Back to the hub

GDPR Article 28: what must a data processing agreement contain?

Article 28 governs controllers and their processors. You may use only processors that give sufficient guarantees, and the processing must run under a written data processing agreement. That contract has to include the specific terms Article 28(3) lists, from documented instructions and confidentiality through to deletion of data and audit rights.

Applies to: Any controller that engages a processor, such as a SaaS vendor, and any processor that handles personal data on a controller's behalf.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Almost every SaaS company is on both sides of Article 28: you are a processor for your customers, and a controller when you use vendors such as hosting, email, analytics, or payment providers. The article sets the rules for that relationship, and the centre of it is a written contract, usually called a data processing agreement. Signing one is not a formality. Using a processor without a compliant agreement is itself a breach.

When Article 28 applies

Article 28 applies wherever a processor handles personal data on behalf of a controller. Two duties sit at the front. First, under Article 28(1), a controller may use only processors that provide sufficient guarantees of appropriate technical and organisational measures, which means you have to assess a vendor's security posture before you hand over data. Second, the processing must be governed by a binding written contract that sets out the subject matter and duration, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller.

What the data processing agreement must say

Article 28(3) then lists the specific terms the contract has to contain. The processor must process only on the controller's documented instructions; ensure the people it authorises to process are under a duty of confidentiality; take the security measures required by Article 32; respect the conditions for engaging sub-processors; assist the controller in responding to data subject rights requests; assist with security, breach notification, and data protection impact assessments; delete or return all personal data at the end of the service; and make available the information needed to demonstrate compliance, allowing for and contributing to audits. A DPA that is missing any of these terms is not compliant.

Sub-processors and audits

Two clauses cause the most friction in practice. Sub-processing under Article 28(2) and (4) requires the controller's prior authorisation, whether specific or general, and the sub-processor must be bound to the same data protection obligations. Audit rights under Article 28(3)(h) mean the processor must let the controller verify compliance, which many vendors satisfy with a security report rather than an on-site audit. For where these duties sit among your other obligations, see the GDPR compliance hub.

Next step

If you are not sure whether your vendor contracts carry the Article 28(3) terms, run the free 2-minute Obligation Scan. It flags where a data processing agreement is missing or thin, so you can close the gap before a customer's security review or a regulator asks to see it.

Compliance checklist

  • Identify every vendor that processes personal data on your behalf (Article 28(1)).
  • Check they offer sufficient guarantees of appropriate technical and organisational measures before you engage them.
  • Put a written data processing agreement in place that carries the Article 28(3) terms.
  • Confirm how sub-processors are authorised and bound to equivalent terms (Article 28(2) and (4)).
  • Check the exit terms: data is deleted or returned at the end, and audit and information rights are included.

Sources

Last verified: 2026-07-23

Informational, not legal advice.