[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-gdpr-processor-contract-for-a-saas-company-the-eight-terms-of-article-28-3-every-customer-addendum-carries-the-duty-most-of-them-forget-and-what-sits-beside-them-under-dora":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-gdpr-processor-contract-for-a-saas-company-the-eight-terms-of-article-28-3-every-customer-addendum-carries-the-duty-most-of-them-forget-and-what-sits-beside-them-under-dora","The GDPR processor contract for a SaaS company: the eight terms of Article 28(3) every customer addendum carries, the duty most of them forget, and what sits beside them under DORA","A SaaS company signs the same contract with every customer it processes data for, and Article 28(3) fixes its content: the subject matter and duration, the eight undertakings from documented instructions to audits, and the processor's duty to flag an instruction that infringes the Regulation. What each term means for a software vendor, the sub-processor rule of Article 28(2) and (4), the Commission's 2021 standard clauses, the liability of Article 82 and the fine ceiling of Article 83, and the DORA Article 30 clause a bank customer sends beside each term. With the free checklist that reads the two addenda as one.","2026-09-12",{"who":10,"when":11,"do":12},"Every SaaS company, hosted API or managed service that processes personal data for its customers, as their processor under Article 4(8); the terms bind the vendor whether the customer sends its own addendum or signs the vendor's.","The contract is due before the first processing for that customer and is re-read at every change of sub-processor (Article 28(2)); a bank, insurer or payment institution sends the DORA Article 30 clauses in the same addendum, in force since 17 January 2025, and the two sets are negotiated together.","Run the free checklist with the customer's addendum open: mark each of the eight terms agreed, negotiating or missing, note the clause number, and where the customer is a financial entity, continue into the DORA clause checklist with the same document.","\nThe processor contract is the GDPR document a software company signs most often and reads least. Every customer that puts personal data into the product is a controller, and Article 28(3) says its processing by you is governed by a contract with a fixed content: the subject matter and duration, the nature and purpose, the type of personal data and the categories of data subjects, the obligations and rights of the controller, and eight undertakings by the processor. The wording differs from customer to customer; the eight terms do not. This article reads them from the vendor's side and hands you the [checklist that tracks them](\u002Fgdpr\u002Fprocessor-terms) contract by contract.\n\n## Before the eight terms: who signs, and what Article 28 asks first\n\nArticle 28(1) lets a controller use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. That sentence is why the customer's security questionnaire arrives before the contract: the guarantees are what the questionnaire asks for, and an ISO 27001 certificate with a scope that covers the product is the shortest answer to it.\n\nArticle 28(2) is the sub-processor rule. The processor does not engage another processor without prior specific or general written authorisation of the controller; under a general authorisation, the processor informs the controller of any intended change and gives it the opportunity to object. For a SaaS company, this is the sub-processor list on the website and the notice period in the contract, and it is where most negotiations start. Article 28(4) then requires the same data protection obligations to flow down to each sub-processor by contract, and makes the first processor fully liable to the controller for the sub-processor's performance.\n\nArticle 28(7) allowed the Commission to adopt standard contractual clauses for the contract itself; it did so on 4 June 2021, and a vendor can offer them instead of drafting. Article 28(10) is the trap at the edge: a processor that determines the purposes and means of a processing is a controller for it, so a vendor that mines customer data for its own product analytics has left the processor role for that use.\n\n## The eight terms of Article 28(3), from the vendor's side\n\n**(a) Documented instructions.** The processor processes the personal data only on documented instructions from the controller, transfers to a third country included, unless Union or member state law requires otherwise, in which case it informs the controller first. For a SaaS the instructions are the contract, the order form and the product's configuration; the term is why the customer's admin settings are a legal document.\n\n**(b) Confidentiality.** The persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality. Employment contracts and contractor agreements are the evidence, and the onboarding record is where an auditor looks.\n\n**(c) Security.** The processor takes all measures required under Article 32: the pseudonymisation and encryption, the confidentiality, integrity, availability and resilience, the restore capability and the regular testing. The ISO 27001 system is the answer to this term, and the customer will ask for the certificate's scope, not just its existence.\n\n**(d) Sub-processors.** The conditions of Article 28(2) and (4) are respected: authorisation, notice, flow-down. The sub-processor list is a term of the contract, and the notice period is the negotiation.\n\n**(e) Assistance with data subject rights.** Taking into account the nature of the processing, the processor assists the controller by appropriate technical and organisational measures in responding to requests under Chapter III. In practice: the export, the deletion and the correction functions of the product, and a support process for the requests the product cannot self-serve.\n\n**(f) Assistance with Articles 32 to 36.** Security, breach notification, impact assessments and prior consultation: the processor assists, taking into account the nature of the processing and the information available to it. The breach part is the clock the customer runs: your Article 33(2) notice to the controller starts its 72 hours, and the contract usually fixes how fast you send it.\n\n**(g) Deletion or return.** At the end of the provision of services, at the choice of the controller, the processor deletes or returns all the personal data and deletes existing copies, unless Union or member state law requires storage. The export function, the deletion schedule and the backup retention are the three things the term turns on.\n\n**(h) Information and audits.** The processor makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates. The second subparagraph of Article 28(3) adds the duty most contracts forget: the processor immediately informs the controller if, in its opinion, an instruction infringes the Regulation or other Union or member state data protection provisions. A vendor that takes an unlawful instruction without saying so shares the liability for it.\n\n## Liability and the fine\n\nArticle 82(2) makes a processor liable for the damage caused by processing only where it has not complied with the obligations specifically directed to processors or has acted outside or contrary to the controller's lawful instructions, and Article 82(4) makes controllers and processors involved in the same processing jointly and severally liable to the data subject. Article 83(4)(a) sets the fine ceiling for the obligations of processors under Article 28 at EUR 10 million or 2% of worldwide annual turnover. The eight terms are what the customer's lawyers are pricing when they send the addendum.\n\n## Beside the terms: the DORA clauses a bank customer sends\n\nWhen the customer is a bank, an insurer, an investment firm, a payment or e-money institution, a crypto-asset service provider or a fund manager, the same addendum carries the [contract clauses of DORA Article 30](\u002Fdora\u002Fcontract-clauses), in force since 17 January 2025. The two sets overlap term by term: the GDPR instructions of (a) sit beside the DORA service description of 30(2)(a); the security of (c) beside 30(2)(c); the sub-processor conditions of (d) beside the subcontracting conditions 30(2)(a) requires; the assistance of (f) beside the incident assistance of 30(2)(f); the deletion or return of (g) beside the access, recovery and return of 30(2)(d); the audits of (h) beside the access, inspection and audit rights of 30(3)(e). Only the data subject rights of (e) have no DORA counterpart. The [checklist](\u002Fgdpr\u002Fprocessor-terms) quotes the DORA clause beside each term when you say the customer is a financial entity, and continues into the DORA checklist with the same customer name, so the negotiation is read once rather than twice.\n\n## Writing it down\n\nOpen the customer's addendum next to the [checklist](\u002Fgdpr\u002Fprocessor-terms), mark each term agreed, negotiating or missing, and note the clause number and the wording. The result is a document per customer to copy or download, and the list of open terms is the agenda for the next call. Keep it next to the [record of processing](\u002Fgdpr\u002Frecord-of-processing) the contract describes: the categories of processing in the processor's record are the ones the contract's subject matter names, and a customer reading both will expect them to agree.\n",1789383984540]