The processor contract is the GDPR document a software company signs most often and reads least. Every customer that puts personal data into the product is a controller, and Article 28(3) says its processing by you is governed by a contract with a fixed content: the subject matter and duration, the nature and purpose, the type of personal data and the categories of data subjects, the obligations and rights of the controller, and eight undertakings by the processor. The wording differs from customer to customer; the eight terms do not. This article reads them from the vendor's side and hands you the checklist that tracks them contract by contract.

Before the eight terms: who signs, and what Article 28 asks first

Article 28(1) lets a controller use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. That sentence is why the customer's security questionnaire arrives before the contract: the guarantees are what the questionnaire asks for, and an ISO 27001 certificate with a scope that covers the product is the shortest answer to it.

Article 28(2) is the sub-processor rule. The processor does not engage another processor without prior specific or general written authorisation of the controller; under a general authorisation, the processor informs the controller of any intended change and gives it the opportunity to object. For a SaaS company, this is the sub-processor list on the website and the notice period in the contract, and it is where most negotiations start. Article 28(4) then requires the same data protection obligations to flow down to each sub-processor by contract, and makes the first processor fully liable to the controller for the sub-processor's performance.

Article 28(7) allowed the Commission to adopt standard contractual clauses for the contract itself; it did so on 4 June 2021, and a vendor can offer them instead of drafting. Article 28(10) is the trap at the edge: a processor that determines the purposes and means of a processing is a controller for it, so a vendor that mines customer data for its own product analytics has left the processor role for that use.

The eight terms of Article 28(3), from the vendor's side

(a) Documented instructions. The processor processes the personal data only on documented instructions from the controller, transfers to a third country included, unless Union or member state law requires otherwise, in which case it informs the controller first. For a SaaS the instructions are the contract, the order form and the product's configuration; the term is why the customer's admin settings are a legal document.

(b) Confidentiality. The persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality. Employment contracts and contractor agreements are the evidence, and the onboarding record is where an auditor looks.

(c) Security. The processor takes all measures required under Article 32: the pseudonymisation and encryption, the confidentiality, integrity, availability and resilience, the restore capability and the regular testing. The ISO 27001 system is the answer to this term, and the customer will ask for the certificate's scope, not just its existence.

(d) Sub-processors. The conditions of Article 28(2) and (4) are respected: authorisation, notice, flow-down. The sub-processor list is a term of the contract, and the notice period is the negotiation.

(e) Assistance with data subject rights. Taking into account the nature of the processing, the processor assists the controller by appropriate technical and organisational measures in responding to requests under Chapter III. In practice: the export, the deletion and the correction functions of the product, and a support process for the requests the product cannot self-serve.

(f) Assistance with Articles 32 to 36. Security, breach notification, impact assessments and prior consultation: the processor assists, taking into account the nature of the processing and the information available to it. The breach part is the clock the customer runs: your Article 33(2) notice to the controller starts its 72 hours, and the contract usually fixes how fast you send it.

(g) Deletion or return. At the end of the provision of services, at the choice of the controller, the processor deletes or returns all the personal data and deletes existing copies, unless Union or member state law requires storage. The export function, the deletion schedule and the backup retention are the three things the term turns on.

(h) Information and audits. The processor makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates. The second subparagraph of Article 28(3) adds the duty most contracts forget: the processor immediately informs the controller if, in its opinion, an instruction infringes the Regulation or other Union or member state data protection provisions. A vendor that takes an unlawful instruction without saying so shares the liability for it.

Liability and the fine

Article 82(2) makes a processor liable for the damage caused by processing only where it has not complied with the obligations specifically directed to processors or has acted outside or contrary to the controller's lawful instructions, and Article 82(4) makes controllers and processors involved in the same processing jointly and severally liable to the data subject. Article 83(4)(a) sets the fine ceiling for the obligations of processors under Article 28 at EUR 10 million or 2% of worldwide annual turnover. The eight terms are what the customer's lawyers are pricing when they send the addendum.

Beside the terms: the DORA clauses a bank customer sends

When the customer is a bank, an insurer, an investment firm, a payment or e-money institution, a crypto-asset service provider or a fund manager, the same addendum carries the contract clauses of DORA Article 30, in force since 17 January 2025. The two sets overlap term by term: the GDPR instructions of (a) sit beside the DORA service description of 30(2)(a); the security of (c) beside 30(2)(c); the sub-processor conditions of (d) beside the subcontracting conditions 30(2)(a) requires; the assistance of (f) beside the incident assistance of 30(2)(f); the deletion or return of (g) beside the access, recovery and return of 30(2)(d); the audits of (h) beside the access, inspection and audit rights of 30(3)(e). Only the data subject rights of (e) have no DORA counterpart. The checklist quotes the DORA clause beside each term when you say the customer is a financial entity, and continues into the DORA checklist with the same customer name, so the negotiation is read once rather than twice.

Writing it down

Open the customer's addendum next to the checklist, mark each term agreed, negotiating or missing, and note the clause number and the wording. The result is a document per customer to copy or download, and the list of open terms is the agenda for the next call. Keep it next to the record of processing the contract describes: the categories of processing in the processor's record are the ones the contract's subject matter names, and a customer reading both will expect them to agree.