Skip to content
Topic Contested in court

Processing Agreement

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Contract between controller and processor defining processing terms

2,960 linked items 2 Laws34 Case Law46 Guidance2798 Enforcement58 News

Overview

16 sources · Jul 15, 2026

Legal Framework

Article 28 GDPR mandates a binding written contract between controllers and processors, requiring specification of the subject matter, duration, nature, purpose, types of personal data, and categories of data subjects. This processing agreement must legally bind the processor to act solely on documented controller instructions, implement appropriate security measures, and assist the controller in fulfilling data subject rights requests. Recital 108 and Article 46(2)(c) GDPR extend these contractual requirements to international data transfers: absent an adequacy decision, parties must implement appropriate safeguards, primarily through standard contractual clauses (SCCs) or supervisory authority-approved contractual clauses, ensuring data subjects retain enforceable rights regardless of the destination country.

Key Developments

The Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems (Schrems II) established that SCCs provide uniform contractual guarantees but may require supplementary measures depending on the destination country's legal framework. The ruling places the burden on the controller or processor to conduct a case-by-case assessment of whether the third country's laws undermine the SCCs' effectiveness, necessitating additional technical or contractual safeguards. Dutch administrative jurisprudence (Reikwijdte beginselplicht tot handhaving en onderzoeksverplichtingen van de AP) confirms that the absence of a valid processor agreement and adequate transfer safeguards constitutes distinct, actionable violations warranting supervisory authority intervention. The EDPB has subsequently elaborated that codes of conduct and certification mechanisms can serve as appropriate transfer safeguards under Article 46, offering complementary tools to standard contractual clauses within complex processing arrangements.

