NUDAYOSH

BLOG · 2026-06-25

GDPR Article 28: the data processing agreement almost nobody verifies

Every supplier that handles your data needs a processing agreement. What Article 28 GDPR requires, the AEPD fines, and how to comply.

Quick summary

  • Article 28 of the GDPR requires a written data processing agreement (DPA) with every third party that processes personal data on your company's behalf.
  • Without that contract, the processing is unlawful, no matter how reputable the supplier.
  • The contract isn't enough: as the controller you must verify the supplier's guarantees before granting access (due diligence).
  • The Article 28 penalty regime reaches up to €10M or 2% of annual global turnover, whichever is higher.
  • Typical processors include your cloud ERP, IT support, payroll firm and email-marketing provider.

What is a data processor?

It's any third party that processes personal data on your company's behalf, following your instructions. You decide the purposes and means (you're the controller); they execute (they're the processor).

Everyday examples: your cloud software provider, the IT support company with remote access, the firm that runs your payroll, the email-marketing tool. If that processor in turn hires another (for example, the cloud infrastructure where it's hosted), that party is a sub-processor, and must also be documented and authorised.

What does Article 28 force you to sign?

A written contract (DPA) stating, as a minimum: subject matter, duration, nature and purpose of the processing; data types and categories of data subjects; the controller's instructions; confidentiality; security measures; the sub-processor regime; assistance with rights and breaches; international transfers (with their assessment where relevant); and return or deletion at the end.

Why isn't having the contract enough?

Because the GDPR also requires due diligence: as the controller you must only use processors offering sufficient guarantees, and check it before opening the door to the data. The authority has fined companies precisely for not verifying who they gave access to.

Multiply that by the number of suppliers handling data in a mid-sized company — 50, 100, 200 relationships, each with its sub-processors, expiries and transfers — and managing it in a spreadsheet stops being viable. That's exactly what an inspection treats as "failing to demonstrate due diligence".

How much does ignoring it cost?

The Article 28 penalty regime reaches €10M or 2% of global turnover. There are precedents in Spain of six-figure fines for giving a supplier access to data without a signed processing agreement, and significant cases over poor management of processors and sub-processors. This is the clock already running today, not the one in the future.

Keep reading

Was this article useful? Let's talk.

Do you know how many of your suppliers expose you today?

We make it clear: how many handle data, embed AI, or access your systems, and for how many you have an up-to-date contract and verification. GDPR, AI Act and NIS2 in a single record.

Ask us for details →

We'll reply with a first diagnosis of your supplier exposure · hola@nudayosh.com

Frequently asked questions

About Article 28 GDPR and data processing agreements.

Is my cloud software provider a data processor?

Yes, if it processes personal data on your behalf. The SaaS provider, IT support, the payroll firm and email marketing are typical processors under Article 28 GDPR.

What happens if I work with a supplier without a processing agreement?

The processing is unlawful even if everything works. There are precedents in Spain of fines for giving an IT supplier access to data without a signed DPA.

Do I have to control sub-processors too?

Yes. You must know and authorise sub-processors, such as the cloud infrastructure, and impose the same obligations on them through a change-notification mechanism.

Is an old processing agreement still valid?

Not automatically. Agreements predating the GDPR had to be adapted to Article 28; generic references to the regulation are not valid.

How do I verify a supplier's guarantees?

By assessing and documenting its security measures, certifications, breach-notification capability, reliability and the location of the processing because of its implications for international transfers.