Data Processor
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The entity that processes personal data on behalf of the controller
Overview
24 sources · Jul 23, 2026Legal Framework
Article 28 GDPR establishes the core legal regime for data processors. A controller may only engage a processor that provides sufficient guarantees of implementing appropriate technical and organisational measures. The relationship must be governed by a written contract—or other legally binding act—that mandatorily addresses the subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. Article 28(3) enumerates specific contractual clauses required, including instructions-only processing, confidentiality obligations, security measures under Article 32, restrictions on engaging sub-processors without prior authorisation, assistance obligations for data subject rights and breach notification, and deletion or return of data at termination.
Article 29 GDPR reinforces the chain of command: both the processor and any person acting under the authority of the controller or processor who has access to personal data may process them only on instructions, unless legally compelled otherwise. Article 44 GDPR extends the regime to international transfers: both controllers and processors must comply with Chapter V safeguards when transferring data to third countries, including when sub-processors are located outside the EU.
The sub-processor regime under Article 28(2) and (4) is particularly relevant in cloud computing contexts, where service providers routinely outsource hosting or shared server capacity to third parties. Processors must flow down equivalent data protection obligations to each sub-processor.
Key Developments
The Court of Justice's Schrems II ruling invalidated the Privacy Shield framework, directly impacting processors relying on third-country sub-processors. Processors must now implement supplementary transfer impact assessments and adopt appropriate safeguards, typically Standard Contractual Clauses, for any onward transfer outside the EU.
Dutch courts have clarified the enforcement expectations around processor agreements. In a case before the Dutch judiciary involving ActiveCampaign, a data subject argued that the absence of a valid processor agreement and Standard Contractual Clauses constituted independent violations warranting supervisory authority action. The court held that while the AP must investigate complaints appropriately, its investigative duty does not extend to proving the absence of violations—but the existence of a valid Article 28 agreement and transfer safeguards remains a distinct compliance obligation.
The Polish DPA's €2.68 million fine against DPD Polska demonstrates that deficient processing agreements carry substantial financial risk. The Italian Garante's fine against the Ministry of Enterprises further confirms that inadequate processing arrangements are enforceable across both private and public sector processors.
The EDPB has also issued recommendations on processor binding corporate rules, expanding the available transfer mechanisms for processor-led international data flows.
Practical Guidance
- Execute a written Article 28(3) agreement before any processing begins; verbal arrangements or generic terms of service without the mandatory enumerated clauses are insufficient and independently sanctionable.
- Obtain the controller's prior specific or general written authorisation before engaging any sub-processor; where general authorisation is used, notify the controller of intended changes and provide an objection mechanism.
- Conduct transfer impact assessments for all sub-processors located outside the EU, implement Standard Contractual Clauses, and add supplementary measures where local law undermines the safeguards.
- Bind all personnel with access to personal data under enforceable confidentiality obligations, as required by Article 28(3)(b) and reinforced by Article 29.
- Establish documented procedures for assisting the controller with data subject rights requests, breach notification under Article 33, and data deletion or return at contract termination.