GDPR Data Processing Agreement (DPA): Article 28 Explained (2026)

By Recording Law Editorial Team20 min read
GDPR Data Processing Agreement (DPA): Article 28 Explained (2026)

Frequently Asked Questions

What is a data processing agreement under GDPR?

A data processing agreement (DPA) is a written contract that GDPR Article 28 requires a controller to enter into with every processor before that processor handles personal data on the controller's behalf. The DPA must set out the subject-matter, duration, nature, and purpose of the processing, and must include the eight categories of mandatory obligations listed in Article 28(3), including the processor's duty to follow documented instructions only, maintain confidentiality, implement security measures, manage sub-processors, assist with data-subject rights, assist with breach notification and DPIAs, delete or return data at the end of the relationship, and cooperate with audits.

When do you need a GDPR DPA?

A DPA is required every time a processor processes personal data on a controller's behalf. The obligation applies regardless of industry, organisation size, contract value, or the sensitivity of the data involved. It applies before any processing begins. Common examples where DPAs are required include cloud storage providers hosting a controller's data, SaaS platforms processing customer records, payroll bureaus processing employee data, analytics providers processing website-visitor data, and IT support contractors with access to systems containing personal data. A DPA is not required between joint controllers (which have a separate obligation under Article 26) or where the third party processes data entirely independently for its own purposes.

What must a GDPR DPA include?

Article 28(3) specifies eight categories of mandatory clauses: (a) process only on documented controller instructions; (b) ensure authorised staff are bound to confidentiality; (c) implement Article 32 security measures; (d) comply with sub-processor authorisation and flow-down requirements; (e) assist the controller with data-subject rights requests; (f) assist with breach notification under Articles 33 and 34, DPIAs under Article 35, and prior consultation under Article 36; (g) delete or return all personal data after services end; and (h) make information available for audits and inspections and immediately inform the controller of any instruction that appears to infringe the GDPR. Beyond those clauses, the DPA must also specify the processing subject-matter, duration, nature, purpose, data types, and categories of data subjects.

Who provides the DPA: controller or processor?

The legal obligation to ensure a DPA is in place rests on the controller under Article 28(1). In practice, large processors (cloud providers and SaaS vendors) typically draft and publish standard DPAs that controllers are invited to accept. The controller cannot delegate its legal obligation to the processor by countersigning a DPA without reviewing its content. The controller must verify that any processor-provided DPA satisfies all eight elements of Article 28(3). Where the processor does not offer a standard DPA, the controller must draft one or use the Commission's Article 28 standard contractual clauses (Implementing Decision (EU) 2021/915) as the base.

What is the difference between a controller and a processor under GDPR?

Article 4(7) defines a controller as the entity that determines the purposes and means of processing personal data, meaning it decides why the data is processed and how. Article 4(8) defines a processor as an entity that processes personal data on behalf of the controller, following the controller's instructions without independently determining the processing purpose. The EDPB's Guidelines 07/2020 confirm that this distinction is functional and factual: labelling a party as a processor in a contract does not make it one if it exercises independent control over purposes. A processor that starts determining processing purposes on its own becomes a controller under Article 28(10) and assumes full controller liability.

Can the Commission's standard contractual clauses be used as a DPA?

Yes. Commission Implementing Decision (EU) 2021/915 of 4 June 2021 adopted standard contractual clauses specifically for controller-processor relationships under Article 28. These Article 28 SCCs provide a pre-approved template that automatically satisfies the Article 28(3) mandatory-clause requirements when used without modification. Parties complete the appendices with their specific processing parameters (data categories, purposes, security measures, sub-processor lists). The Article 28 SCCs are distinct from the 2021 international transfer SCCs under Decision (EU) 2021/914; where international transfers are also involved, both sets of clauses may be needed.

What are the consequences of not having a DPA?

Failing to have a compliant DPA is an independent GDPR violation subject to administrative fines of up to EUR 10 million or two percent of total worldwide annual turnover under Article 83(4). Where the missing DPA is part of broader accountability failures, higher fines under Article 83(5) may also be imposed. Beyond fines, supervisory authorities can issue processing bans under Article 58(2), which may halt business operations. Controllers may also face civil liability under Article 82 from data subjects who suffer damage. Enforcement decisions finding absent or inadequate processing agreements have been issued by multiple EU supervisory authorities including the Swedish IMY and the Irish Data Protection Commission.

What are sub-processors and how does Article 28 regulate them?

A sub-processor is a third party that a processor engages to carry out specific processing activities on the controller's behalf. Article 28(2) requires the processor to obtain prior specific or general written authorisation from the controller before engaging any sub-processor. Where general authorisation is granted, the processor must notify the controller of any sub-processor changes and give the controller an opportunity to object. Under Article 28(4), the processor must impose on every sub-processor the same data protection obligations as those set out in the controller-processor DPA, and the processor remains fully liable to the controller if the sub-processor fails to perform.

Does a DPA need to address international data transfers?

If the processor or any of its sub-processors will transfer personal data outside the EEA, the DPA must address Chapter V compliance. Article 28(3)(a) requires the DPA to cover any instruction to transfer data to a third country. Where a valid adequacy decision covers the destination, the DPA should identify it. Where no adequacy decision applies, the DPA must incorporate the relevant Chapter V mechanism, which for a controller-to-processor transfer is typically Module 2 of the 2021 Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914. The Article 28 SCCs and the international transfer SCCs can be combined in a single agreement.

What does 'documented instructions' mean in a GDPR DPA?

Article 28(3)(a) requires the processor to process personal data only on documented instructions from the controller. 'Documented' means written or otherwise recorded. The DPA itself constitutes the primary set of instructions, specifying the permitted processing operations, data categories, purposes, and retention periods. Ad-hoc instructions given during the course of the service relationship must also be documented to be valid. The final sentence of Article 28(3) places an obligation on the processor to immediately inform the controller if, in its opinion, any instruction infringes the GDPR or other applicable data protection law. A processor that follows an instruction it knows to be unlawful without flagging the issue risks losing the liability protection that compliance with documented instructions provides under Article 82(3).

Sources and References

  1. GDPR Regulation (EU) 2016/679, Articles 4, 28, 32, 33, 35, 82, and 83(eur-lex.europa.eu)
  2. Commission Implementing Decision (EU) 2021/914, Standard Contractual Clauses for International Transfers(eur-lex.europa.eu)
  3. Commission Implementing Decision (EU) 2021/915, Standard Contractual Clauses between Controllers and Processors(eur-lex.europa.eu)
  4. EDPB Guidelines 07/2020 on the Concepts of Controller and Processor under the GDPR(edpb.europa.eu)
  5. European Commission, Standard Contractual Clauses for Data Transfers(commission.europa.eu)
Share: