Meaning
Mandatory contractual provisions under European data protection law ensure that service providers handle personal data according to specific instructions. These article 28 dpa clauses define the legal boundaries of data processing by a third party. The document identifies the nature and duration of the data handling alongside the specific obligations of the processor.
Statutory Mandate
Compliance requirements for article 28 dpa clauses demand that any processing activity performed on behalf of a controller rests on a written contract. This document must specify that the processor acts only on documented instructions unless required by law to do otherwise.
Liability Allocation
Obligations within the framework of article 28 dpa clauses include the duty to assist the controller in responding to requests from individuals exercising their rights. The processor must maintain security standards that protect against unauthorized access or data loss. Every sub-processor engaged by the primary provider must sign a contract that carries the same protections found in the original agreement.
If a sub-processor fails to meet these standards, the original processor remains fully liable to the controller for the performance of those obligations.
Audit Right
Access to information necessary to demonstrate compliance with article 28 dpa clauses is a standard requirement in these agreements. The controller may conduct inspections to verify that the processor adheres to the stated protocols.