Privacy (international)

GDPR Article 28 — Processors & Sub-processors

Article 28 of the GDPR governs the relationship between a controller and any processor that handles personal data on its behalf. Processing must be governed by a binding contract that imposes specific security and confidentiality duties.

Official source (opens in a new tab): Regulation (EU) 2016/679, Article 28

Scope

Who it applies to.

Article 28 binds a relationship between two roles the GDPR defines separately: the controller, which determines the purposes and means of processing (Article 4(7)), and the processor, which processes personal data on the controller’s behalf (Article 4(8)). Territorial reach comes from Article 3: it covers processing by an establishment in the Union wherever the processing itself happens, and non-EU controllers and processors offering goods or services to, or monitoring the behaviour of, people in the Union. A firm holding its own client files is normally a controller.

Use only processors that can prove their guarantees
Article 28(1) permits a controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. This is a selection duty that bites before any data moves: you have to assess the processor, not merely take its word. Article 28(5) lets adherence to an approved code of conduct (Article 40) or certification (Article 42) serve as one element demonstrating those guarantees — an element, not a substitute.
Put the processing under a written contract
Article 28(3) requires a contract or other binding legal act setting out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the controller’s obligations and rights. Article 28(9) requires it in writing, including electronic form. The Commission adopted standard contractual clauses for this purpose in Implementing Decision (EU) 2021/915.
Confine the processor to documented instructions
Under Article 28(3)(a) the processor must process personal data only on documented instructions from the controller, including as to transfers to a third country, unless Union or Member State law requires otherwise. Article 28(10) supplies the sanction: a processor that infringes the Regulation by determining the purposes and means of processing is treated as a controller for that processing.
Authorise and control the sub-processor chain
Article 28(2) bars a processor from engaging another processor without prior specific or general written authorisation; under a general authorisation it must inform you of intended additions or replacements and give you the opportunity to object. Article 28(4) requires the same data-protection obligations to be imposed downstream, and leaves the initial processor fully liable to you for the sub-processor’s performance.
Preserve audit and information rights
Article 28(3)(h) obliges the processor to make available all information necessary to demonstrate compliance with Article 28, and to allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Article 28(3)(f) separately requires it to assist you with your own Articles 32 to 36 duties — security, breach notification, and impact assessments.
Return or delete the data at the end of the service
Article 28(3)(g) requires the processor, at your choice, to delete or return all personal data after the end of the provision of services relating to processing, and to delete existing copies unless Union or Member State law requires storage. Article 28(3)(b) separately requires that persons authorised to process the data have committed themselves to confidentiality or are under a statutory confidentiality duty.

The vendor & sub-processor obligation

What it puts on you.

A processor cannot engage a sub-processor without authorization, and must flow the same data-protection obligations down to every sub-processor — leaving the controller accountable for a whole chain of parties. Each cloud or AI service, and each of their subcontractors, extends that chain.

the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
GDPR Article 28(1) (official text)

How self-hosting addresses it

Remove the third party, remove the burden.

Keeping personal data on a system you operate inside your own perimeter means there is no external processor — and therefore no sub-processor chain to authorize, contract, and supervise for that processing.

How FileFerret applies

When indexing, search, and AI inference all run on hardware inside your own network, no outside party processes the personal data on your behalf — so no Article 28(3) contract, no Article 28(2) sub-processor authorisation, and no Article 28(4) flow-down chain arises for that processing. Your own controller duties — lawful basis, Article 32 security, data-subject rights — are untouched. See how it’s built →

Full, current text is maintained at the official source: Regulation (EU) 2016/679, Article 28.

Enforcement

Who enforces it, and how.

Enforcement sits with the national supervisory authorities, whose corrective powers under Article 58(2) include reprimands, orders to bring processing into compliance, and a temporary or definitive limitation — including a ban — on processing. Those powers reach processors directly, not only controllers. Article 83 sets two fine tiers; Article 28 sits in the lower one, because Article 83(4)(a) covers obligations pursuant to Articles 25 to 39: up to €10 million, or 2 percent of total worldwide annual turnover of the preceding financial year, whichever is higher.

Common questions

Questions firms ask.

Article 28 is in the lower fine tier — does that make it a minor exposure?

The tier is lower, but it is not the whole picture. Article 58(2) lets a supervisory authority order processing stopped outright, and Article 82(1) gives data subjects a right to compensation for material or non-material damage. A processor acting outside your instructions can also put the underlying processing in breach of Articles 5 and 6, which do sit in the €20 million / 4 percent tier under Article 83(5).

Can we satisfy Article 28(3) by pasting its list of duties into our vendor agreement?

Only partly. The opening of Article 28(3) requires the contract to set out the subject-matter, duration, nature and purpose of the processing, the type of personal data, and the categories of data subjects — facts specific to your engagement that generic wording cannot supply. The Commission’s standard contractual clauses in Implementing Decision (EU) 2021/915 are drafted to meet Article 28(3) and (4), with annexes you complete.

What happens if an AI vendor uses our client data to improve its own models?

That is the scenario Article 28(10) addresses. If a processor infringes the Regulation by determining the purposes and means of processing, it is considered a controller for that processing — so reuse beyond your documented instructions under Article 28(3)(a) can recharacterise the vendor and leave it directly answerable. That does not retire your own controller duties over the disclosure.

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.