BLOG · 2026-06-25
GDPR Article 28: the data processing agreement almost nobody verifies
Every supplier that handles your data needs a processing agreement. What Article 28 GDPR requires, the AEPD fines, and how to comply.
Quick summary
- Article 28 of the GDPR requires a written data processing agreement (DPA) with every third party that processes personal data on your company's behalf.
- Without that contract, the processing is unlawful, no matter how reputable the supplier.
- The contract isn't enough: as the controller you must verify the supplier's guarantees before granting access (due diligence).
- The Article 28 penalty regime reaches up to €10M or 2% of annual global turnover, whichever is higher.
- Typical processors include your cloud ERP, IT support, payroll firm and email-marketing provider.
What is a data processor?
It's any third party that processes personal data on your company's behalf, following your instructions. You decide the purposes and means (you're the controller); they execute (they're the processor).
Everyday examples: your cloud software provider, the IT support company with remote access, the firm that runs your payroll, the email-marketing tool. If that processor in turn hires another (for example, the cloud infrastructure where it's hosted), that party is a sub-processor, and must also be documented and authorised.
What does Article 28 force you to sign?
A written contract (DPA) stating, as a minimum: subject matter, duration, nature and purpose of the processing; data types and categories of data subjects; the controller's instructions; confidentiality; security measures; the sub-processor regime; assistance with rights and breaches; international transfers (with their assessment where relevant); and return or deletion at the end.
Why isn't having the contract enough?
Because the GDPR also requires due diligence: as the controller you must only use processors offering sufficient guarantees, and check it before opening the door to the data. The authority has fined companies precisely for not verifying who they gave access to.
Multiply that by the number of suppliers handling data in a mid-sized company — 50, 100, 200 relationships, each with its sub-processors, expiries and transfers — and managing it in a spreadsheet stops being viable. That's exactly what an inspection treats as "failing to demonstrate due diligence".
How much does ignoring it cost?
The Article 28 penalty regime reaches €10M or 2% of global turnover. There are precedents in Spain of six-figure fines for giving a supplier access to data without a signed processing agreement, and significant cases over poor management of processors and sub-processors. This is the clock already running today, not the one in the future.
Keep reading
Was this article useful? Let's talk.
