GDPR Article 28 outlines the relationship between data controllers and data processors—requiring a shared contract that defines how the processor will handle data provided by the controller.
This contract must include language that limit how, when, and why data can be processed, including:
In 2017, the Information Commissioner’s Office (ICO) published additional guidelines for contracts between data controllers and data processors, stating they should include:
The contract between data controllers and processors is binding and must protect a data subject's rights.