subcontracting & Data Processing Agreements (Art. 28)

A data processor acts exclusively on documented instructions from the controller. Article 28 GDPR mandates a legally binding Data Processing Agreement (DPA) containing 10 mandatory statutory clauses.

Open in interactive reader
⚖️ Mandatory Contractual Regime 📋 10 Mandatory Clauses (Art. 28.3)

Subcontracting & Data Processing Agreements (Art. 28)

⚡ In 30 seconds

Under Article 28, processing by a processor must be governed by a binding contract in writing (DPA). The contract sets out the subject-matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, and the specific statutory obligations defined in Article 28(3).

Mandatory Clause (Art. 28.3) Contractual Safeguard Requirement
(a) Documented Instructions Processes personal data solely on documented controller instructions, including on international transfers.
(b) Confidentiality Ensures that persons authorized to process data have committed themselves to statutory or contractual confidentiality.
(c) Security Measures Implements all appropriate technical and organizational measures required under Article 32.
(d) Sub-processor Rules Does not engage another processor without prior specific or general written authorization of the controller.
(e) Assisting Rights Assists the controller by appropriate measures in responding to data subject rights requests (Chapter III).
(f) Assisting Compliance Assists the controller in ensuring compliance with Articles 32 to 36 (security, breach notifications, DPIAs).
(g) Deletion or Return At the choice of controller, deletes or returns all personal data after the end of the provision of services.
(h) Audits & Inspections Makes available all necessary information and allows for audits, including inspections, conducted by controller.
⚡ Key Takeaways
  • Standard terms of service without Article 28 clauses leave both parties non-compliant.
  • Sub-processors must be bound by the same data protection obligations (Art. 28.4).
  • The European Commission has published standard contractual clauses specifically for Article 28.
⚠️ Common Pitfall

Failing to secure audit rights in cloud contracts, which deprives the controller of demonstrable compliance oversight.

🛠️ In Practice

Use the European Commission's standard Article 28 contractual clauses for all vendor onboarding workflows.

⚖️ Official Sources: Art. 28 GDPR · Recital 81 · Commission Implementing Decision (EU) 2021/915 ✓ Legal review: 23 August 2026

✓ Key takeaways

  • A written DPA under Article 28(3) is a strict statutory duty binding controller and processor.
  • A processor that repurposes data for its own commercial ends becomes a de facto controller subject to fines.
  • Controllers must conduct due diligence, engaging only processors providing sufficient guarantees.

⚠ Common pitfall: Omitting the requirement for processors to seek prior written authorization before engaging sub-processors.

→ Actionable practice: Maintain an updated register of all processors and sub-processors with signed DPAs for each processing activity.

← Controller Obligations & Joint Controllership (Art. 24 & 26) International Data Transfers Outside the EU (Chapter V) →