Controller-to-Processor Transfers: What Article 28 GDPR Requires

A practical guide to Article 28 GDPR requirements for controller-to-processor relationships, covering mandatory contracts, processor due diligence, required terms, sub-processor authorization, liability, security, oversight, and the distinction from international data transfer rules.

Controller-to-Processor Transfers: What Article 28 GDPR Requires
ChatGPT generated image from: Government of Alberta — Contracts — Available through Flickr here
Key Points: (1) Written contracts are mandatory between controllers and processors under Article 28 GDPR. (2) Controllers must use processors that provide sufficient guarantees for GDPR compliance. (3) Contracts must cover instructions, confidentiality, security, assistance, audits, and deletion or return of data. (4) Sub-processors require authorization, and Article 28 obligations must flow down to them. (5) The original processor remains liable for its sub-processors. (6) Article 28 contracts are separate from Chapter V international transfer requirements.

Whenever a controller engages a processor to process personal data on its behalf, the GDPR requires the relationship to be governed by a binding written agreement or other legal act. These contractual requirements are set out primarily in Article 28 GDPR and are a central part of the GDPR’s accountability framework.

The same principle applies further down the processing chain. If a processor engages another organization—a sub-processor—to carry out processing activities on behalf of the controller, the processor must obtain the controller’s prior specific or general written authorization and must impose appropriate contractual obligations on the sub-processor.

These requirements are sometimes referred to as the GDPR’s controller-to-processor (C2P) contractual requirements or data processing agreement (DPA) requirements.

Importantly, Article 28 contracts are not the same as the safeguards required for international transfers under Chapter V of the GDPR. A controller may need an Article 28-compliant processor agreement because it uses a processor, while separately needing an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another Chapter V mechanism if the arrangement also involves a restricted international transfer. See: When Can Personal Data Leave the EU? A Practical Guide to GDPR International Transfers

Controllers Must Select Processors Providing Sufficient Guarantees

Article 28(1) provides that a controller may use only processors that provide “sufficient guarantees” that they will implement appropriate technical and organizational measures so that the processing:

  • complies with the GDPR; and
  • protects the rights of data subjects.

A processor selection is not simply a procurement decision. Controllers should conduct appropriate due diligence before entrusting personal data to a service provider.

The level of diligence should reflect the nature and risks of the processing. Relevant considerations may include the processor's security measures, experience, expertise, reliability, resources, compliance practices, and ability to assist the controller in meeting its GDPR obligations.

Under Article 28(5), adherence to an approved code of conduct under Article 40 or an approved certification mechanism under Article 42 may be used as one element for demonstrating that a processor provides sufficient guarantees.

A Controller-Processor Agreement Must Be in Writing

Under Article 28(3), processing by a processor must be governed by a contract or other legal act under EU or Member State law that is binding on the processor.


Article 28(9) expressly requires the agreement to be in writing, including in electronic form.

The agreement must first describe the processing relationship itself, including:

  • the subject matter of the processing;
  • its duration;
  • the nature and purpose of the processing;
  • the types of personal data involved;
  • the categories of data subjects; and
  • the rights and obligations of the controller.

But simply describing the processing is not enough. Article 28(3) also specifies a series of substantive obligations that must be imposed on the processor.

What Must a Controller-to-Processor Contract Require?

An Article 28-compliant agreement must require the processor to:

1. Process Personal Data Only on Documented Instructions

The processor must process personal data only on the controller's documented instructions, including instructions relating to transfers of personal data to third countries or international organizations.

There is an exception where processing is required by EU or Member State law applicable to the processor. In that situation, the processor generally must inform the controller of the legal requirement before carrying out the processing, unless the applicable law prohibits disclosure on important grounds of public interest.

This requirement reflects a fundamental distinction between controllers and processors: the controller determines the purposes and means of processing, while the processor processes personal data on the controller's behalf and pursuant to its instructions. See: What is a Controller?

2. Ensure Confidentiality

The processor must ensure that persons authorized to process the personal data have:

  • committed themselves to confidentiality; or
  • are subject to an appropriate statutory duty of confidentiality.

3. Implement Appropriate Security Measures

The processor must take all measures required under Article 32 GDPR, which governs the security of processing. See: GDPR Data Security Explained: A Practical Guide to Technical and Organizational Measures

Depending on the risks involved, these may include technical and organizational measures relating to areas such as encryption, confidentiality, integrity, availability, resilience, restoration capabilities, testing, and security risk management.

