UK

UK GDPR: Processors (Article 28)

Processor Requirements [Art 28]

Key requirement: A written contract is mandatory between controller and processor.

Rule: Controllers can only use processors that provide sufficient guarantees, and must have a written contract in place.

Controller obligations [Art 28(1)]

RequirementDetailsCitation
Use only compliant processorsSufficient guarantees of appropriate measuresArt 28(1)
Written contract requiredOr other legal actArt 28(3)
Authorise sub-processorsProcessor needs written authorisationArt 28(2)

Required contract terms [Art 28(3)]

The contract must set out:

TermWhat it coversCitation
Subject-matter and durationScope of processingArt 28(3)
Nature and purposeWhat processing is forArt 28(3)
Type of personal dataCategories of dataArt 28(3)
Categories of data subjectsWhose dataArt 28(3)
Controller obligations and rightsController’s responsibilitiesArt 28(3)

Processor obligations in contract [Art 28(3)(a-h)]

ObligationDetailsCitation
Process only on instructionsDocumented instructions from controllerArt 28(3)(a)
ConfidentialityEnsure persons processing are confidentialArt 28(3)(b)
Security measuresTake all measures per Article 32Art 28(3)(c)
Sub-processor conditionsSame data protection obligationsArt 28(3)(d)
Assist with data subject rightsHelp controller respond to requestsArt 28(3)(e)
Assist with security obligationsHelp with Arts 32-36Art 28(3)(f)
Delete or return dataAt end of servicesArt 28(3)(g)
Allow auditsMake available information, allow auditsArt 28(3)(h)

Sub-processors [Art 28(2), (4)]

ScenarioRequirementCitation
General authorisationController gives general written authorisationArt 28(2)
Specific authorisationController authorises each sub-processorArt 28(2)
Notification of changesInform controller, opportunity to objectArt 28(2)
Same obligationsSub-processor contract must mirror main contractArt 28(4)
Processor remains liableFor sub-processor’s performanceArt 28(4)

Source Text

Article 28(1): Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.

Article 28(3): Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:

(a) processes the personal data only on documented instructions from the controller…

(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality…

(c) takes all measures required pursuant to Article 32;

(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;

(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights…

(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing…

(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

Citation

Article 28, UK GDPR

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt