Guide · GDPR

What must a data processing agreement contain? GDPR Article 28(3), point by point

Updated 8 October 2026 · 7 min read

A data processing agreement is mandatory whenever a processor handles personal data for a controller, and GDPR Article 28(3) sets its minimum content. It must describe the processing and then bind the processor to eight points, from acting only on documented instructions to deleting or returning the data at the end and opening itself to audits.

Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.

Official text on EUR-Lex · Open the source

The figure behind it

GDPR Article 28 has 10 paragraphs; paragraph 3 alone lists 8 points, (a) to (h), that every controller-processor contract must stipulate. Source: Regulation (EU) 2016/679, Article 28, EUR-Lex text as held by Rekvira (corpus of 2 September 2026)

Everything quoted below came back from Rekvira's tools on 24 September 2026, from the EUR-Lex text of the GDPR (Regulation (EU) 2016/679). The UK GDPR keeps the same article numbers.

Is a data processing agreement mandatory?

Yes, whenever one organisation processes personal data on behalf of another. Article 28(1) makes the controller responsible for choosing the processor: it "shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures". Article 28(3) then requires the contract. A signed contract does not replace the first duty. You still have to judge the guarantees, and Article 28(5) lets an approved code of conduct or certification serve as evidence of them.

"DPA" is the market's name. The Regulation says "contract or other legal act under Union or Member State law", so a binding legal act under EU or national law can take the place of a contract.

What must the contract say about the processing?

The first sentence of Article 28(3) fixes five descriptive items, and each has to be filled in for the actual processing:

  • the subject-matter and duration of the processing
  • the nature and purpose of the processing
  • the type of personal data
  • the categories of data subjects
  • the obligations and rights of the controller

What are the eight required clauses?

Article 28(3) continues: the contract "shall stipulate, in particular, that the processor" does each of the following. "In particular" makes this a minimum, not a full list.

PointWhat the processor must doThe article's words
(a)Act only on documented instructions, including on transfers outside the EU"processes the personal data only on documented instructions from the controller"
(b)Bind its staff to confidentiality"persons authorised to process the personal data have committed themselves to confidentiality"
(c)Apply the security measures of Article 32"takes all measures required pursuant to Article 32"
(d)Follow the sub-processor rules"respects the conditions referred to in paragraphs 2 and 4 for engaging another processor"
(e)Help the controller answer data subject requests"assists the controller by appropriate technical and organisational measures, insofar as this is possible"
(f)Help with security, breach notification, DPIAs and prior consultation"assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36"
(g)Delete or return the data at the end, as the controller chooses"at the choice of the controller, deletes or returns all the personal data"
(h)Provide compliance information and allow audits"allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller"
GDPR Article 28(3), points (a) to (h), quoted from the read_unit call below. The middle column is our summary.

Two details in the text are easy to miss. Point (a) carries a disclosure duty: if the law obliges the processor to process data without an instruction, it "shall inform the controller of that legal requirement before processing", unless that law forbids it. And after the list, the article adds that the processor "shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation". A good contract names who receives that warning and how fast.

Point (f) is where the DPA meets your DPIA. Articles 32 to 36 include the data protection impact assessment and prior consultation, so the processor must supply what you need for them. When a DPIA is required under Article 35 walks through that duty.

How do sub-processors work?

Two paragraphs set the rules. The first is about permission:

"The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes." (Article 28(2))

The second is about the chain. Under Article 28(4) the processor must impose "the same data protection obligations" on the sub-processor by contract, and if the sub-processor fails, "the initial processor shall remain fully liable to the controller". In practice a general authorisation needs a notice mechanism and an objection window written into the DPA, or the objection right in 28(2) has nothing to work with.

  • 10

    paragraphs in GDPR Article 28

  • 8

    points, (a) to (h), every contract must stipulate

  • 5

    descriptive items the contract must set out first

Regulation (EU) 2016/679, Article 28, as returned by read_unit on 24 September 2026.

Does it have to be signed on paper?

No. Article 28(9) reads in full: "The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form." An agreement concluded electronically can meet the form requirement; whether its content meets paragraph 3 is a separate check.

You also do not have to draft from scratch. Article 28(6) allows the contract to be based "in whole or in part" on standard contractual clauses, which the Commission (Article 28(7)) or a supervisory authority (Article 28(8)) may adopt.

What if the processor decides how the data is used?

Then it stops being a processor for that processing. Article 28(10): "if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing." Article 29 repeats the underlying rule for everyone with access: no processing "except on instructions from the controller", unless the law requires it.

For ICT providers to banks and insurers, DORA adds its own contract requirements on top of Article 28. See DORA Article 28 on its own page.

Recorded run

The question:What must a data processing agreement contain under the GDPR?

  1. search_regulation(regulation="gdpr", query="contract between controller and processor what must it contain")

    Let the corpus rank the passages for the reader's own question.

    For the question as typed, the search ranked "Article 28(4)" first and "Article 28(6)" second; "Article 28(3)", the list of required clauses, came tenth of 25.

  2. read_unit(regulation="gdpr", kind="article", number="28")

    Read Article 28 whole, not a search excerpt.

    The whole article in 10 pinpointed paragraphs, including "shall stipulate, in particular, that the processor"

  3. lookup_obligations(regulation="gdpr", role="processor")

    Which articles name the processor as addressee.

    No article title names the processor together with the word obligation; the titles that name the role are listed instead, and "Article 28" is one of them.

  4. verify_citation(regulation="gdpr", citation="Article 28(3)", quote="Processing by a processor shall be governed by a contract or other legal act under Union or Member State law")

    Check the pinpoint and the exact sentence before quoting it.

    Quote found: the Article 28(3) sentence quoted at the top of this page is the held text.

  5. read_unit(regulation="gdpr", kind="article", number="29")

    The instruction rule that sits beside Article 28.

    "shall not process those data except on instructions from the controller"

  6. read_unit(regulation="gdpr", kind="recital", number="81")

    The recital behind the processor contract.

Real calls to Rekvira’s production server, captured 24 September 2026. Corpus as of 2 September 2026.

Limits

Rekvira returns the text of the Regulation with its pinpoint and the date of the text. It does not review your contract or say whether it complies; that judgement stays with you and your DPO or counsel. National law and supervisory authorities' standard clauses are not in the corpus.

Do this in your assistant

Read GDPR Article 28 with Rekvira. I will paste our data processing agreement. For each of Article 28(3) points (a) to (h), quote the article's words, then quote the clause in our agreement that covers it, or say that none does.

Paste this into Claude, ChatGPT, Cursor or any MCP client connected to https://mcp.rekvira.com/mcp. No account is needed to start.Install steps for each client

Start with the keyless trial.

No account, no API key, and free during the beta.

https://mcp.rekvira.com/mcp