Article 28 of the GDPR: Processors

Article 28 of the GDPR: Processors

Article 28 of the GDPR Explained

The data controller may only engage processors offering sufficient guarantees regarding data protection.

A written contract must govern the relationship and must specify, in particular:

  • The subject matter, duration, nature and purpose of the processing;
  • The types of data and the categories of data subjects;
  • The obligations of the processor, including confidentiality, security, assistance with requests, return or deletion of data, auditability, etc.

Why This Article is Important for Your GDPR Compliance

Data controllers remain fully responsible for the data, even when outsourcing. The selection and monitoring of data processors are therefore crucial aspects to ensure the overall compliance of your organisation.

How to Comply with GDPR Article 28

  • Assess the guarantees provided by your sub-processors (certifications, documented practices...).
  • Enter into a GDPR-compliant data processing agreement.
  • Regularly monitor the practices of sub-processors (audits, compliance reviews).
  • Ensure that no data processing is carried out without the controller's authorisation.

Examples of Application of Article 28 of the GDPR

  • A company entrusts its data hosting to a cloud provider: a GDPR data processing agreement is signed.
  • An HR firm outsources payroll processing to a service provider: it verifies the security and confidentiality guarantees.
  • A company uses an outsourced CRM: it governs the processing activities through a specific clause in the contract.

Related Resources

Accelerate your compliance in a few clicks

Thanks to our all-in-one solution, you can easily accelerate and ensure your compliance:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise awareness among your teams with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.

GDPR: Self-assess now