UK GDPR Article 28(3): what a processor contract must say
By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 8 min read
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Short answer
UK GDPR Article 28 requires a written contract whenever a supplier processes personal data on your firm’s behalf as a processor. The contract must set out four details of the processing and eight terms, points (a) to (h): documented instructions, confidentiality, security, sub-processors, help with rights requests, help with security and breach duties, deletion or return, and audits.
This explainer is for the person in a small accounting, advice or immigration firm who signs software and AI supplier contracts. Article 28 matters now because the Data (Use and Access) Act 2025 amended its wording, and the Information Commission replaced the Information Commissioner’s Office (ICO) on 30 September 2026. VexraLabs sits on the other side of this contract: we are a supplier outside the UK, so we have to offer these terms ourselves. The sections below list every required term, the rules in Article 28(1), 28(2), 28(4) and 28(9), a clause checklist to copy, and the extra step for overseas suppliers.
What is an Article 28 processor contract?
An Article 28 processor contract is the written agreement that binds a supplier to handle personal data only as your firm instructs. It is often called a data processing agreement (DPA). Article 28(3)says processing by a processor “shall be governed by a contract or other legal act” that is binding on the processor.
The duty applies every time a controller uses a processor, whatever the size of either party. The regulator’s guidance says that in the UK a contract is likely to be the appropriate means, not some other legal act, and that a set of contracts can meet the rule if the processor is ultimately bound to each controller. The DPA is often a schedule to the main services agreement or to the supplier’s online terms.
Who is the controller, the processor and the sub-processor?
The controller is your firm, the processor is the supplier, and a sub-processor is a supplier your supplier uses. Article 4(7) defines a controller as the body that determines the purposes and means of processing personal data. Article 4(8) defines a processor as a body that processes personal data on behalf of the controller.
“Sub-processor” is shorthand for another processor engaged by the processor. The regulator notes that the term is not taken from the UK GDPR itself. A cloud host or an AI model provider behind your software supplier is a sub-processor when it processes your clients’ personal data. The roles follow the facts: under Article 28(10), a processor that determines the purposes and means of processing is treated as a controller for that processing.
What must the contract set out about the processing?
The opening words of Article 28(3) require the contract to set out four details of the processing:
- The subject-matter and duration of the processing.
- The nature and purpose of the processing.
- The type of personal data and the categories of data subjects.
- The obligations and rights of the controller.
These details usually sit in a schedule. A supplier that cannot fill the schedule in has not yet understood what it will do with your clients’ data. The regulator says the controller needs to be very clear from the outset about the extent of the processing it is contracting out.
What eight terms does Article 28(3) require?
Article 28(3) requires the contract to stipulate eight things about the processor, in points (a) to (h). The table gives each one in the order of the legislation.
| Point | The contract must say that the processor… | Detail in the text |
|---|---|---|
| (a) Instructions | Processes the personal data only on documented instructions from the controller | Covers transfers to a third country or international organisation. The one exception is where domestic law requires the processing; the processor then informs the controller first, unless that law prohibits it on important grounds of public interest. |
| (b) Confidentiality | Ensures that persons authorised to process the data have committed themselves to confidentiality | Or are under an appropriate statutory obligation of confidentiality. |
| (c) Security | Takes all measures required pursuant to Article 32 | Article 32 is the security of processing duty. |
| (d) Sub-processors | Respects the conditions in Article 28(2) and 28(4) for engaging another processor | Written authorisation first; the same obligations passed down. |
| (e) Rights requests | Assists the controller, by appropriate technical and organisational measures, to respond to requests to exercise data subjects' rights under Chapter III | Taking into account the nature of the processing, and insofar as this is possible. |
| (f) Security, breaches, DPIAs | Assists the controller in ensuring compliance with Articles 32 to 36 | Taking into account the nature of processing and the information available to the processor. |
| (g) End of contract | Deletes or returns all the personal data, at the choice of the controller, after the end of the services, and deletes existing copies | Unless domestic law requires storage of the personal data. |
| (h) Audits | Makes available all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections | Audits are conducted by the controller or another auditor mandated by the controller. |
One more sentence follows point (h). The processor “shall immediately inform the controller if, in its opinion, an instruction infringes” the UK GDPR or other domestic law relating to data protection. Put that sentence in the contract too.
