Controller-to-Processor Transfers: What Article 28 GDPR Requires
A practical guide to Article 28 GDPR requirements for controller-to-processor relationships, covering mandatory contracts, processor due diligence, required terms, sub-processor authorization, liability, security, oversight, and the distinction from international data transfer rules.
Key Points: (1) Written contracts are mandatory between controllers and processors under Article 28 GDPR. (2) Controllers must use processors that provide sufficient guarantees for GDPR compliance. (3) Contracts must cover instructions, confidentiality, security, assistance, audits, and deletion or return of data. (4) Sub-processors require authorization, and Article 28 obligations must flow down to them. (5) The original processor remains liable for its sub-processors. (6) Article 28 contracts are separate from Chapter V international transfer requirements.
Whenever a controller engages a processor to process personal data on its behalf, the GDPR requires the relationship to be governed by a binding written agreement or other legal act. These contractual requirements are set out primarily in Article 28 GDPR and are a central part of the GDPR’s accountability framework.
The same principle applies further down the processing chain. If a processor engages another organization—a sub-processor—to carry out processing activities on behalf of the controller, the processor must obtain the controller’s prior specific or general written authorization and must impose appropriate contractual obligations on the sub-processor.
These requirements are sometimes referred to as the GDPR’s controller-to-processor (C2P) contractual requirements or data processing agreement (DPA) requirements.
Importantly, Article 28 contracts are not the same as the safeguards required for international transfers under Chapter V of the GDPR. A controller may need an Article 28-compliant processor agreement because it uses a processor, while separately needing an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another Chapter V mechanism if the arrangement also involves a restricted international transfer. See: When Can Personal Data Leave the EU? A Practical Guide to GDPR International Transfers
Controllers Must Select Processors Providing Sufficient Guarantees
Article 28(1) provides that a controller may use only processors that provide “sufficient guarantees” that they will implement appropriate technical and organizational measures so that the processing:
- complies with the GDPR; and
- protects the rights of data subjects.
A processor selection is not simply a procurement decision. Controllers should conduct appropriate due diligence before entrusting personal data to a service provider.
The level of diligence should reflect the nature and risks of the processing. Relevant considerations may include the processor's security measures, experience, expertise, reliability, resources, compliance practices, and ability to assist the controller in meeting its GDPR obligations.
Under Article 28(5), adherence to an approved code of conduct under Article 40 or an approved certification mechanism under Article 42 may be used as one element for demonstrating that a processor provides sufficient guarantees.
A Controller-Processor Agreement Must Be in Writing
Under Article 28(3), processing by a processor must be governed by a contract or other legal act under EU or Member State law that is binding on the processor.
Article 28(9) expressly requires the agreement to be in writing, including in electronic form.
The agreement must first describe the processing relationship itself, including:
- the subject matter of the processing;
- its duration;
- the nature and purpose of the processing;
- the types of personal data involved;
- the categories of data subjects; and
- the rights and obligations of the controller.
But simply describing the processing is not enough. Article 28(3) also specifies a series of substantive obligations that must be imposed on the processor.
What Must a Controller-to-Processor Contract Require?

An Article 28-compliant agreement must require the processor to:
1. Process Personal Data Only on Documented Instructions
The processor must process personal data only on the controller's documented instructions, including instructions relating to transfers of personal data to third countries or international organizations.
There is an exception where processing is required by EU or Member State law applicable to the processor. In that situation, the processor generally must inform the controller of the legal requirement before carrying out the processing, unless the applicable law prohibits disclosure on important grounds of public interest.
This requirement reflects a fundamental distinction between controllers and processors: the controller determines the purposes and means of processing, while the processor processes personal data on the controller's behalf and pursuant to its instructions. See: What is a Controller?
2. Ensure Confidentiality
The processor must ensure that persons authorized to process the personal data have:
- committed themselves to confidentiality; or
- are subject to an appropriate statutory duty of confidentiality.
3. Implement Appropriate Security Measures
The processor must take all measures required under Article 32 GDPR, which governs the security of processing. See: GDPR Data Security Explained: A Practical Guide to Technical and Organizational Measures
Depending on the risks involved, these may include technical and organizational measures relating to areas such as encryption, confidentiality, integrity, availability, resilience, restoration capabilities, testing, and security risk management.
4. Comply With the Rules for Sub-Processors
The processor must comply with Article 28's requirements before engaging another processor. This includes obtaining the controller's required authorization and imposing appropriate contractual obligations on the sub-processor. (See below)
5. Assist With Data Subject Rights
Taking into account the nature of the processing, the processor must assist the controller through appropriate technical and organizational measures, insofar as possible, with responding to requests by individuals exercising their Chapter III GDPR rights.
These may include requests relating to access, rectification, erasure, restriction, portability, and objection.
6. Assist With Security and Accountability Obligations
The processor must assist the controller with compliance with the obligations contained in Articles 32–36 GDPR, taking into account the nature of the processing and the information available to the processor.
