UK GDPR (UK General Data Protection Regulation)
Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.28: Article 28 Processor

A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.19(c) 1.19(c) Covert monitoring: use the information only for the investigation, few people involved, disclosure rules, contracts with investigators, and SARs
  • 1.22 1.22 Third-party monitoring providers: check compliance, choose a competent processor and have a contract
  • 3.2 3.2 Commercial monitoring tools: settle controller and processor roles first, choose a processor with guarantees, and get enough information by contract
  • A.1 A.1 Know who controls the system, agree joint and processor roles in writing, and set procedures, a named owner and regular audits

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.