Articles 32 to 36, named in point (f), cover security, notifying a personal data breach to the regulator and to the people affected, the data protection impact assessment (DPIA) and prior consultation. So point (f) is what obliges a supplier to help with a DPIA for AI tools. The regulator recommends that the contract is as clear as possible about how the processor will help.
What do Article 28(1), 28(2), 28(4) and 28(9) add?
These four paragraphs set the rules around the contract: who you may appoint, how sub-processors are approved, what passes down the chain, and the form of the contract.
- Article 28(1), choosing the supplier.The controller “shall use only processors providing sufficient guarantees” to implement appropriate technical and organisational measures, so that processing meets the UK GDPR and protects data subjects’ rights. The check comes before the signature.
- Article 28(2), authorising sub-processors.The processor shall not engage another processor without the controller’s prior specific or general written authorisation. Under a general authorisation, the processor informs the controller of any intended addition or replacement, which gives the controller the opportunity to object.
- Article 28(4), passing obligations down.The processor imposes “the same data protection obligations” on the sub-processor by contract. If the sub-processor fails, the initial processor “shall remain fully liable to the controller”.
- Article 28(9), form.Both contracts “shall be in writing, including in electronic form”.
Two further paragraphs are optional routes. Article 28(5) lets a processor use an approved code of conduct or certification as “a means of demonstrating” sufficient guarantees; the Data (Use and Access) Act 2025 substituted those words on 20 August 2025. Article 28(6) and 28(8) let the contract rest on standard contractual clauses adopted by “the Commission”, the word substituted on 30 September 2026.
What does Article 28(3) not require?
Article 28(3) sets a minimum, and three terms firms expect to find there come from elsewhere. The regulator says the eight terms are the minimum required, and the parties are free to add their own.
- A breach deadline in hours. Article 33(2)places a direct duty on the processor to notify the controller “without undue delay” after becoming aware of a personal data breach. A fixed number of hours is a commercial term to negotiate.
- A record-keeping clause.The regulator’s guidance says the UK GDPR does not require a clause making the processor keep records of its processing; Article 30(2) imposes that duty on processors directly.
- Liability caps, indemnities and price. Article 28 says nothing about them. The guidance calls the commercial aspects a matter for the parties.
Clause checklist to hold a software or AI supplier to
The 14 clauses below restate Article 28 as plain contract terms. Clauses 1 to 11 track the Article. Clauses 12 to 14 go beyond its minimum and are marked. This is a starting point to adapt with your own adviser, not a finished agreement.
- Schedule: the subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.
- The Supplier processes the personal data only on the Firm’s documented instructions, including for any transfer outside the UK.
- If UK law requires other processing, the Supplier tells the Firm before it processes, unless that law prohibits this on important grounds of public interest.
- The Supplier tells the Firm immediately if it believes an instruction infringes UK data protection law.
- Everyone the Supplier authorises to process the data is bound by a confidentiality commitment or a statutory duty of confidentiality.
- The Supplier takes all measures required by Article 32 of the UK GDPR. Schedule: the measures in place.
- The Supplier engages no sub-processor without the Firm’s prior written authorisation. Schedule: authorised sub-processors. The Supplier gives notice of any intended addition or replacement, and the Firm may object.
- The Supplier binds each sub-processor in writing to the same data protection obligations, and remains fully liable to the Firm for each sub-processor’s performance.
- The Supplier assists the Firm, by appropriate technical and organisational measures, to respond to data subject requests, and assists with security, breach notification, DPIAs and prior consultation (Articles 32 to 36).
- When the services end the Supplier deletes or returns all personal data, as the Firm chooses, and deletes existing copies unless UK law requires storage.
- The Supplier gives the Firm all information needed to demonstrate compliance with Article 28, and allows and contributes to audits and inspections by the Firm or its appointed auditor.
- Beyond the minimum: the Supplier notifies the Firm of a personal data breach without undue delay, and within an agreed number of hours.
- Beyond the minimum, for AI features: the Supplier does not use the Firm’s personal data to train or improve models, and each AI model provider is listed as a sub-processor.
- Beyond the minimum, for a Supplier outside the UK: the parties sign a transfer safeguard before any personal data is sent or made accessible.
