UK GDPR Article 28: what processors must do, and how suppliers show sufficient guarantees
“Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.” — UK GDPR Article 28(1).
If you process personal data for customers — hosting it, supporting it, analysing it — you are their processor, and Article 28 is the reason for their security questionnaire, their contract schedule and their audit clause. This page sets out what the article requires, quoted from the legislation, and what a supplier can put forward as evidence.
The eight contract terms, and the evidence behind each
Article 28(3) requires a contract that sets out the subject-matter and duration of the processing, its nature and purpose, the type of personal data and categories of data subjects, and the obligations and rights of the controller. It must stipulate, in particular, that the processor:
| The processor | Evidence an ISO 27001 ISMS can provide (our reading) | |
|---|---|---|
| a | processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by domestic law | Documented procedures and change control; the contract itself is the instruction set |
| b | ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality | Confidentiality terms in employment and contractor agreements (people controls) |
| c | takes all measures required pursuant to Article 32 | The Article 32 measures — the core of what an ISMS risk treatment covers |
| d | respects the conditions referred to in paragraphs 2 and 4 for engaging another processor | Supplier management and a record of sub-processors |
| e | taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III | Procedures for handling individuals' requests, where the ISMS scope includes them |
| f | assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor | Incident management and breach notification procedures; DPIA support |
| g | at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless domestic law requires storage of the personal data | Secure deletion and return procedures at contract end |
| h | makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller | Audit readiness — the ISMS already runs internal audits and hosts external ones |
The right-hand column is our reading, not the law's. A certificate does not satisfy any of these terms; the contract does. What an ISO 27001 management system gives a processor is ready evidence when the controller asks how each term is met.
Sufficient guarantees: the test before the contract
Article 28(1) is a duty on the controller: use only processors that provide sufficient guarantees. The ICO puts the controller's position plainly: “Controllers are primarily responsible for overall compliance with the UK GDPR, and for demonstrating that compliance.” That is why the questions arrive before the contract is signed.
Where certification enters the law
Article 28(5): “Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.” Those words were substituted by the Data (Use and Access) Act 2025. An Article 42 mechanism is a scheme with ICO-approved criteria — see UK GDPR certification. An ISO 27001 certificate is not one, though it may still be evidence a controller chooses to rely on.
Sub-processors
“The processor shall not engage another processor without prior specific or general written authorisation of the controller.” Where the authorisation is general, the processor must tell the controller about intended changes, giving it the opportunity to object.
The obligations pass down: under Article 28(4) the same data protection obligations must be imposed on the sub-processor by contract. And the liability stays with you: “Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.”
For an ISO 27001 holder
Supplier management is part of an ISMS's control set, and the Statement of Applicability records how it is applied. The sub-processor list a controller asks for is the same list your supplier controls should already maintain — our reading of how the two meet.
Security: Article 28 points to Article 32
Term (c) is short — the processor “takes all measures required pursuant to Article 32” — and carries the whole of the security requirement with it. Article 32 applies directly to processors as well: its first paragraph says “the controller and the processor shall implement” the measures. What those measures are is set out on Article 32.
Audits
Term (h) requires the processor to make information available and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller”. A processor that already hosts an annual ISO 27001 surveillance audit has the evidence organised; the controller's audit right exists regardless.
The ICO's contracts guidance is under review
“Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.” The article text quoted on this page is the current legislation; check the ICO page for updated guidance.
We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. Contract terms are a matter for the parties and their advisers; the law is quoted from legislation.gov.uk.
Where this fits
Common questions
What does Article 28 GDPR require?
That a controller uses only processors that provide “sufficient guarantees” of appropriate technical and organisational measures, that processing is governed by a written contract with specified terms, that the processor does not appoint sub-processors without authorisation, and that sub-processors carry the same obligations.
What must a data processing agreement include?
Article 28(3) lists the details (subject-matter, duration, nature and purpose, types of data, categories of data subject, the controller's obligations and rights) and eight terms, (a) to (h): documented instructions, confidentiality, Article 32 security, sub-processor conditions, help with individuals' rights, help with Articles 32 to 36, deletion or return at the end, and audits.
Does the contract have to be in writing?
Yes. “The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing”. The ICO: “Whenever a controller uses a processor, there must be a written contract (or other legal act) in place.”
Can ISO 27001 prove sufficient guarantees?
The law names one route explicitly: Article 28(5) allows adherence to an approved code of conduct or an approved Article 42 certification mechanism to be used as a means of demonstrating sufficient guarantees. ISO 27001 is not an Article 42 mechanism. It can still be evidence a controller weighs — that is a judgement for the controller, not something the article provides for.
Who is liable if a sub-processor fails?
The processor that appointed it. “Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.”
Can we use a sub-processor without asking?
No. “The processor shall not engage another processor without prior specific or general written authorisation of the controller.” Under a general authorisation, the processor must tell the controller about changes so it has the opportunity to object.
Does Article 28 require audits?
It requires the processor to make available all information necessary to demonstrate compliance and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller” — Article 28(3)(h).
Sources cited on this page
- UK GDPR Article 28 (Processor), legislation.gov.uk
- ICO, Contracts (Guide to accountability and governance)
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- ICO, Certification schemes: a guide (updated 13 February 2026)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer sent you a processor questionnaire?
Say what they asked for and what you already hold. An ISO 27001 scope that covers the service can be the core of the answer.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.