What is a GDPR processor agreement under Article 28?
A GDPR processor agreement is the contract or other legal act, under Union or Member State law, that must govern processing by a processor on behalf of a controller and that must be binding on the processor with regard to the controller. Article 28(3) also requires that act to set out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the controller’s obligations and rights. “DPA” is a common label, not a defined GDPR term. Article 28(1) adds that the controller shall use only processors providing sufficient guarantees. On this trainer’s live catalog, the controller-and-processor chapter currently holds 44 of 379 active questions.
Who is a processor — and who is not?
A processor processes personal data on behalf of the controller (Article 4(8)); a controller determines the purposes and means (Article 4(7)). Status follows the facts of the processing, not the heading on a commercial contract.
| Role | Test | Typical exam trap |
|---|---|---|
| Controller | Article 4(7) | Calling a vendor “processor” while it still decides why the data are used. |
| Processor | Article 4(8) plus Article 28 | Treating a public privacy policy as the binding act. |
| Joint controllers | Article 26 | Using an Article 28 template for joint control — see joint controllers under Article 26. |
| Person under authority | Article 29 | Signing Article 28 with own staff. EDPB Guidelines 07/2020, paragraph 78, treat the controller’s own employees as not processors; Article 29 also covers persons acting under a processor’s authority. |
What must a GDPR processor agreement include?
After those descriptive particulars, Article 28(3) requires the contract to stipulate, in particular, the processor duties in points (a) to (h). Points (d), 28(2) and 28(4) then cover sub-processors.
| Clause | Processor duty in Article 28(3) |
|---|---|
| (a) | Process only on documented instructions, including for transfers, unless Union or Member State law requires otherwise (with the information duty stated there). |
| (b) | Confidentiality commitment or statutory confidentiality for authorised persons. |
| (c) | All measures required pursuant to Article 32. |
| (d) | Respect paragraphs 2 and 4 when engaging another processor. |
| (e) | Assist with Chapter III data-subject rights, insofar as possible. |
| (f) | Assist with Articles 32 to 36 — the cluster that includes breach notification and a DPIA. |
| (g) | Delete or return the data at the controller’s choice after the services end, unless the law requires storage. |
| (h) | Provide information to demonstrate compliance and contribute to audits; immediately flag instructions that, in the processor’s opinion, infringe data-protection law. |
Article 28(2) forbids engaging another processor without prior specific or general written authorisation; general authorisation still requires notice so the controller can object. Article 28(4) imposes the same data-protection obligations on that other processor and keeps the initial processor fully liable if it fails. Those processors also belong in the record of processing activities where Article 30 applies.
Can Commission standard contractual clauses replace a custom GDPR processor agreement?
Article 28(6) allows the contract to be based, in whole or in part, on standard contractual clauses under paragraphs 7 and 8, including as part of a certification under Articles 42 and 43. Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021) adopted such clauses. Its Article 1 says the Annex fulfils Article 28(3) and (4); Article 2 allows their use between a controller and a processor. Clause 1(f) of those clauses states they do not by themselves ensure Chapter V compliance, so they are not a substitute for the international-transfer toolkit.
When does a processor become a controller?
If a processor infringes the GDPR by determining the purposes and means of processing, Article 28(10) treats that processor as a controller in respect of that processing, without prejudice to Articles 82, 83 and 84. Article 83(4)(a) covers controller and processor obligations pursuant to Articles 8, 11, 25 to 39 and 42 and 43 — Article 28 sits in that 25-to-39 range — with fines up to 10 000 000 EUR, or for an undertaking up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher.
How was this guide checked?
GDPR Exam Trainer mapped each legal sentence to the English EUR-Lex text of Articles 4, 28, 29 and 83(4) and to Commission Decision (EU) 2021/915, and used EDPB Guidelines 07/2020 only for the employee-versus-processor distinction. The responsible organisation is GDPR Exam Trainer. The method is source mapping plus an independent citation gate, for DPO candidates — not legal advice.
Frequently asked questions
These answers apply Article 28, Article 29 and Decision (EU) 2021/915 to the questions practitioners actually ask about processor contracts.
Can a privacy policy replace an Article 28 contract?
No. Article 28(3) requires a contract or other legal act under Union or Member State law that is binding on the processor with regard to the controller. A public privacy notice informs data subjects; it does not create those processor duties.
Do employees need an Article 28 processor agreement?
No, not where they process personal data as part of the controller’s own entity. EDPB Guidelines 07/2020, paragraph 78, treat employees and similar staff acting under the direct authority of the controller as not processors. Article 29 separately says that any person acting under the authority of the controller or of the processor shall not process those data except on the controller’s instructions, unless Union or Member State law requires it.
What is the difference between specific and general sub-processor authorisation?
Article 28(2) allows prior specific written authorisation or general written authorisation. With general authorisation, the processor must inform the controller of intended additions or replacements so the controller can object.
Do Commission standard contractual clauses satisfy Article 28?
They can satisfy Article 28(3) and (4). Decision (EU) 2021/915 states that its Annex clauses fulfil those requirements and may be used between a controller and a processor. The same clauses say they do not by themselves ensure Chapter V transfer compliance.
What happens if a processor starts deciding why and how the data are processed?
Article 28(10) says that if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing, without prejudice to Articles 82, 83 and 84.