Get Demo
↑

GDPR Data Processing Agreement (Article 28): Template and Checklist

Article 28 requires a binding processor contract covering instructions, security, sub-processors, assistance with rights, breach notice.

Published: September 2026 Compliance · GDPR 8–12 min read

When a processor processes personal data on a controller’s behalf, Article 28 requires a binding contract (the Data Processing Agreement). Controllers must use only processors that provide sufficient guarantees.

CyberSilo’s own processor terms live at cybersilo.tech/dpa. This page is the educational template/checklist for your broader vendor estate.

Related: GDPR hub · GDPR for SaaS · RoPA.

Art 28 essentials: documented instructions, confidentiality, Art 32 security, sub-processor authorisation and flow-down, assistance with rights/DPIA/breach, audit/information rights, and deletion or return at end of service.

Article 28 Checklist

Template Section Headings

Use these headings in counsel-reviewed agreements: Definitions · Processing details (annex) · Instructions · Security · Sub-processors · International transfers (Chapter V) · Assistance · Breach notice timelines · Audit · Term & deletion · Liability / insurance (commercial).

How CyberSilo Helps

Close the Processor Contract Gap

Inventory processors, attach Art 28 DPAs, and track sub-processor changes before the next supervisory review.

Frequently Asked Questions

Is a click-through ToS enough?

Only if it includes the Article 28 mandatory content and is binding. Many SaaS ToS packages need a dedicated DPA annex.

Who notifies the supervisory authority of a breach?

Controllers notify under Article 33. Processors must notify the controller without undue delay after becoming aware.

Where is CyberSilo’s DPA?

https://cybersilo.tech/dpa

GDPR hub · CyberSilo DPA · SaaS obligations · Transfers · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!