Clause 13 has no wording of its own in Article 28. It applies points (a) and (d): training a model on client data is processing outside your instructions unless you instruct it, and a model provider is another processor. An AI policy for UK firms names the tools staff may use, and this contract is the condition for a tool to go on that list.
What changes when the supplier is outside the UK?
A supplier outside the UK needs the Article 28 contract and a transfer mechanism, because giving it access to personal data is a restricted transfer. The regulator uses “restricted transfer” for sending personal information, or making it accessible, to a separate organisation located outside the UK.
Article 44A allows such a transfer only if regulations approve it, appropriate safeguards cover it, or a derogation applies. Standard data protection clauses issued by the regulator are one safeguard under Article 46(2)(d). The International Data Transfer Agreement (IDTA) is one of two sets it has issued, and the firm sending the data also completes a transfer risk assessment.
This is our own position. VexraLabs is a two-person team in Pakistan. When we build a system that holds a UK firm’s client data, the firm is the controller, we are the processor, and our access from Pakistan is a restricted transfer. So we will provide and sign a data processing agreement and the UK IDTA before any work on client data starts. The eight terms are fixed by the Article. The hard part is the schedule: the list of data types and sub-processors has to be true for the system actually built.
What happens if the contract is missing?
A missing or incomplete contract is an infringement of Article 28 by the controller and by the processor. Article 83(4)(a)sets the maximum fine for breaching Articles 25 to 39 at £8,700,000 or, for an undertaking, 2% of total worldwide annual turnover of the preceding financial year, whichever is higher.
That figure is a ceiling, not a tariff. The practical cost arrives sooner: without the contract a firm has no agreed right to audit the supplier, to get its data back, or to learn which sub-processors hold it.
The processor contract is one of several controls on a supplier. Our pillar guide, AI in regulated industries: UK rules and human review, sets out the wider rules it sits within, and why we have a person sign off everything AI drafts. Firms regulated by the Financial Conduct Authority should also check the FCA outsourcing rules (SYSC 8): they are binding rules for some firms and guidance for others, and they add outsourcing terms on top of Article 28. Our services and prices page shows the work we would do under these contracts.
Frequently asked questions
Is a data processing agreement the same as an Article 28 contract?
Yes. Data processing agreement (DPA) is the common name for the contract Article 28(3) requires between a controller and a processor. It is often a schedule to the main services agreement.
Does a processor contract need a paper signature?
No. Article 28(9) says the contract shall be in writing, including in electronic form.
Can a supplier add sub-processors without asking?
No. Article 28(2) requires the controller's prior specific or general written authorisation. Under a general authorisation the supplier gives notice of any intended addition or replacement, and the controller has the opportunity to object.
Is there an official UK data processing agreement template?
Article 28(8) lets the Information Commission adopt standard contractual clauses, and Article 28(6) lets a contract be based on them. As checked on 8 October 2026, no UK set has been adopted. The regulator's guidance points to the Danish SCCs approved by the European Data Protection Board, which it says should comply with Article 28 if used without amendment, and its brief guide has a checklist of the required terms.
Does Article 28 apply to AI tools?
Yes, when the tool's supplier processes personal data on your firm's behalf. The supplier is then a processor, and any model provider it uses is a sub-processor that needs authorisation under Article 28(2).
Sources
- UK GDPR Article 28 (processor), legislation.gov.uk
- UK GDPR Article 4 (definitions), legislation.gov.uk
- UK GDPR Article 33 (notification of a personal data breach), legislation.gov.uk
- UK GDPR Article 44A (general principles for transfers), legislation.gov.uk
- UK GDPR Article 46 (transfers subject to appropriate safeguards), legislation.gov.uk
- UK GDPR Article 83 (administrative fines), legislation.gov.uk
- Data (Use and Access) Act 2025, section 118 (abolition of the office of Information Commissioner), legislation.gov.uk
- Regulator guidance: What needs to be included in the contract?, ico.org.uk
- Regulator guidance: Contracts and liabilities between controllers and processors (overview), ico.org.uk
- Regulator guidance: Contracts (brief guide, with the checklist of required terms), ico.org.uk
- Regulator guidance: When is a contract needed and why is it important?, ico.org.uk
- Regulator guidance: A brief guide to international transfers, ico.org.uk
- Regulator guidance: Standard data protection clauses (the UK IDTA and the Addendum), ico.org.uk