Practical Guidance

  • Execute a comprehensive Article 28 GDPR processing agreement before any data processing commences, explicitly detailing controller instructions, security obligations, breach notification timelines, and sub-processor authorization procedures.
  • Integrate Article 46 GDPR transfer mechanisms—specifically the Commission's current SCC modules—directly into the processing agreement whenever personal data leaves the EEA.
  • Conduct a documented transfer impact assessment for each third-country transfer as required by Schrems II, evaluating whether local surveillance laws necessitate supplementary technical measures like strong encryption or contractual transparency obligations.
  • Mandate flow-down clauses ensuring all sub-processors are bound by data protection terms equivalent to the primary processing agreement, preserving the controller's audit and liability rights.
  • Monitor EDPB guidance on codes of conduct and certifications to deploy them as supplementary transfer safeguards where standard clauses alone prove insufficient for specific third-country contexts.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 2
Art. 46(2)(c) standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2); GDPR Art. 46(2)(d) standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to i… GDPR Art. 58(3)(g) to adopt standard data protection clauses referred to in Article 28(8) and in point (d) of Article 46(2); GDPR Art. 64(1)(d) aims to determine standard data protection clauses referred to in point (d) of Article 46(2) and in Article 28(8); GDPR rec 109 Recital 109 — standard data protection clauses contractual flexibility GDPR Apr 2016 rec 108 Recital 108 — appropriate safeguards for international data transfers GDPR Apr 2016
Case Law 34
¶172 Second, wholly automated decisions may be adopted either by a processor established in a third country, acting on behalf of the controller established… Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23. ¶102 The appropriate safeguards referred to in Article 48(1) of Regulation 2018/1725, listed in Article 48(2) and (3) of that regulation, may be provided f… Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A ¶103 However, the standard data protection clauses provided for in Article 48(2)(b) of Regulation 2018/1725 may require the adoption of supplementary measu… Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A ¶8 In de overwegingen 6, 10, 101, 103, 104, 107 tot en met 109, 114, 116 en 141 AVG staat te lezen: „(6) Door snelle technologische ontwikkelingen en glo… HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 Hof van Justitie EU HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Hof van Justitie EU Jul 2020 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 District Court Den Haag Rb. Den Haag - C/09/689833 District Court Den Haag May 2026 GDPRhub CJEU - C-311/18 - Facebook Ireland and Schrems GDPRhub Jul 2026 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 507/17 Google LLC v CNIL CJEU Sep 2019 CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin CJEU Dec 2023 136/17 GC and Others v CNIL CJEU Sep 2019 CJEU UNABHäNGIGES LANDESZENTRUM FüR DATENSCHUTZ SCHLESWIG-HOLSTEIN v. WIRTSCHAFTSAKADEMIE SCHLESWIG-HOLDSTEIN GmbH CJEU Jun 2018 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 601/21 Meta Platforms and Others v Bundeskartellamt CJEU Jul 2023 311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems CJEU Jul 2020 Show 14 more →
Guidance 46
§0 PREFACE Guidelines 9/2022 on personal data breach notification under GDPR §42 Article 26 GDPR concerns joint controllers and specifies that joint controllers shall determine their respective responsibilities for compliance with … Guidelines 9/2022 on personal data breach notification under GDPR §33 When the code of conduct is to be used for transfers and onward transfers by a processor to subprocessors, a reference to the code of conduct and the … Guidelines 04/2021 on Codes of Conduct as tools for transfers §2 Adopted 4 The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of… EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 222024 on certain obligations following from the Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) EDPB Oct 2024 edps joint opinion 22021 on standard contractual clauses for the EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries EDPB Jan 2021 note on data transfers under the gdpr to the united kingdom Information note on data transfers under the GDPR to the United Kingdom after the transition period EDPB Dec 2020 asked questions on the judgment of the court of justice of the Frequently Asked Questions on the judgment of the Court of Justice of the European Union in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems EDPB Jul 2020 note on data transfers under the gdpr in the event of a no Information note on data transfers under the GDPR in the event of a no-deal Brexit EDPB Feb 2019 252025 on the decision of the polish supervisory Opinion 25/2025 on the decision of the Polish Supervisory Authority regarding the Processor Binding Corporate Rules of the BOX Group EDPB Oct 2025 opinion 202515 dbo certificationcriteria Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH EDPB Jul 2025 Show 26 more →
Enforcement 2798
§29 The Regional Administrative Court, in its justification of the judgment of August 26, 2020, file ref. II SA/Wa 2826/19 (upheld by the Supreme Administ… UODO (Poland) - DKN.5131.34.2023 §79 The description of the context of processing is largely general in nature. The Center identified the recipients of the data using the formula: "The da… UODO (Poland) - DKN.5131.27.2023 NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 Polish National Personal Data Protection Office (UODO) DPD Polska sp. z o.o.: Insufficient data processing agreement Polish National Personal Data Protection Office (UODO) Feb 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 UODO (Poland) UODO (Poland) - DKN.5131.7.2022 UODO (Poland) Apr 2026 Croatian Data Protection Authority (azop) Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Croatian Data Protection Authority (azop) Nov 2025 Italian Data Protection Authority (Garante) Ministero delle Imprese e del Made in Italy: Insufficient data processing agreement Italian Data Protection Authority (Garante) Feb 2026 AEPD (Spain) AEPD (Spain) - EXP202306354 (PS/00312/2024) AEPD (Spain) Feb 2026 Spanish Data Protection Authority (aepd) Aena, een klein en middelgroot bedrijf (KMO), S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Spanish Data Protection Authority (aepd) Nov 2025 NL French Data Protection Authority (CNIL) Company: Non-compliance with general data processing principles French Data Protection Authority (CNIL) Dec 2025 Croatian Data Protection Authority (azop) Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Croatian Data Protection Authority (azop) Nov 2025 NL Spanish Data Protection Authority (aepd) Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Mar 2026 French Data Protection Authority (CNIL) FREE: Insufficient technical and organisational measures to ensure information security French Data Protection Authority (CNIL) Jan 2026 French Data Protection Authority (CNIL) FREE MOBILE: Insufficient technical and organisational measures to ensure information security French Data Protection Authority (CNIL) Jan 2026 French Data Protection Authority (CNIL) GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing French Data Protection Authority (CNIL) Sep 2025 French Data Protection Authority (CNIL) GOOGLE IRELAND LIMITED: Onvoldoende juridische basis voor de verwerking van gegevens. French Data Protection Authority (CNIL) Sep 2025 NL Garante per la protezione dei dati personali (Italy) Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs Garante per la protezione dei dati personali (Italy) Jan 2026 Spanish Data Protection Authority (aepd) Aena, S.M.E., S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Nov 2025 Spanish Data Protection Authority (aepd) SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient data processing agreement Spanish Data Protection Authority (aepd) Oct 2025 French Data Protection Authority (CNIL) GOOGLE LLC: Onvoldoende juridische basis voor de verwerking van gegevens. French Data Protection Authority (CNIL) Sep 2025 NL Show 2778 more →
News 58
European Data Protection Board EDPB identifies challenges hindering the full implementation of the right to erasure European Data Protection Board Feb 2026 GDPRhub CNIL (France) - SAN-2025-014 GDPRhub Jan 2026 European Data Protection Board Strengthening data protection worldwide: EDPB meets with the countries and organisation with an adequacy decision European Data Protection Board Dec 2025 European Data Protection Board EDPB contributes to the LED evaluation and adopts recommendations on the application for Processor BCR European Data Protection Board Jan 2026 EDPB Strengthening data protection globally: The European Data Protection Board (EDPB) is meeting with countries and organizations that have an adequacy decision. EDPB Dec 2025 GDPRhub VDAI (Lithuania) - Decision No. 3R-1700. GDPRhub Jan 2026 GDPRhub AEPD (Spain) - EXP202500113 GDPRhub Jan 2026 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 EDPB Strengthening data protection globally: The European Data Protection Board (EDPB) meets with countries and organizations subject to an adequacy decision. EDPB Dec 2025 European Data Protection Board Data Protection Day 2026: keeping children’s personal data safe online European Data Protection Board Jan 2026 GDPRhub Authority for the protection of personal data (Italy) - 10201989 GDPRhub Jan 2026 GDPRhub VDAI (Litouwen) - Besluit nr. 3R-1700. GDPRhub Jan 2026 NL GDPRhub AEPD (Spain) - EXP202306073 GDPRhub Jan 2026 GDPRhub DSB (Austria) - 2025-0.395.497 GDPRhub Jan 2026 EDPB Coordinated Enforcement Framework: EDPB selects topic for 2026 EDPB Oct 2025 EDPB Support the EDPB’s work as an expert EDPB Nov 2025 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 GDPRhub AEPD (Spain) - EXP202306073 GDPRhub Jan 2026 EDPB Coordinated Enforcement Framework: The EDPB selects a topic for 2026. EDPB Oct 2025 Show 38 more →
Literature 22
SSRN Electronic Journal Unprotected Processing by Default vs Data Protection by Design and by Default Under the GDPR for Schrems II and GDPR SSRN Electronic Journal Jan 2022 European Data Protection Law Review Council of Europe ∙ Convention 108+, the GDPR, and Data Processing in the National Security Domain European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review Civil Liability for Processing of Personal Data in the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: Draft Personal Data Processing Law European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 Show 2 more →