Article 28 is one of the GDPR's most operationally significant provisions for enterprises that rely on vendors, SaaS platforms, or service providers to process customer data on their behalf. It requires a formal Data Processing Agreement (DPA) between the controller (the company that determines why data is processed) and any processor (a third party that processes data on the controller's instructions).
The DPA must specify the subject matter, duration, nature, and purpose of processing, the type of personal data involved, and the rights and obligations of both parties. Processors are prohibited from engaging sub-processors without prior written authorization from the controller.
Article 28 compliance requires enterprises to maintain an accurate, up-to-date inventory of all vendors with access to personal data, a task that grows significantly more complex as organizations adopt more SaaS tools, AI systems, and third-party integrations. Failures here have resulted in significant GDPR enforcement actions, particularly when processors experience data breaches and controllers cannot demonstrate adequate contractual oversight.