Processing Agreement
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Contract between controller and processor defining processing terms
Overview
16 sources · Jul 15, 2026Legal Framework
Article 28 GDPR mandates a binding written contract between controllers and processors, requiring specification of the subject matter, duration, nature, purpose, types of personal data, and categories of data subjects. This processing agreement must legally bind the processor to act solely on documented controller instructions, implement appropriate security measures, and assist the controller in fulfilling data subject rights requests. Recital 108 and Article 46(2)(c) GDPR extend these contractual requirements to international data transfers: absent an adequacy decision, parties must implement appropriate safeguards, primarily through standard contractual clauses (SCCs) or supervisory authority-approved contractual clauses, ensuring data subjects retain enforceable rights regardless of the destination country.
Key Developments
The Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems (Schrems II) established that SCCs provide uniform contractual guarantees but may require supplementary measures depending on the destination country's legal framework. The ruling places the burden on the controller or processor to conduct a case-by-case assessment of whether the third country's laws undermine the SCCs' effectiveness, necessitating additional technical or contractual safeguards. Dutch administrative jurisprudence (Reikwijdte beginselplicht tot handhaving en onderzoeksverplichtingen van de AP) confirms that the absence of a valid processor agreement and adequate transfer safeguards constitutes distinct, actionable violations warranting supervisory authority intervention. The EDPB has subsequently elaborated that codes of conduct and certification mechanisms can serve as appropriate transfer safeguards under Article 46, offering complementary tools to standard contractual clauses within complex processing arrangements.
Practical Guidance
- Execute a comprehensive Article 28 GDPR processing agreement before any data processing commences, explicitly detailing controller instructions, security obligations, breach notification timelines, and sub-processor authorization procedures.
- Integrate Article 46 GDPR transfer mechanisms—specifically the Commission's current SCC modules—directly into the processing agreement whenever personal data leaves the EEA.
- Conduct a documented transfer impact assessment for each third-country transfer as required by Schrems II, evaluating whether local surveillance laws necessitate supplementary technical measures like strong encryption or contractual transparency obligations.
- Mandate flow-down clauses ensuring all sub-processors are bound by data protection terms equivalent to the primary processing agreement, preserving the controller's audit and liability rights.
- Monitor EDPB guidance on codes of conduct and certifications to deploy them as supplementary transfer safeguards where standard clauses alone prove insufficient for specific third-country contexts.