Skip to content
Topic Contested in court

Data Processor

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The entity that processes personal data on behalf of the controller

291 linked items 21 Case Law68 Guidance151 Enforcement28 News23 Literature

Overview

24 sources · Jul 23, 2026

Legal Framework

Article 28 GDPR establishes the core legal regime for data processors. A controller may only engage a processor that provides sufficient guarantees of implementing appropriate technical and organisational measures. The relationship must be governed by a written contract—or other legally binding act—that mandatorily addresses the subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. Article 28(3) enumerates specific contractual clauses required, including instructions-only processing, confidentiality obligations, security measures under Article 32, restrictions on engaging sub-processors without prior authorisation, assistance obligations for data subject rights and breach notification, and deletion or return of data at termination.

Article 29 GDPR reinforces the chain of command: both the processor and any person acting under the authority of the controller or processor who has access to personal data may process them only on instructions, unless legally compelled otherwise. Article 44 GDPR extends the regime to international transfers: both controllers and processors must comply with Chapter V safeguards when transferring data to third countries, including when sub-processors are located outside the EU.

The sub-processor regime under Article 28(2) and (4) is particularly relevant in cloud computing contexts, where service providers routinely outsource hosting or shared server capacity to third parties. Processors must flow down equivalent data protection obligations to each sub-processor.

Key Developments

The Court of Justice's Schrems II ruling invalidated the Privacy Shield framework, directly impacting processors relying on third-country sub-processors. Processors must now implement supplementary transfer impact assessments and adopt appropriate safeguards, typically Standard Contractual Clauses, for any onward transfer outside the EU.

Dutch courts have clarified the enforcement expectations around processor agreements. In a case before the Dutch judiciary involving ActiveCampaign, a data subject argued that the absence of a valid processor agreement and Standard Contractual Clauses constituted independent violations warranting supervisory authority action. The court held that while the AP must investigate complaints appropriately, its investigative duty does not extend to proving the absence of violations—but the existence of a valid Article 28 agreement and transfer safeguards remains a distinct compliance obligation.

The Polish DPA's €2.68 million fine against DPD Polska demonstrates that deficient processing agreements carry substantial financial risk. The Italian Garante's fine against the Ministry of Enterprises further confirms that inadequate processing arrangements are enforceable across both private and public sector processors.

The EDPB has also issued recommendations on processor binding corporate rules, expanding the available transfer mechanisms for processor-led international data flows.

