GDPR: all pages

GDPR · the processor contract

The processor contract, term by term

Eight terms, each the Regulation's own words; mark each one agreed, negotiating or missing, and the checklist is written below with the ISO 27701 reading and, for a bank customer, the DORA clause beside it.

Which party are you?
Is the customer a financial entity under DORA?

A bank, insurer, investment firm, payment or e-money institution, crypto-asset service provider or fund manager sends the Article 30 clauses in the same addendum.

The 8 terms of Article 28(3)

Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:

28(3)(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;

ISO 27701, StandardOS's reading: B.8.2.1, B.8.2.4

28(3)(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

ISO 27701, StandardOS's reading: B.8.2.1, Clause 6.4

28(3)(c) takes all measures required pursuant to Article 32;

ISO 27701, StandardOS's reading: Clause 6.6, Clause 6.7, Clause 6.9

28(3)(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;

ISO 27701, StandardOS's reading: B.8.5.6, B.8.5.7, B.8.5.8

28(3)(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;

ISO 27701, StandardOS's reading: B.8.3.1

28(3)(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;

ISO 27701, StandardOS's reading: B.8.2.5, Clause 6.13

28(3)(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;

ISO 27701, StandardOS's reading: B.8.4.2

28(3)(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

ISO 27701, StandardOS's reading: B.8.2.5, Clause 6.15

With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.

0 agreed, 0 negotiating, 8 missing, of 8.

The checklist

# Article 28(3) processor terms checklist

Read from the processor's side: the terms the customer's contract must carry and the company undertakes.
Written on  with the free checklist at getstandardos.com; each term is Article 28(3) of Regulation (EU) 2016/679 as the Official Journal words it.

> Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:

0 agreed, 0 negotiating, 8 missing, of 8.

## 28(3)(a)

processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;

Status: Missing
ISO 27701, StandardOS's reading: B.8.2.1, B.8.2.4
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(b)

ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

Status: Missing
ISO 27701, StandardOS's reading: B.8.2.1, Clause 6.4
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(c)

takes all measures required pursuant to Article 32;

Status: Missing
ISO 27701, StandardOS's reading: Clause 6.6, Clause 6.7, Clause 6.9
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(d)

respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;

Status: Missing
ISO 27701, StandardOS's reading: B.8.5.6, B.8.5.7, B.8.5.8
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(e)

taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;

Status: Missing
ISO 27701, StandardOS's reading: B.8.3.1
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(f)

assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;

Status: Missing
ISO 27701, StandardOS's reading: B.8.2.5, Clause 6.13
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(g)

at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;

Status: Missing
ISO 27701, StandardOS's reading: B.8.4.2
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

## 28(3)(h)

makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

Status: Missing
ISO 27701, StandardOS's reading: B.8.2.5, Clause 6.15
Beside it under DORA: no DORA counterpart; the term stands on its own
Note: (none)

> With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.

Open terms: 28(3)(a), 28(3)(b), 28(3)(c), 28(3)(d), 28(3)(e), 28(3)(f), 28(3)(g), 28(3)(h).

This is a checklist against the Regulation's text, not legal advice; the wording that satisfies each term is the contract's own. Generated by StandardOS.

One contract per customer, with its terms as rows

StandardOS keeps each processor contract as a row per customer with the eight terms' status, next to the record of processing the contract describes and the breach clock the customer's Article 33(2) notice starts.

The terms are Article 28(3), points (a) to (h), read from the Official Journal, never typed on this page. This is a checklist, not legal advice.