GDPR Data Processor Contract
We review and strengthen GDPR data processor contract terms under Article 28
Common gaps in a GDPR data processor contract
3 mins read • Legal Writer • GDPR • 25 February 2026
The General Data Protection Regulation (GDPR) requires controllers to enter into a GDPR data processor contract with external parties that process personal data on their behalf. Despite this, contracts may contain deficiencies – a risk that the Data Protection Agency has identified in its supervisory work.
Under Article 28 GDPR, a data processor contract must regulate, among other things, the purposes of processing, instructions, security measures, sub-processors and responsibility for processing after the engagement has ended. In supervisory cases, the Data Protection Agency has found that contracts are missing entirely, or that the agreements fail to meet the basic requirements. Such deficiencies have resulted in administrative fines.
Recurring GDPR data processor contract issues identified in supervision
Even where a processor contract is in place, it does not always meet the minimum requirements under GDPR. Common deficiencies in processor contracts include:
- The purpose of the processing and the instructions are not clearly stated.
- Information security requirements are unclear or missing entirely.
- Sub-processors are not regulated, or are permitted without prior approval.
- There are no instructions on how personal data must be handled after the contract ends.
- Incident reporting and allocation of responsibility are not regulated.
- The processor terms are embedded in general terms and conditions without any reference to Article 28 GDPR.
To avoid deficiencies, each GDPR data processor contract must be reviewed specifically against the requirements of GDPR. This means that all mandatory points under Article 28 of the General Data Protection Regulation must be regulated in the agreement. General references to other documents, standard terms or the supplier’s own policy are not sufficient.
If the agreement is unclear or incomplete, both parties risk acting in breach of the General Data Protection Regulation. This applies in particular where it is unclear who is responsible for what, how instructions must be documented, or what requirements apply when sub-contractors are used. In such cases, the supervisory authority may determine that the parties are not complying with GDPR. It is therefore not enough merely to have an agreement in place – it must also be correctly drafted and followed in practice.
Key provisions in a data processing agreement GDPR review
Particular attention should be given to how the agreement regulates:
- The purpose of the processing and the processor’s instructions.
- The requirements for technical and organisational security measures.
- Rules for sub-processors, including the approval procedure.
- What must happen to the personal data when the processing ends, such as erasure or return of the data.
- Procedures for reporting personal data breaches.
A legally robust approach also requires the agreement to be documented, updated and actively monitored. The controller bears ultimate responsibility for ensuring that a valid data processor contract is in place – and that the processing is carried out in accordance with it.
At Morling Consulting, our GDPR lawyers help organisations across Europe draft compliant GDPR data processor contract terms, prepare a robust data processing agreement GDPR framework, and identify and remedy deficiencies in existing agreements.
The General Data Protection Regulation (GDPR) requires controllers to enter into a GDPR data processor contract with external parties that process personal data on their behalf. Despite this, contracts may contain deficiencies – a risk that the Data Protection Agency has identified in its supervisory work.
Under Article 28 GDPR, a data processor contract must regulate, among other things, the purposes of processing, instructions, security measures, sub-processors and responsibility for processing after the engagement has ended. In supervisory cases, the Data Protection Agency has found that contracts are missing entirely, or that the agreements fail to meet the basic requirements. Such deficiencies have resulted in administrative fines.
Recurring GDPR data processor contract issues identified in supervision
Even where a processor contract is in place, it does not always meet the minimum requirements under GDPR. Common deficiencies in processor contracts include:
- The purpose of the processing and the instructions are not clearly stated.
- Information security requirements are unclear or missing entirely.
- Sub-processors are not regulated, or are permitted without prior approval.
- There are no instructions on how personal data must be handled after the contract ends.
- Incident reporting and allocation of responsibility are not regulated.
- The processor terms are embedded in general terms and conditions without any reference to Article 28 GDPR.
To avoid deficiencies, each GDPR data processor contract must be reviewed specifically against the requirements of GDPR. This means that all mandatory points under Article 28 of the General Data Protection Regulation must be regulated in the agreement. General references to other documents, standard terms or the supplier’s own policy are not sufficient.
If the agreement is unclear or incomplete, both parties risk acting in breach of the General Data Protection Regulation. This applies in particular where it is unclear who is responsible for what, how instructions must be documented, or what requirements apply when sub-contractors are used. In such cases, the supervisory authority may determine that the parties are not complying with GDPR. It is therefore not enough merely to have an agreement in place – it must also be correctly drafted and followed in practice.
Key provisions in a data processing agreement GDPR review
Particular attention should be given to how the agreement regulates:
- The purpose of the processing and the processor’s instructions.
- The requirements for technical and organisational security measures.
- Rules for sub-processors, including the approval procedure.
- What must happen to the personal data when the processing ends, such as erasure or return of the data.
- Procedures for reporting personal data breaches.
A legally robust approach also requires the agreement to be documented, updated and actively monitored. The controller bears ultimate responsibility for ensuring that a valid data processor contract is in place – and that the processing is carried out in accordance with it.
At Morling Consulting, our GDPR lawyers help organisations across Europe draft compliant GDPR data processor contract terms, prepare a robust data processing agreement GDPR framework, and identify and remedy deficiencies in existing agreements.
GDPR lawyer
Do you need to review or update a GDPR data processor contract? Contact us and we will assess the agreement against Article 28 requirements
"*" indicates required fields