Data processing agreement: the clause the question tests
Whether the processing sits under a written processor contract with the terms the law requires.
How the customer usually asks it
example"Will you sign our data processing agreement?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.34 Privacy and protection of personal identifiable information (PII) |
| SIG (Shared Assessments) | domain O Privacy |
| GDPR, Regulation (EU) 2016/679 | Art. 28 Processor |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The supplier's processing terms checked against the stipulations of GDPR Article 28(3), and the flow-down terms used with its own subprocessors.
The clauses, with what an assessor asks for
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where answers usually fall short: Missing documented consent for all data subjects; Incomplete inventory of PII across legacy systems
Source: ISO/IEC 27001:2022
SIG domain O PrivacyWhat it asks for, in one line (the standard's own text is not quoted here):
Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.
Where answers usually fall short: No transfer impact assessment for non adequacy jurisdictions; DSR metrics not tracked against statutory deadlines
Source: SIG (Shared Assessments)
GDPR Art. 28 ProcessorUse only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
Where answers usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
Source: GDPR, Regulation (EU) 2016/679