Article 28: Processor
Praxikon tracks Article 28 (Processor) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 28 govern?
Article 28 sets out what must happen when an organisation has another party process personal data on its behalf, for example a payroll provider or a cloud service. The controller may only use processors that provide sufficient guarantees that they implement appropriate technical and organisational measures (paragraph 1). The arrangements must be laid down in a written contract with mandatory elements (paragraphs 3 and 9), and a processor may only engage another processor with the controller's authorisation (paragraphs 2 and 4). The article exists because the protection of the data subject must not disappear once data leaves the building: recital 81 explains that the processor must be bound to the controller and that the choice of a processor should rest on expert knowledge, reliability and resources. A processor that starts determining the purposes and means of processing itself is treated as a controller for that processing (paragraph 10).
Key term: Data processing agreement: the written contract that binds the processor to the controller and sets out what it may do with the personal data (paragraphs 3 and 9)
Directly affects:controllerprocessorCommissionsupervisory authority
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Use only processors that demonstrably provide sufficient guarantees (paragraph 1) and put a written contract in place with each processor covering all the elements of paragraph 3 (paragraph 9). Decide in advance whether and how the processor may engage other processors and keep the ability to object (paragraph 2). Use your right to information and audits to check that the arrangements are being followed (paragraph 3(h)).
Processor
Process only on documented instructions from the controller and warn the controller immediately if you think an instruction infringes the GDPR (paragraph 3(a) and the final subparagraph of paragraph 3). Do not engage another processor without written authorisation and impose the same obligations on that other processor; you remain fully liable to the controller for what that other processor does (paragraphs 2 and 4). If you determine the purposes and means of processing yourself, you are treated as a controller for that processing (paragraph 10).
Data Subject
You do not need to do anything yourself. The article protects you because the controller may only use processors that provide sufficient guarantees for the protection of your rights (paragraph 1) and the processor must help answer your requests, such as access or erasure (paragraph 3(e)).
Compliance checklist
Related recitals
To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing a...
(82)In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be ...
Cross-references
Frequently asked questions
Connections
What connects to Article 28 GDPR
Themes where this returns
The counterpart in the other law
Guidelines
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)