Execution of Processing Contract with Required Provisions, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3).

Assessment Step

1
Execution of Processing Contract with Required Provisions (ExecutionofProcessingContractwithRequiredProvisions)
Does the entity ensure that its relationship with each data processor is governed by a binding contract or legal act that includes all required elements under Article 28(3), including the subject matter, duration, nature, purpose, types of data, categories of data subjects, and obligations and rights of the controller?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Execution of Processing Contract with Required Provisions
The data controller must ensure that processing by the data processor is governed by a contract or other legal act that is binding and contains all the elements specified in Article 28(3), including subject matter and duration of processing, nature and purpose of processing, types of personal data, categories of data subjects, and obligations and rights of the controller.
Citation
GDPR
Art. 28(3), Recital 81