← GDPR · Controller obligations

Art.28 — Processors and processing agreements

critical vendor-managementthird-party

Requirement

Processing by a processor shall be governed by a contract setting out the subject matter, duration, nature and purpose of processing, the obligations in Article 28(3), and the requirement for prior authorisation of sub-processors.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
processorsub-processorsubprocessorvendorthird party
Required element 2 — any one of
data processing agreementdpacontractwritten agreementarticle 28contractual
Supporting terms — specificity signals
sub-processor listprior authorisationaudit rightassist with requestsdelete on terminationconfidentiality
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no data processing agreement no sub-processor list

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA 1798.100(d) Contracts with service providers, contractors and third parties vendor-management third-party
SOC 2 CC9.2 Vendor and business partner risk management vendor-management third-party
ISO 27001 A.5.19 Information security in supplier relationships vendor-management third-party
PCI DSS 4.0.1 12.8 Third-party service provider management vendor-management third-party
HIPAA 164.308(b)(1) Business associate contracts (R) vendor-management third-party
GLBA 314.4(f) Oversight of service providers vendor-management third-party
NIST CSF 2.0 GV.SC-03 Supply chain risk management is integrated vendor-management third-party
NDPA 2023 s.29 Data processor engagement vendor-management third-party