Article 28 of the GDPR: Processors
Article 28 of the GDPR Explained
The data controller may only engage processors offering sufficient guarantees regarding data protection.
A written contract must govern the relationship and must specify, in particular:
- The subject matter, duration, nature and purpose of the processing;
- The types of data and the categories of data subjects;
- The obligations of the processor, including confidentiality, security, assistance with requests, return or deletion of data, auditability, etc.
Why This Article is Important for Your GDPR Compliance
Data controllers remain fully responsible for the data, even when outsourcing. The selection and monitoring of data processors are therefore crucial aspects to ensure the overall compliance of your organisation.
Examples of Application of Article 28 of the GDPR
- A company entrusts its data hosting to a cloud provider: a GDPR data processing agreement is signed.
- An HR firm outsources payroll processing to a service provider: it verifies the security and confidentiality guarantees.
- A company uses an outsourced CRM: it governs the processing activities through a specific clause in the contract.
Related Resources
Accelerate your compliance in a few clicks
Thanks to our all-in-one solution, you can easily accelerate and ensure your compliance:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR training e-learning
Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.
How to Comply with GDPR Article 28