Regulation (EU) 2016/679 (General Data Protection Regulation)
- Document
- 4 May 2016
- Event
- 25 May 2018
- Retrieved
- 16 September 2026
The workload
Any business that hands personal data to a vendor to process on its behalf, an email provider, a hosting platform, a support-desk tool, takes on the work of putting a written contract in place with that vendor before data starts flowing, not after. Article 28 of the GDPR makes this a duty of the controller: it may use only processors providing sufficient guarantees to meet the regulation's requirements, and that arrangement must be governed by a contract or other legal act setting out specific terms, not a general assurance on a vendor's sales page.
What the documents show
Verified: Article 28(3) lists what the contract must cover, including that the processor acts only on the controller's documented instructions, keeps personnel under confidentiality, implements the security measures Article 32 requires, assists with data-subject rights requests, deletes or returns data at the end of the engagement, and makes information available to demonstrate compliance. Verified: Article 28(2) requires the processor to obtain the controller's prior authorisation, general or specific, before engaging a sub-processor. Verified: Article 28(6) to (8) allow the contract to rely, in whole or in part, on standard contractual clauses, but the article does not state that using a vendor's own standard-form data-processing agreement automatically satisfies every requirement; that depends on whether the specific document actually contains the Article 28(3) terms. A secondary, unofficial rendering of the article's text, consulted for cross-reference, mirrors the same paragraph structure without adding independent legal authority.
The operating cost
The regulation sets no fee for compliance; the cost is the time to read a vendor's agreement against the Article 28(3) list, or, where a vendor refuses to sign one, the time to find a different vendor. Neither source prices that labour, and enforcement cost is a separate question governed by the GDPR's fine provisions, which sit outside Article 28 and are not addressed here.
The stop condition
Editorially, since Article 28 does not name a review interval: a reasonable practice is to re-check a signed agreement whenever the processing relationship changes materially, a new sub-processor is added, the categories of data processed change, or the vendor updates its standard terms, rather than treat a document signed once as permanently sufficient.
- Does the vendor's own agreement actually contain each of the Article 28(3) items, or only a subset dressed as a complete document?
- Has the vendor disclosed its sub-processors, and does the contract require notice before adding a new one, per Article 28(2)?
- If the vendor relies on standard contractual clauses under Article 28(7) to (8), which version, and does it match the current one?
A signed processing agreement is evidence of an attempt to comply, not proof of it. Article 28 names what the document must contain; whether a specific vendor's form actually contains it is a reading exercise, not a formality to skip.
Sources & reading trail
The regulation's own text of Article 28, paragraphs 1-8, listing the mandatory contents of a controller-processor contract and the conditions for engaging a sub-processor.
Source published: 4 May 2016 · Retrieved: 16 September 2026
An unofficial mirror of the Article 28 text, consulted only to cross-check paragraph structure against the official eur-lex version.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.