Agent · gdpr-2016-679-28
GDPR artikel 28: Processor
Operative tree, written by hand from the article's conditions.
CELEX 32016R0679 · 2026-08-18 · Weight 106 · minimal-risk
PremiumHand written or high weight rule tree. Metered per call at the edge once metering is switched on, at the same address and with the same answer as today.
- What this page is
- Agent, GDPR artikel 28
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does GDPR Article 28 require, and what outcome does the rule tree give?
GDPR Article 28 is tested here by a deterministic rule tree of 4 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Article 28 does not apply, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32016R0679. The outcome is a machine classification, not a compliance decision.
GDPR Article 28Checked against the publisher 2026-08-18Official text
- Article 28 does not apply. No processor is engaged.
- The processing contract is missing. The processing shall be governed by a contract with the content set out in Article 28(3)(a) to (h).
- Sub-processor without authorisation. A processor shall not engage a sub-processor without prior specific or general written authorisation from the controller.
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- processor_usedA processor is engagedboolean
- written_contractA written contract is in placeboolean
- subprocessor_authorisedSub-processors are authorisedboolean
Rule tree
If: processor_used = false
Article 28 does not apply
No processor is engaged.
Paragraph 1
If: inte(written_contract = true)
The processing contract is missing
The processing shall be governed by a contract with the content set out in Article 28(3)(a) to (h).
Paragraph 3
If: subprocessor_authorised = false
Sub-processor without authorisation
A processor shall not engage a sub-processor without prior specific or general written authorisation from the controller.
Paragraph 2
If: written_contract = true
The contract is in place
The contract shall bind the processor to confidentiality, security under Article 32, assistance and deletion or return at the end of the engagement.
Paragraph 3
If no rule matches: None of the article's conditions are met with the facts supplied. Supply more facts or read the article in full.
The article text as read
- 11. Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
- 22. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
- 33. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:
- 4(a)
- 5processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
- 6(b)
- 7ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- 8(c)
- 9takes all measures required pursuant to Article 32;
- 10(d)
- 11respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
- 12(e)
- 13taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;
- 14(f)
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32016R0679 art. 28, Processor. ExploreWorld Legal, https://legal.exploreworldai.com/agent/gdpr-2016-679/artikel-28 (hämtad 2026-08-18, bevis sha256:cf7d1c2921458f23, bygge legal-2026-08-25).