These provisions address:
- security of processing (see: GDPR Data Security Explained: A Practical Guide to Technical and Organizational Measures);
- personal data breach notification to supervisory authorities and communication of certain breaches to affected individuals (see: GDPR Data Breaches Explained: Security Incidents, Risk Assessment and Notification Requirements);
- Data Protection Impact Assessments (DPIAs) (see: The GDPR’s DPIA Requirement: Identifying, Assessing, and Mitigating High-Risk Processing); and
- prior consultation with supervisory authorities.
7. Delete or Return Personal Data When Services End
At the controller's choice, the processor must delete or return the personal data when the processing services end and delete existing copies.
An exception applies where EU or Member State law requires continued storage of the data.
8. Provide Information and Permit Audits
The processor must make available to the controller all information necessary to demonstrate compliance with Article 28.
It must also allow for and contribute to audits, including inspections, conducted by the controller or an auditor appointed by the controller.
In addition, if the processor believes that an instruction from the controller violates the GDPR or other applicable EU or Member State data protection law, it must immediately inform the controller.
What Happens When a Processor Uses a Sub-Processor?
Processors frequently rely on other service providers to perform parts of their services. Article 28 therefore establishes specific rules for processor-to-sub-processor relationships.
Under Article 28(2), a processor may not engage another processor without the controller's prior specific or general written authorization.
With specific authorization, the controller approves a particular sub-processor.
With general authorization, the processor may use sub-processors within the scope of the authorization, but it must inform the controller of intended additions or replacements so that the controller has an opportunity to object.
Authorization alone is not enough.
Article 28(4) requires the processor to impose on the sub-processor, through a contract or other legally binding act, the same data protection obligations contained in the controller-processor arrangement, insofar as they apply to the processing being performed.
In particular, the sub-processor must provide sufficient guarantees that it will implement appropriate technical and organizational measures so that the processing complies with the GDPR.
The Original Processor Remains Responsible
Engaging a sub-processor does not allow the original processor to transfer its responsibility to another organization.
If the sub-processor fails to fulfill its data protection obligations, Article 28(4) provides that the initial processor remains fully liable to the controller for the performance of the sub-processor's obligations.
This creates a contractual chain: Controller → Processor → Sub-Processor
The GDPR's protections are intended to follow the personal data throughout that processing chain.
When a Processor Becomes a Controller
A service provider's status does not depend solely on what the contract calls it.
Article 28(10) provides that if a processor violates the GDPR by determining the purposes and means of processing, it will be considered a controller with respect to that processing.
This reflects the GDPR's functional approach to the controller-processor distinction: the parties cannot determine their legal roles merely by labeling one organization a “controller” and the other a “processor.”
The analysis ultimately depends on what each organization actually does with the personal data and who determines why and how the relevant processing takes place.
Practical checklist
When engaging a processor, controllers should consider documenting:
- Processor status — Is the service provider actually acting as a processor for the relevant processing?
- Due diligence — Does the processor provide sufficient guarantees?
- Article 28 agreement — Is a compliant written agreement in place?
- Processing details — Are the purpose, duration, data, data subjects and processing activities clearly described?
- Security — Are appropriate technical and organizational measures documented?
- Sub-processors — Has specific or general authorization been established?
- Data subject rights — Can the processor provide the assistance required by the controller?
- Incident response — Are breach notification and assistance procedures defined?
- Audits and evidence — Can the controller obtain the information necessary to demonstrate compliance?
- Deletion and return — Is there a process for handling personal data when the services terminate?
- International transfers — Is a separate Chapter V transfer mechanism required?
- Ongoing oversight — Is the processor relationship periodically reviewed rather than treated as a one-time contracting exercise?
ADDITIONAL RESOURCES
Legal citations
Relevant provisions include:
- Article 28 — Processor
- Article 29 — Processing under the authority of the controller or processor
- Recital 81 - The Use of Processors*
EDPB and DPA guidance
- EDPB — Guidelines 07/2020 on the concepts of controller and processor in the GDPR The EDPB's guidelines provide detailed guidance on distinguishing controllers, processors and joint controllers and on the contractual requirements governing controller-processor relationships.
- Irish Data Protection Commission — A Practical Guide to Data Controller to Data Processor Contracts under GDPR Practical guidance on preparing controller-processor contracts, including the mandatory provisions required by Article 28.
- UK Information Commissioner's Office (ICO) — Contracts and liabilities between controllers and processors
- Office of the Privacy Commissioner of Canada: Guidance concerning outsourcing and processing of personal information by third parties
Cloud processors
Cloud services commonly create more complex controller-processor and sub-processor arrangements. Relevant resources include:
- European Data Protection Supervisor (EDPS) - Guidelines on the use of cloud computing services by EU institutions and bodies
- Article 29 Working Party - Opinion 05/2012 on Cloud Computing (WP196) Although predating the GDPR, the Opinion remains useful background on cloud provider relationships, contractual safeguards, transparency, security and sub-processing.
- ENISA - Cloud Security Guide for SMEs
- NIST - Cybersecurity Supply Chain Risk Management