Practical Guidance

  • Execute a written Article 28(3) agreement before any processing begins; verbal arrangements or generic terms of service without the mandatory enumerated clauses are insufficient and independently sanctionable.
  • Obtain the controller's prior specific or general written authorisation before engaging any sub-processor; where general authorisation is used, notify the controller of intended changes and provide an objection mechanism.
  • Conduct transfer impact assessments for all sub-processors located outside the EU, implement Standard Contractual Clauses, and add supplementary measures where local law undermines the safeguards.
  • Bind all personnel with access to personal data under enforceable confidentiality obligations, as required by Article 28(3)(b) and reinforced by Article 29.
  • Establish documented procedures for assisting the controller with data subject rights requests, breach notification under Article 33, and data deletion or return at contract termination.
Everything on this topic, by type links go to the exact provision / paragraph / section
Case Law 21
¶172 Second, wholly automated decisions may be adopted either by a processor established in a third country, acting on behalf of the controller established… Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23. ¶8 In de overwegingen 6, 10, 101, 103, 104, 107 tot en met 109, 114, 116 en 141 AVG staat te lezen: „(6) Door snelle technologische ontwikkelingen en glo… HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) ¶10 Artikel 4 van die verordening bepaalt: „In deze verordening wordt verstaan onder: […] 2) ‚verwerking’: een bewerking of een geheel van bewerkingen met… HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) ¶11 In artikel 23 van diezelfde verordening is het volgende bepaald: „1. De reikwijdte van de verplichtingen en rechten als bedoeld in de artikelen 12 tot… HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 Hof van Justitie EU HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Hof van Justitie EU Jul 2020 252/21 Meta Platforms v noyb CJEU Jan 2023 300/21 UI v Österreichische Post AG CJEU May 2023 District Court Den Haag Rb. Den Haag - C/09/689833 District Court Den Haag May 2026 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 623/17 Privacy International v Secretary of State CJEU Oct 2020 507/17 Google LLC v CNIL CJEU Sep 2019 807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin CJEU Dec 2023 136/17 GC and Others v CNIL CJEU Sep 2019 311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems CJEU Jul 2020 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 601/21 Meta Platforms and Others v Bundeskartellamt CJEU Jul 2023 Administrative Court Munich VG München - M 26a K 25.5210 Administrative Court Munich May 2026 LG Rostock LG Rostock - 3 O 762/19 LG Rostock Sep 2020 GHARL GHARL - 200.256.426 GHARL Nov 2019 Social Court Nuremberg SG Nürnberg - S 5 SF 65/24 DS Social Court Nuremberg Jun 2026 Show 1 more →
Guidance 68
guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 222024 on certain obligations following from the Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) EDPB Oct 2024 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 Show 48 more →
Enforcement 151
NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 UODO (Poland) UODO (Poland) - DKN.5131.7.2022 UODO (Poland) Apr 2026 Croatian Data Protection Authority (azop) Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Croatian Data Protection Authority (azop) Nov 2025 NL UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 HDPA (Greece) HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College HDPA (Greece) Jul 2026 Polish National Personal Data Protection Office (UODO) DPD Polska sp. z o.o.: Insufficient data processing agreement Polish National Personal Data Protection Office (UODO) Feb 2026 Information Commissioner (ICO) CAPITA PENSION SOLUTIONS LIMITED: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Information Commissioner (ICO) Oct 2025 NL French Data Protection Authority (CNIL) MOBIUS SOLUTIONS LTD: Niet-naleving van de algemene principes voor gegevensverwerking. French Data Protection Authority (CNIL) Dec 2025 NL Spanish Data Protection Authority (aepd) SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Onvoldoende overeenkomst met betrekking tot gegevensverwerking. Spanish Data Protection Authority (aepd) Oct 2025 NL Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 Italian Data Protection Authority (Garante) Ministero delle Imprese e del Made in Italy: Insufficient data processing agreement Italian Data Protection Authority (Garante) Feb 2026 AEPD (Spain) AEPD (Spain) - EXP202306354 (PS/00312/2024) AEPD (Spain) Feb 2026 Croatian Data Protection Authority (azop) Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Croatian Data Protection Authority (azop) Nov 2025 Italian Data Protection Authority (Garante) FT Solutions S.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Italian Data Protection Authority (Garante) Oct 2025 NL Dutch Supervisory Authority for Data Protection (AP) Municipality of Tilburg: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Veenendaal: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Gooise Meren: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Show 131 more →
News 28
GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub VDAI (Litouwen) - Besluit nr. 3R-1700. GDPRhub Jan 2026 NL GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub CNIL (France) - SAN-2025-014 GDPRhub Jan 2026 European Data Protection Board EDPB contributes to the LED evaluation and adopts recommendations on the application for Processor BCR European Data Protection Board Jan 2026 GDPRhub VDAI (Lithuania) - Decision No. 3R-1700. GDPRhub Jan 2026 Autoriteit Persoonsgegevens Three recommendations for a strong data processing agreement in the event of a cyberattack Autoriteit Persoonsgegevens Nov 2025 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 Autoriteit Persoonsgegevens Three recommendations for a robust data processing agreement in the event of a cyberattack. Autoriteit Persoonsgegevens Nov 2025 European Digital Rights Artificial intelligence is not as artificial as you might think. European Digital Rights Nov 2025 European Digital Rights Artificial intelligence isn't as artificial as you might think. European Digital Rights Nov 2025 GDPRhub De Deense toezichthouder (SA) heeft de regio Syddanmark berispt omdat de procedures voor het controleren van verwerkingsactiviteiten niet voldoende duidelijk waren. GDPRhub Sep 2022 NL Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL News An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR? News Nov 2022 News WODC: Rapport Bescherming gegeven Evaluatie UAVG meldplicht datalekken en de boetebevoegdheid News Jun 2022 NL Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL IAPP De AEPD (Autoriteit voor Persoonsgegevens) heeft een tool ontwikkeld waarmee verantwoordelijken voor de verwerking van persoonsgegevens de relevante autoriteiten kunnen identificeren waaraan een datalek moet worden gemeld. IAPP Oct 2022 NL AEPD De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). AEPD Oct 2022 NL Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 Show 8 more →
Literature 23
European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Greece: The New Data Protection Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Journal of Data Protection Privacy General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Journal of Data Protection Privacy Sep 2021 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review Germany ∙ Data Protection Authorities Give Guidance on Direct Marketing under GDPR European Data Protection Law Review Jan 2019 Show 3 more →