Admin 10 Jun 2026 14:32

 

Understanding Article 28(3) GDPR The ControllerProcessor Agreement

The General Data Protection Regulation (GDPR) obliges organisations that handle personal data to adopt strict safeguards and clear contractual relationships. Article 28 sets out the requirements for the relationship between a data controller and a data processor. Paragraph3 of this article details the specific content that must be included in a controllerprocessor agreement (CPA). This page explains the legal background, the mandatory clauses, bestpractice tips, and the consequences of noncompliance.

Why a ControllerProcessor Agreement Matters

Under the GDPR, a controller determines the purposes and means of processing personal data, while a processor carries out processing on behalf of the controller. The regulator expects a written contract that:"

  • Defines the responsibilities of each party;
  • Ensures that the processor only acts on documented instructions;
  • Provides safeguards for the security of the data.

Without a valid CPA, the controller may be held liable for the processors actions, and the processor could face administrative fines. Moreover, the agreement is a key piece of evidence during supervisory authority investigations.

Legal Basis Article 28(3) Wording

The regulation states that a controller must use a contract or other legal act "under Union or Member State law" that binds the processor to the controller and includes the following items:

1. SubjectMatter and Duration of Processing

The contract must clearly state what data will be processed, for which specific purposes, and for how long the processing will continue. This helps both parties verify that processing does not exceed the agreed scope.

2. Nature and Purpose of Processing

Beyond the mere description of data types, the agreement must articulate the nature (e.g., collection, storage, analysis) and the purpose (e.g., marketing, fulfilment of contracts, employee management). This clause prevents mission creep where a processor expands activities without consent.

3. Types of Personal Data and Categories of Data Subjects

Specifying the categories of data subjects (customers, employees, suppliers) and the kind of personal data (identifiers, financial information, health data) is essential for risk assessment and for applying the correct security measures.

4. Obligations of the Processor

The processor must commit to:

  • Processing only on documented instructions from the controller;
  • Implementing appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk;
  • Ensuring that persons authorised to process the data are bound by confidentiality;
  • Assisting the controller in exercising datasubject rights;
  • Assisting with dataprotection impact assessments (DPIAs) where required;
  • Cooperating with supervisory authorities;
  • Not engaging another processor (subprocessor) without prior written authorisation, unless the contract provides a transparent mechanism for such authorisation.

5. Subprocessing Rules

If the processor wishes to engage subprocessors, the agreement must contain a clause that:

  • Requires the controllers prior written consent;
  • Mandates the same dataprotection obligations for the subprocessor as the primary processor;
  • Provides the controller with a right to object to any subprocessor.

6. International Data Transfers

Any transfer of personal data outside the European Economic Area (EEA) must be governed by an appropriate legal mechanism (e.g., Standard Contractual Clauses, Binding Corporate Rules). The CPA must disclose the transfer mechanism and the safeguards in place.

7. Security Measures

While the GDPR does not prescribe a precise list of technical controls, the contract must reference a riskbased approach, covering:

  • Encryption (at rest and in transit);
  • Access controls and authentication;
  • Regular testing, vulnerability assessments, and penetration testing;
  • Incident response and breach notification procedures.

8. Data Breach Notification

The processor must agree to notify the controller without undue delay after becoming aware of a personal data breach. The CPA should set a maximum timeframe (commonly 2448hours) and identify the format of the notification.

9. Assistance with DataSubject Rights

When a data subject exercises rights (access, rectification, erasure, restriction, portability, objection), the processor must provide the controller with the necessary information or take direct action, as directed.

10. Return or Deletion of Data

Upon termination of the contract, the processor must either return all personal data to the controller or securely delete it, unless EU or Member State law requires storage. The CPA should detail the method of deletion and any certification required.

Best Practices for Drafting a Robust CPA

  • Use a template that reflects the specific industry. Healthcare, finance, and advertising have additional sectorspecific obligations.
  • Make the obligations measurable. Instead of appropriate security measures, specify encryption using AES256, multifactor authentication for all admin accounts, and quarterly penetration testing.
  • Include audit rights. Give the controller the ability to conduct or commission audits of the processors compliance.
  • Review and update regularly. The GDPR is dynamic; contracts should be revisited at least annually or when the scope of processing changes.
  • Document instructions. Keep a written log of all controller instructions to the processor; this can be vital evidence in a dispute.
  • Clarify liability. Although the GDPR imposes joint liability, the CPA can allocate responsibility for specific breaches, provided it does not conflict with the law.

Consequences of NonCompliance

If a CPA fails to contain the mandatory clauses of Article28(3), the following risks arise:

  • Administrative fines: Up to 20million or 4% of global annual turnover for serious infringements.
  • Legal liability: The controller may be held liable for the processors unlawful processing.
  • Reputational damage: Data breaches disclosed without a proper contractual basis can erode customer trust.
  • Contractual disputes: Lack of clarity may lead to costly litigation between the parties.

Sample Clause (Illustrative Only)

The following excerpt demonstrates how the mandatory elements can be combined into a single clause. It is provided for illustration; legal counsel should tailor it to each specific relationship.

1. SubjectMatter & Duration   The Processor shall process the Personal Data described in AnnexA solely for the purposes set out in AnnexB and for the duration of the Services Agreement, unless earlier terminated in accordance with Clause12.2. Nature, Purpose & Types of Data   Processing shall consist of collection, storage, analysis and reporting of the categories of Data Subjects listed in AnnexA, in order to enable the Controller to fulfil contractual obligations with its customers.3. Obligations of the Processor   a) Process only on documented instructions from the Controller;   b) Implement the technical and organisational measures set out in AnnexC;   c) Ensure that persons authorised to process the Data are subject to confidentiality obligations;   d) Assist the Controller with DPIAs, breach notifications and datasubject requests;   e) Not engage subprocessors without prior written authorisation from the Controller;   f) Promptly notify the Controller of any personal data breach no later than 24hours after detection....    

Conclusion

Article28(3) of the GDPR makes it clear that a controllerprocessor relationship cannot rely on informal understandings. A welldrafted CPA protects both parties, demonstrates compliance, and provides a defensible record if a supervisory authority intervenes. By embedding the twelve mandatory elements, supplementing them with concrete technical specifications, and reviewing the agreement regularly, organisations can manage dataprotection risk while maintaining the flexibility needed for modern digital operations.

For further reading, consult the text of the GDPR and the guidance issued by the European Data Protection Board (EDPB) on processor contracts.

Reference Files For Article 28 (3) General Data Protection Regulation (GDPR) Controller Processor Agreement
Screenshoot
File Name
200528_avv_version_en.pdf

File Size
0.27 MB

File Type
PDF

File Site
Description
This file is just a reference file for Article 28 (3) General Data Protection Regulation (GDPR) Controller Processor Agreement. Does not guarantee that the specific things you want are included in it.
Direct download (wait 10 seconds)

Article 28 (3) General Data Protection Regulation (GDPR) Controller Processor Agreement an...


admin
Admin
2026-06-10 14:32:06

General Data Protection Regulation (GDPR) and Reference File Download Link


admin
Admin
2026-06-05 10:24:06

General Data Protection Regulation (GDPR) Policy and Reference File Download Link


admin
Admin
2026-06-10 15:44:06

EU General Data Protection Regulation (GDPR) Implementation And Compliance Guide and Refer...


admin
Admin
2026-06-11 08:04:06

Technology S Role In Data Protection The Missing Link In GDPR Transformation and Reference...


admin
Admin
2026-06-11 15:42:06