Article 28 GDPR

The GDPR article that governs how controllers use processors: sufficient guarantees, a binding contract with set terms, and rules for engaging subprocessors.

Article 28 requires controllers to use only processors that provide sufficient guarantees (28(1)); forbids processors to engage another processor without the controller’s written authorisation, and requires notice of changes so the controller can object (28(2)); lists what the contract must contain (28(3)); and requires the same obligations to be passed down to subprocessors, with the first processor remaining fully liable for them (28(4)).

It is the reason SaaS vendors publish subprocessor lists and offer data processing agreements.

Source: GDPR Art. 28 ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.