4. Comply With the Rules for Sub-Processors

The processor must comply with Article 28's requirements before engaging another processor. This includes obtaining the controller's required authorization and imposing appropriate contractual obligations on the sub-processor. (See below)

5. Assist With Data Subject Rights

Taking into account the nature of the processing, the processor must assist the controller through appropriate technical and organizational measures, insofar as possible, with responding to requests by individuals exercising their Chapter III GDPR rights.

These may include requests relating to access, rectification, erasure, restriction, portability, and objection.

6. Assist With Security and Accountability Obligations

The processor must assist the controller with compliance with the obligations contained in Articles 32–36 GDPR, taking into account the nature of the processing and the information available to the processor.

These provisions address:

7. Delete or Return Personal Data When Services End

At the controller's choice, the processor must delete or return the personal data when the processing services end and delete existing copies.

An exception applies where EU or Member State law requires continued storage of the data.

8. Provide Information and Permit Audits

The processor must make available to the controller all information necessary to demonstrate compliance with Article 28.

It must also allow for and contribute to audits, including inspections, conducted by the controller or an auditor appointed by the controller.

In addition, if the processor believes that an instruction from the controller violates the GDPR or other applicable EU or Member State data protection law, it must immediately inform the controller.

What Happens When a Processor Uses a Sub-Processor?

Processors frequently rely on other service providers to perform parts of their services. Article 28 therefore establishes specific rules for processor-to-sub-processor relationships.

Under Article 28(2), a processor may not engage another processor without the controller's prior specific or general written authorization.

With specific authorization, the controller approves a particular sub-processor.

With general authorization, the processor may use sub-processors within the scope of the authorization, but it must inform the controller of intended additions or replacements so that the controller has an opportunity to object.

Authorization alone is not enough.

Article 28(4) requires the processor to impose on the sub-processor, through a contract or other legally binding act, the same data protection obligations contained in the controller-processor arrangement, insofar as they apply to the processing being performed.

In particular, the sub-processor must provide sufficient guarantees that it will implement appropriate technical and organizational measures so that the processing complies with the GDPR.

The Original Processor Remains Responsible

Engaging a sub-processor does not allow the original processor to transfer its responsibility to another organization.

If the sub-processor fails to fulfill its data protection obligations, Article 28(4) provides that the initial processor remains fully liable to the controller for the performance of the sub-processor's obligations.

This creates a contractual chain: Controller → Processor → Sub-Processor


The GDPR's protections are intended to follow the personal data throughout that processing chain.

When a Processor Becomes a Controller

A service provider's status does not depend solely on what the contract calls it.


Article 28(10) provides that if a processor violates the GDPR by determining the purposes and means of processing, it will be considered a controller with respect to that processing.

This reflects the GDPR's functional approach to the controller-processor distinction: the parties cannot determine their legal roles merely by labeling one organization a “controller” and the other a “processor.”

The analysis ultimately depends on what each organization actually does with the personal data and who determines why and how the relevant processing takes place.

Practical checklist

When engaging a processor, controllers should consider documenting:

  1. Processor status — Is the service provider actually acting as a processor for the relevant processing?
  2. Due diligence — Does the processor provide sufficient guarantees?
  3. Article 28 agreement — Is a compliant written agreement in place?
  4. Processing details — Are the purpose, duration, data, data subjects and processing activities clearly described?
  5. Security — Are appropriate technical and organizational measures documented?
  6. Sub-processors — Has specific or general authorization been established?
  7. Data subject rights — Can the processor provide the assistance required by the controller?
  8. Incident response — Are breach notification and assistance procedures defined?
  9. Audits and evidence — Can the controller obtain the information necessary to demonstrate compliance?
  10. Deletion and return — Is there a process for handling personal data when the services terminate?
  11. International transfers — Is a separate Chapter V transfer mechanism required?
  12. Ongoing oversight — Is the processor relationship periodically reviewed rather than treated as a one-time contracting exercise?

ADDITIONAL RESOURCES

Relevant provisions include:

EDPB and DPA guidance

Cloud processors

Cloud services commonly create more complex controller-processor and sub-processor arrangements. Relevant resources include:

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe