Analysis of GDPR Article 28

Processor Governance, Accountability Architecture, and Technical Compliance Controls

Introduction: The Structural Importance of Article 28

General Data Protection Regulation (GDPR) Article 28 occupies a foundational position within the GDPR's accountability framework because it governs the legal and operational relationship between data controllers and data processors. While many organisations focus primarily on lawful bases for processing or data subject rights, Article 28 serves as the mechanism through which controllers operationalise accountability when personal data processing is delegated to third parties.

Article 28 embodies a core GDPR principle: responsibility for compliance cannot be outsourced. Controllers may outsource processing activities, but they cannot outsource accountability. Consequently, Article 28 creates a regulatory architecture that combines contractual obligations, organisational governance, technical safeguards, audit rights, supply-chain oversight, and demonstrable accountability.

Particularly Significant In

  • Modern cloud ecosystems
  • Software-as-a-Service environments
  • Managed service arrangements
  • AI processing supply chains
  • Multinational outsourcing structures

The Legal Purpose of Article 28

Article 28 establishes four fundamental objectives and creates what may be described as a "delegated accountability model." The processor performs operational processing functions, but the controller remains responsible for ensuring those activities remain compliant with GDPR requirements.

Processor Selection

Ensuring controllers select processors capable of GDPR compliance

Contractual Safeguards

Imposing mandatory contractual safeguards throughout the relationship

Sub-processor Accountability

Extending accountability throughout sub-processor chains

Evidence of Compliance

Providing evidence through audits, oversight, and documentation

Article 28(1): Due Diligence and Processor Selection

The first paragraph establishes a pre-contractual obligation. Controllers must use only processors that provide "sufficient guarantees" that appropriate technical and organisational measures (TOMs) have been implemented. The GDPR does not require controllers merely to obtain contractual promises — controllers must conduct a reasonable assessment demonstrating that the processor can actually meet GDPR requirements. Recital 81 reinforces this expectation by emphasising expertise, reliability, resources, and security capabilities.

✓ Appropriate Compliance

A healthcare provider evaluates a cloud-hosting vendor:

  • Reviews ISO 27001 certification
  • Examines penetration testing reports
  • Reviews incident response procedures
  • Evaluates subcontractor arrangements

✗ Potential Non-Compliance

  • Controller signs a standard vendor agreement without reviewing security documentation
  • No risk assessment is conducted
  • No assessment of processing capabilities occurs

Article 28(2): Authorisation of Sub-processors

Processors may not appoint sub-processors without authorisation. This requirement reflects a broader GDPR concern regarding transparency and supply-chain visibility.

Specific Authorisation

The controller explicitly approves each individual sub-processor before engagement, providing granular oversight of the processing chain.

General Authorisation

Processors must notify controllers of intended changes and provide a meaningful opportunity to object before onboarding new sub-processors.

✓ Compliant Example

  • A cloud provider notifies customers before onboarding a new data analytics sub-processor
  • Customers receive a 30-day objection period

✗ Non-Compliant Example

  • A processor silently introduces multiple new vendors without controller awareness

Article 28(3): Mandatory Data Processing Agreement Requirements

The heart of Article 28 lies in paragraph 3. Every controller-processor relationship must be governed by a binding legal instrument containing prescribed clauses. These provisions are mandatory and cannot be omitted.

Article 28(3)(a): Processing Only on Documented Instructions

Processors may process personal data only according to documented controller instructions. This requirement prevents processors from independently determining purposes or means of processing. The EDPB has emphasised that processors must notify controllers when instructions appear unlawful.

✓ Compliant

A payroll processor receives documented instructions defining employee data processing activities, with clear scope, purpose, and limitations specified in writing.

✗ Non-Compliant

The processor uses payroll information to develop internal analytics products — acting beyond the scope of controller instructions and independently determining a new processing purpose.

Article 28(3)(b): Confidentiality Obligations

Personnel authorised to process personal data must be bound by confidentiality obligations. This requirement extends across all categories of personnel with access to personal data.

Employees

All permanent staff with access to personal data must be subject to binding confidentiality obligations as a condition of employment.

Contractors & Consultants

External contractors and consultants must execute confidentiality agreements before being granted any access to personal data systems.

Temporary Workers

Temporary and agency workers must be covered by equivalent confidentiality undertakings regardless of the duration of their engagement.

✓ Compliant Controls

  • Mandatory confidentiality agreements
  • Annual confidentiality training

✗ Non-Compliant Indicators

  • Shared access credentials among contractors
  • No confidentiality undertakings in place

Article 28(3)(c): Security of Processing

Processors must implement security measures consistent with Article 32. This creates a direct and important linkage between Article 28 and GDPR cybersecurity requirements, ensuring that security obligations flow through the entire processing chain.

Encryption

Data must be encrypted both in transit and at rest using appropriate cryptographic standards.

Access Control

Robust identity and access management with least-privilege principles enforced throughout.

Logging & Monitoring

Comprehensive audit logging with tamper-resistant records and active security monitoring.

Resilience Testing

Regular testing of systems to ensure availability, integrity, and confidentiality can be restored.

Backup Procedures

Validated backup and recovery procedures ensuring data can be restored following an incident.

Article 28(3)(d): Sub-processor Flow-Down Obligations

Processors must impose equivalent obligations on sub-processors. This creates a contractual chain of accountability. The obligations need not be word-for-word identical but must provide equivalent protection throughout the entire processing chain.

This cascading obligation structure ensures that GDPR protections do not terminate at the first contractual layer. Where a cloud provider contracts with subcontractors, those subcontractors must maintain equivalent GDPR obligations — not merely commercial service terms.

✓ Compliant

Cloud provider contracts require all subcontractors to maintain equivalent GDPR obligations, verified through contractual review and periodic assurance activities.

✗ Non-Compliant

Security obligations terminate at the first processor layer, leaving sub-processors operating without binding GDPR-equivalent contractual requirements.

Article 28(3)(e): Assistance with Data Subject Rights

Processors must assist controllers in responding to data subject rights requests. This obligation recognises that processors often hold the technical capability to locate, retrieve, and action personal data on behalf of controllers.

Access Requests

Processor must support retrieval of personal data held about an individual.

Rectification

Processor must support correction of inaccurate personal data records.

Erasure

Processor must support deletion of personal data upon valid request.

Restriction

Processor must support limiting processing where restriction is requested.

Portability

Processor must support structured data export in machine-readable formats.

✓ Compliant

SaaS provider offers search and deletion tooling enabling controllers to fulfil rights requests efficiently.

✗ Non-Compliant

Processor lacks mechanisms to locate individual records, making rights fulfilment practically impossible.

Article 28(3)(f): Assistance with Controller Compliance Obligations

Processors must assist controllers with a range of broader compliance obligations that require processor cooperation to fulfil effectively.

Security Obligations

Supporting the controller's Article 32 security programme with technical information and cooperation.

Breach Notification

Providing timely incident reports enabling controllers to meet 72-hour supervisory authority notification deadlines.

DPIAs

Supplying technical and operational information necessary for Data Protection Impact Assessments.

Regulatory Consultations

Cooperating with prior consultation processes under Article 36 where high-risk processing is identified.

✓ Compliant

Processor provides incident reports within agreed timelines, enabling the controller to assess breach severity and meet notification obligations.

✗ Non-Compliant

Processor withholds forensic evidence after a breach, preventing the controller from conducting a proper investigation or notifying the supervisory authority.

Article 28(3)(g): Return or Deletion of Data

At contract termination, processors must either return or delete personal data. The choice belongs to the controller unless applicable law requires retention.

Return of Data

Controller may require the processor to return all personal data in a structured, usable format upon termination of the processing relationship.

Deletion of Data

Controller may require secure deletion of all personal data, with the processor providing a certificate of destruction as evidence of compliance.

✓ Compliant

A secure deletion certificate is provided after service termination, confirming all personal data has been irreversibly destroyed in accordance with agreed standards.

✗ Non-Compliant

A former processor retains customer data indefinitely after contract termination, with no deletion process or timeline in place.

Article 28(3)(h): Audit and Demonstration Rights

Processors must demonstrate compliance, provide relevant information, and permit audits. This provision operationalises GDPR accountability by ensuring that contractual commitments can be verified through independent evidence.

Certification Reports

SOC 2 Type II reports and ISO 27001 certificates provide structured third-party assurance of security controls.

Independent Audits

Controllers may commission independent audits of processor systems, with costs and logistics agreed contractually in advance.

Customer Inspection Rights

Contractual rights enabling controllers to conduct on-site or remote inspections of processor compliance programmes.

Articles 28(4) and 28(5): Liability and Certification

Article 28(4): Liability for Sub-processors

Processors remain liable for sub-processor performance. This creates a cascading accountability structure. A processor cannot avoid liability by claiming a subcontractor caused the violation.

If a cloud infrastructure subcontractor experiences a breach, the primary processor remains accountable to the controller. This principle ensures that accountability cannot be diluted through sub-contracting arrangements.


Article 28(5): Certification Mechanisms

Certification schemes may be used as evidence of compliance. Examples include ISO 27001, ISO 27701, and approved GDPR certification frameworks. Certification does not create automatic compliance but serves as supporting evidence within a broader accountability programme.

Recognised Certification Schemes

  • ISO 27001 – Information Security Management
  • ISO 27701 – Privacy Information Management
  • Approved GDPR certification frameworks
  • SOC 2 Type II reports
  • BSI Cloud Computing Compliance Criteria

Articles that Intersect Directly with Article 28

The following GDPR provisions form an integrated compliance framework with Article 28. The EDPB consistently interprets Article 28 through the broader accountability obligations imposed by Articles 5 and 24.

Technical Controls 1–5: Foundation Layer

The first five cross-cutting technical controls establish the foundational governance infrastructure required for full Article 28 compliance.

Processor Risk Assessment Framework

Formal due diligence methodology with security maturity scoring and risk-based processor classification. Ensures Article 28(1) obligations are met through structured, evidenced assessment rather than contractual assumption.

Vendor Security Assurance Programme

Evidence collection, security questionnaires, and independent assessment review. Provides ongoing assurance that processors maintain the "sufficient guarantees" required by Article 28(1).

Data Processing Agreement Lifecycle Management

Mandatory Article 28 clause verification, contract version control, and renewal monitoring. Ensures DPAs remain current, complete, and enforceable throughout the processor relationship.

Sub-processor Governance Programme

Centralised sub-processor inventory, change notification workflows, and objection management process. Operationalises Article 28(2) authorisation requirements at scale.

Data Flow Mapping

End-to-end processor visibility, processing activity tracing, and transfer pathway identification. Provides the foundational visibility required to manage processor chains effectively.

Technical Controls 6–10: Access, Encryption & Monitoring

The second group of controls addresses identity governance, cryptographic protection, confidentiality management, and security monitoring — directly supporting Article 28(3)(b) and (c) obligations.

Identity & Access Management

  • Least privilege enforcement
  • Role-based access controls
  • Privileged access monitoring

Strong Authentication Controls

  • Multi-factor authentication
  • Hardware token support
  • Adaptive authentication mechanisms

Encryption Governance

  • Encryption in transit
  • Encryption at rest
  • Cryptographic key management

Confidentiality Management

  • Employee NDAs
  • Contractor confidentiality obligations
  • Role-specific training

Security Monitoring & Logging

  • Centralised logging
  • SIEM integration
  • Tamper-resistant audit trails

Technical Controls 11–15: Vulnerability, Incident & Rights

The third group of controls addresses vulnerability management, incident response integration, data subject rights support, retention governance, and audit enablement — operationalising the Article 28(3)(e), (f), (g), and (h) obligations.

1

Vulnerability Management Programme

Continuous scanning, risk-based remediation, and patch governance. Ensures processors maintain the security posture required by Article 32 and Article 28(3)(c).

2

Incident Response Integration

Controller notification procedures, escalation matrices, and forensic preservation requirements. Supports Article 28(3)(f) breach notification assistance obligations.

3

Data Subject Rights Support Platform

Record discovery capability, deletion orchestration, and workflow automation. Enables processors to fulfil Article 28(3)(e) assistance obligations efficiently at scale.

4

Data Retention and Disposal Framework

Retention schedules, automated deletion workflows, and secure destruction verification. Operationalises Article 28(3)(g) return and deletion obligations.

5

Audit Rights Enablement

Evidence repositories, audit coordination procedures, and compliance dashboards. Directly supports Article 28(3)(h) demonstration and audit rights.

Technical Controls 16–20: Monitoring, Transfer & Accountability

The final group of controls addresses continuous third-party monitoring, secure development, international transfer governance, business continuity, and the accountability documentation repository that underpins demonstrable GDPR compliance.

Third-Party Continuous Monitoring

Security posture monitoring, external attack-surface assessments, and compliance drift detection. Ensures processor compliance is verified on an ongoing basis rather than solely at contract inception.

Secure Development Lifecycle Controls

Secure coding standards, application security testing, and privacy-by-design checkpoints. Embeds GDPR compliance into processor product development processes.

International Transfer Governance

SCC management, transfer impact assessments, and jurisdictional risk monitoring. Ensures Article 44–49 obligations are met throughout the processor chain.

Business Continuity and Resilience Controls

Backup validation, disaster recovery testing, and recovery time objectives. Supports Article 32 resilience requirements flowing through Article 28(3)(c).

Accountability Documentation Repository

Processor inventories, risk assessments, audit reports, certifications, and evidence of ongoing oversight — the definitive record of Article 28 compliance demonstrability.

Advanced Practitioner Observations

Accountability Over Contracting

Article 28 is fundamentally an accountability provision rather than merely a contracting provision. Modern supervisory authorities increasingly evaluate operational evidence rather than contractual wording alone.

Regulated Risk Management

Processor selection is no longer a procurement exercise; it is a regulated risk-management activity. Controllers must demonstrate substantive assessment of processor capabilities, not merely signature of standard terms.

Sub-processor Chain Transparency

The most significant contemporary compliance challenge is sub-processor chain transparency, particularly in cloud, AI, and SaaS ecosystems where processing chains may extend across multiple jurisdictions and vendors.

Continuous Oversight Required

Organisations that treat Article 28 as a one-time contractual requirement frequently fail audits. GDPR requires continuous oversight throughout the processor relationship lifecycle, not merely at inception.

The Strategic Bridge

In advanced GDPR governance programmes, Article 28 should be understood as the operational bridge connecting legal accountability, third-party risk management, cybersecurity governance, supply-chain assurance, and demonstrable compliance — making it one of the most strategically important provisions within the entire GDPR framework.

Emerging EDPB guidance increasingly emphasises visibility into downstream processor chains and verification of technical safeguards beyond first-tier vendors.

Datari Home