The General Data Protection Regulation (GDPR) obliges organisations that handle personal data to adopt strict safeguards and clear contractual relationships. Article 28 sets out the requirements for the relationship between a data controller and a data processor. Paragraph3 of this article details the specific content that must be included in a controllerprocessor agreement (CPA). This page explains the legal background, the mandatory clauses, bestpractice tips, and the consequences of noncompliance.
Under the GDPR, a controller determines the purposes and means of processing personal data, while a processor carries out processing on behalf of the controller. The regulator expects a written contract that:"
Without a valid CPA, the controller may be held liable for the processors actions, and the processor could face administrative fines. Moreover, the agreement is a key piece of evidence during supervisory authority investigations.
The regulation states that a controller must use a contract or other legal act "under Union or Member State law" that binds the processor to the controller and includes the following items:
The contract must clearly state what data will be processed, for which specific purposes, and for how long the processing will continue. This helps both parties verify that processing does not exceed the agreed scope.
Beyond the mere description of data types, the agreement must articulate the nature (e.g., collection, storage, analysis) and the purpose (e.g., marketing, fulfilment of contracts, employee management). This clause prevents mission creep where a processor expands activities without consent.
Specifying the categories of data subjects (customers, employees, suppliers) and the kind of personal data (identifiers, financial information, health data) is essential for risk assessment and for applying the correct security measures.
The processor must commit to:
If the processor wishes to engage subprocessors, the agreement must contain a clause that:
Any transfer of personal data outside the European Economic Area (EEA) must be governed by an appropriate legal mechanism (e.g., Standard Contractual Clauses, Binding Corporate Rules). The CPA must disclose the transfer mechanism and the safeguards in place.
While the GDPR does not prescribe a precise list of technical controls, the contract must reference a riskbased approach, covering:
The processor must agree to notify the controller without undue delay after becoming aware of a personal data breach. The CPA should set a maximum timeframe (commonly 2448hours) and identify the format of the notification.
When a data subject exercises rights (access, rectification, erasure, restriction, portability, objection), the processor must provide the controller with the necessary information or take direct action, as directed.
Upon termination of the contract, the processor must either return all personal data to the controller or securely delete it, unless EU or Member State law requires storage. The CPA should detail the method of deletion and any certification required.
If a CPA fails to contain the mandatory clauses of Article28(3), the following risks arise:
The following excerpt demonstrates how the mandatory elements can be combined into a single clause. It is provided for illustration; legal counsel should tailor it to each specific relationship.
1. SubjectMatter & Duration The Processor shall process the Personal Data described in AnnexA solely for the purposes set out in AnnexB and for the duration of the Services Agreement, unless earlier terminated in accordance with Clause12.2. Nature, Purpose & Types of Data Processing shall consist of collection, storage, analysis and reporting of the categories of Data Subjects listed in AnnexA, in order to enable the Controller to fulfil contractual obligations with its customers.3. Obligations of the Processor a) Process only on documented instructions from the Controller; b) Implement the technical and organisational measures set out in AnnexC; c) Ensure that persons authorised to process the Data are subject to confidentiality obligations; d) Assist the Controller with DPIAs, breach notifications and datasubject requests; e) Not engage subprocessors without prior written authorisation from the Controller; f) Promptly notify the Controller of any personal data breach no later than 24hours after detection....
Article28(3) of the GDPR makes it clear that a controllerprocessor relationship cannot rely on informal understandings. A welldrafted CPA protects both parties, demonstrates compliance, and provides a defensible record if a supervisory authority intervenes. By embedding the twelve mandatory elements, supplementing them with concrete technical specifications, and reviewing the agreement regularly, organisations can manage dataprotection risk while maintaining the flexibility needed for modern digital operations.
For further reading, consult the text of the GDPR and the guidance issued by the European Data Protection Board (EDPB) on processor contracts.
