GDPR-compliant data processing agreements and vendor management for organisations

GDPR Data Processing under Article 28: Assess Processors, Draft DPAs, Ensure Compliance

GDPR Article 28 requires controllers to engage only processors that provide sufficient guarantees for appropriate technical and organisational measures.

  • 01Draft data processing agreements that meet all Article 28 GDPR requirements
  • 02Processor due diligence covering TOMs, certifications and data protection concepts
  • 03Establish ongoing monitoring and audit processes for data processors
  • 04Manage sub-processors and third-country transfers in full regulatory compliance
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

What does GDPR Article 28 require for data processing agreements and vendor management?

GDPR Article 28 requires controllers to engage only processors that provide sufficient guarantees for appropriate technical and organisational measures. Every data processing relationship must be governed by a written data processing agreement (DPA) specifying the subject matter, duration, nature and purpose of processing, and the processor obligations. ADVISORI supports GDPR-compliant vendor management – from processor assessment through DPA drafting to ongoing monitoring.

We guide you through the full lifecycle of data processing: from selecting the processor through DPA drafting to ongoing monitoring and end-of-contract arrangements.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DPA Drafting and Contract Design

We draft and review data processing agreements under Article 28 GDPR covering all mandatory content – subject matter, duration, TOMs, instruction obligations, sub-processors and deletion provisions.

  • DPA templates with all mandatory content under Article 28(3) GDPR
  • Review of existing data processing agreements for completeness and currency
  • Instruction rights and documentation under Article 29 GDPR
  • Contractual safeguards for deletion and return obligations at contract end
02

Processor Assessment and Due Diligence

We assess your data processors systematically: reviewing technical and organisational measures, certifications, data protection concepts and references before engagement.

  • Structured due diligence checklists for processor assessment
  • TOM review under Article 32 GDPR and security certification evaluation
  • Risk-based classification of processors by data sensitivity
  • Documentation of assessment results for accountability
03

Sub-Processor Management

We establish contractual and organisational frameworks for sub-processors – with authorisation procedures, notification obligations and enforcement rights under Article 28(2) and (4) GDPR.

  • Authorisation procedures for engaging new sub-processors
  • Contractual flow-down of data protection obligations to sub-processors
  • Controller notification and objection rights
  • Liability arrangements and enforcement rights for sub-processor violations
04

Processor Audits and Monitoring

We establish regular review and audit processes for existing processors – from annual reviews through event-driven audits to compliance evidence.

  • Annual compliance reviews of processors using standardised questionnaires
  • Event-driven audits following security incidents or complaints
  • Monitoring of compliance with technical and organisational measures
  • Documentation and reporting for management and supervisory authorities
05

Third-Country Transfers and International Processing

We advise on data transfers to third countries – with standard contractual clauses, transfer impact assessments and adequacy decisions under GDPR Chapter V.

  • Assessment of the legal basis for third-country data transfers
  • Drafting and review of standard contractual clauses (SCCs)
  • Transfer impact assessments (TIA) for high-risk transfers
  • Supplementary measures following the Schrems II ruling
06

Training and Process Integration

We train your business units and procurement teams on data protection requirements for processor selection and integrate DPA processes into existing procurement workflows.

  • Training for procurement and business units on Article 28 GDPR
  • Integration of data protection checklists into procurement processes
  • Practical guidance documents for processor selection
  • Building a data-protection-aware culture in vendor management

5 phases

Our approach to GDPR vendor management

We develop a structured approach to data processing with you – from taking stock through contract drafting to ongoing monitoring of your processors.

  1. Inventory of all service providers and existing data processing agreements

  2. Risk assessment and prioritisation based on the sensitivity of data processed

  3. DPA drafting or revision with all mandatory content under Article 28 GDPR

  4. Establishing regular audit and review processes for data processors

  5. Ongoing monitoring and documentation for accountability under Article 5(2) GDPR

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our expertise in data processing

  • 01Extensive experience drafting data processing agreements for regulated industries
  • 02Proven assessment frameworks for processor due diligence and audits
  • 03Expertise in third-country transfers and international data protection requirements
  • 04Understanding of sector-specific requirements (financial services, healthcare, manufacturing)

Getting data processing right

Without a valid DPA, sharing personal data with service providers is unlawful. Article 28 GDPR requires documented instructions, technical and organisational measures and clear sub-processor provisions. Fines for violations can reach 10 million euros.

7 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about GDPR Vendor Management

When does data processing under GDPR Article 28 apply?

Data processing applies when a service provider (processor) processes personal data on behalf of and under the instructions of the controller. Typical examples include cloud hosting, external payroll processing, newsletter dispatch, IT maintenance with data access, and data carrier disposal. Purely postal services, telecommunications or banking services do not constitute data processing under Article 28.

What must a data processing agreement (DPA) contain?

Article 28(3) GDPR defines mandatory content: subject matter and duration of processing, nature and purpose of processing, types of personal data, categories of data subjects, and obligations and rights of the controller. Additionally, the DPA must address binding instructions, confidentiality, technical and organisational measures, sub-processor arrangements, data subject rights assistance, deletion after contract end, and audit rights.

How should a data processor be assessed before engagement?

The controller must verify the processor has appropriate technical and organisational measures. Assessment methods include on-site audits, reviewing certifications (ISO 27001, SOC 2, BSI C5), examining TOM documentation, checking references and data protection concepts. The assessment must be documented and repeated at regular intervals.

What role do sub-processors play in a DPA?

Article 28(2) GDPR requires the processor not to engage another processor without prior authorisation from the controller. The DPA must specify whether general or specific authorisation applies, how changes are communicated, and which contractual obligations must be passed on to sub-processors. The processor remains liable for its sub-processors.

Who is liable for data protection violations in data processing?

Under Article 82 GDPR, both controller and processor are jointly liable to data subjects. The controller is liable for the entire processing, the processor only for violations of its specific obligations or instructions. Fines under Article 83 GDPR can affect both parties – up to EUR 20 million or 4% of annual turnover.

What happens to the data after the processing relationship ends?

Article 28(3)(g) GDPR stipulates that the processor must delete or return all personal data after the end of processing – at the controller choice – and destroy existing copies. The DPA should specify concrete deadlines, return formats and deletion certificates. Statutory retention obligations of the processor remain unaffected.

How does data processing differ from joint controllership?

In data processing (Article 28 GDPR), the service provider acts under instructions for the controller. In joint controllership (Article 26 GDPR), two or more controllers jointly determine the purposes and means of processing. The distinction is crucial: joint controllership requires an arrangement under Article 26 GDPR instead of a DPA, specifying respective responsibilities and contact points for data subjects.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance