iso27001partnersUK certification, costed Get a cost estimate

UK GDPR Article 28: what processors must do, and how suppliers show sufficient guarantees

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
4 primary sources cited on this page. How we check what is on this site
Why your customer is asking “Sufficient guarantees”

“Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.” — UK GDPR Article 28(1).

If you process personal data for customers — hosting it, supporting it, analysing it — you are their processor, and Article 28 is the reason for their security questionnaire, their contract schedule and their audit clause. This page sets out what the article requires, quoted from the legislation, and what a supplier can put forward as evidence.

The eight contract terms, and the evidence behind each

Article 28(3) requires a contract that sets out the subject-matter and duration of the processing, its nature and purpose, the type of personal data and categories of data subjects, and the obligations and rights of the controller. It must stipulate, in particular, that the processor:

UK GDPR Article 28(3)(a)–(h) (verbatim) and what an ISMS typically evidences (our reading)
The processorEvidence an ISO 27001 ISMS can provide (our reading)
aprocesses the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by domestic lawDocumented procedures and change control; the contract itself is the instruction set
bensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentialityConfidentiality terms in employment and contractor agreements (people controls)
ctakes all measures required pursuant to Article 32The Article 32 measures — the core of what an ISMS risk treatment covers
drespects the conditions referred to in paragraphs 2 and 4 for engaging another processorSupplier management and a record of sub-processors
etaking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter IIIProcedures for handling individuals' requests, where the ISMS scope includes them
fassists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processorIncident management and breach notification procedures; DPIA support
gat the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless domestic law requires storage of the personal dataSecure deletion and return procedures at contract end
hmakes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controllerAudit readiness — the ISMS already runs internal audits and hosts external ones

The right-hand column is our reading, not the law's. A certificate does not satisfy any of these terms; the contract does. What an ISO 27001 management system gives a processor is ready evidence when the controller asks how each term is met.

Sufficient guarantees: the test before the contract

Article 28(1) is a duty on the controller: use only processors that provide sufficient guarantees. The ICO puts the controller's position plainly: “Controllers are primarily responsible for overall compliance with the UK GDPR, and for demonstrating that compliance.” That is why the questions arrive before the contract is signed.

Where certification enters the law

Article 28(5): “Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.” Those words were substituted by the Data (Use and Access) Act 2025. An Article 42 mechanism is a scheme with ICO-approved criteria — see UK GDPR certification. An ISO 27001 certificate is not one, though it may still be evidence a controller chooses to rely on.

Sub-processors

“The processor shall not engage another processor without prior specific or general written authorisation of the controller.” Where the authorisation is general, the processor must tell the controller about intended changes, giving it the opportunity to object.

The obligations pass down: under Article 28(4) the same data protection obligations must be imposed on the sub-processor by contract. And the liability stays with you: “Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.”

For an ISO 27001 holder

Supplier management is part of an ISMS's control set, and the Statement of Applicability records how it is applied. The sub-processor list a controller asks for is the same list your supplier controls should already maintain — our reading of how the two meet.

Security: Article 28 points to Article 32

Term (c) is short — the processor “takes all measures required pursuant to Article 32” — and carries the whole of the security requirement with it. Article 32 applies directly to processors as well: its first paragraph says “the controller and the processor shall implement” the measures. What those measures are is set out on Article 32.

Audits

Term (h) requires the processor to make information available and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller”. A processor that already hosts an annual ISO 27001 surveillance audit has the evidence organised; the controller's audit right exists regardless.

The ICO's contracts guidance is under review

“Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.” The article text quoted on this page is the current legislation; check the ICO page for updated guidance.

We do not give legal advice, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. Contract terms are a matter for the parties and their advisers; the law is quoted from legislation.gov.uk.

Where this fits

Common questions

What does Article 28 GDPR require?

That a controller uses only processors that provide “sufficient guarantees” of appropriate technical and organisational measures, that processing is governed by a written contract with specified terms, that the processor does not appoint sub-processors without authorisation, and that sub-processors carry the same obligations.

What must a data processing agreement include?

Article 28(3) lists the details (subject-matter, duration, nature and purpose, types of data, categories of data subject, the controller's obligations and rights) and eight terms, (a) to (h): documented instructions, confidentiality, Article 32 security, sub-processor conditions, help with individuals' rights, help with Articles 32 to 36, deletion or return at the end, and audits.

Does the contract have to be in writing?

Yes. “The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing”. The ICO: “Whenever a controller uses a processor, there must be a written contract (or other legal act) in place.”

Can ISO 27001 prove sufficient guarantees?

The law names one route explicitly: Article 28(5) allows adherence to an approved code of conduct or an approved Article 42 certification mechanism to be used as a means of demonstrating sufficient guarantees. ISO 27001 is not an Article 42 mechanism. It can still be evidence a controller weighs — that is a judgement for the controller, not something the article provides for.

Who is liable if a sub-processor fails?

The processor that appointed it. “Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor’s obligations.”

Can we use a sub-processor without asking?

No. “The processor shall not engage another processor without prior specific or general written authorisation of the controller.” Under a general authorisation, the processor must tell the controller about changes so it has the opportunity to object.

Does Article 28 require audits?

It requires the processor to make available all information necessary to demonstrate compliance and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller” — Article 28(3)(h).

Sources cited on this page

  1. UK GDPR Article 28 (Processor), legislation.gov.uk
  2. ICO, Contracts (Guide to accountability and governance)
  3. UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
  4. ICO, Certification schemes: a guide (updated 13 February 2026)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A customer sent you a processor questionnaire?

Say what they asked for and what you already hold. An ISO 27001 scope that covers the service can be the core of the answer.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now