Article 28 Requirements
Article 28 Requirements refer to the obligations set out in Article 28 of the EU General Data Protection Regulation (GDPR) that govern the relationship between a data controller and a data processor. They require, among other things, a written contract that sets rules for how the processor handles personal data, when and how it may use sub-processors, and how it supports the controller's compliance duties. In practice, these requirements shape the terms organizations put in place when engaging third parties that process personal data on their behalf.
Article 28 of the GDPR sets out the conditions under which a processor may process personal data on behalf of a controller, most notably the requirement for a binding written agreement (commonly a data processing agreement, or DPA) governing the processing. Per the evidence, its scope includes documented processing instructions, confidentiality obligations, security measures, support for the controller's compliance obligations, and controls on engaging sub-processors: a processor shall not engage another processor without prior specific or general written authorisation of the controller, and in the case of general written authorisation must inform the controller of intended changes. These requirements are specific to the controller-processor relationship for personal data under GDPR and do not, on their own, address financial, operational, geopolitical, or broader ESG risk, nor do they extend GDPR obligations beyond parties within its material and territorial scope. The presence of an Article 28-compliant contract or a processor's attestation to these obligations is a contractual and documentation control; it does not by itself constitute independent verification of the processor's actual practices, and obligations may be interpreted and enforced differently across EU member-state supervisory authorities. Note that 'Article 28' also appears in unrelated legal contexts (for example, Article 28 of New York Public Health Law governing hospitals and clinics), which is distinct from the GDPR provision and should not be conflated with it.
Why it matters
Most organizations do not process personal data entirely in-house; they rely on third parties such as cloud hosting providers, payroll services, marketing platforms, and analytics vendors that handle personal data on their behalf. Article 28 of the GDPR is the provision that governs these controller-processor relationships, requiring a binding written contract (commonly a data processing agreement, or DPA) before a processor handles personal data. For third-party risk and procurement teams, this makes Article 28 a foundational checkpoint in onboarding any vendor that touches personal data within the GDPR's scope: without a compliant agreement in place, the controller may be unable to demonstrate that its processing arrangements meet regulatory expectations.
Article 28's requirements also extend visibility one layer deeper into the supply chain. Because a processor cannot engage a sub-processor without the controller's prior specific or general written authorisation, and because under general authorisation the processor must inform the controller of intended changes, the provision gives controllers a contractual mechanism to track and object to changes among fourth parties. This is significant given that limited visibility beyond the first tier is a persistent challenge in supply chain risk management, though the mechanism is only as effective as the controller's ability to actually monitor and act on the notifications it receives.
It is important not to overstate what an Article 28-compliant contract achieves. The presence of a DPA or a processor's attestation to Article 28 obligations is a contractual and documentation control; it does not by itself independently verify that the processor's actual security and handling practices match its commitments. It also addresses only personal data under GDPR and does not, on its own, cover financial, operational, geopolitical, or broader ESG risk associated with the same third party. Organizations that treat a signed DPA as evidence of verified compliance rather than as a starting point for ongoing oversight may carry more residual risk than they assume.
Who it's relevant to
Inside Article 28 Requirements
Common questions
Answers to the questions practitioners most commonly ask about Article 28 Requirements.
