By Rafael Luque Ocaña

Your AI vendor is almost always a processor: what the Article 28 contract has to say

If an AI vendor processes personal data on your company's behalf, it is a processor, and Article 28 GDPR sets out what the contract must cover.

This article is for anyone contracting an AI service — an assistant, a transcription tool, an agent — that will process personal data about their company's customers, employees or candidates, and who has a set of terms and a data protection annex in front of them to sign. Before reading them, it helps to know what role the vendor plays, because that role determines what the contract has to say.

In most cases the answer is the same. Your company decides what the data are used for and the vendor processes them to provide you with the service: your company is the controller and the vendor, the processor. The GDPR defines a processor as a person or body "which processes personal data on behalf of the controller", and a controller as whoever, "alone or jointly with others, determines the purposes and means of the processing of personal data".

First, the role

When your AI vendor is a processorArticles 4(7), 4(8), 26(1) and 28 of Regulation (EU) 2016/679THE ROLE TURNS ON WHO SETS THE PURPOSES AND MEANS OF EACH PROCESSINGYESNOYESNOif it sets the purposes andmeans on its own · Art. 28(10)An AI service processes personal dataDoes it process them onyour company's behalf?Do you jointly set thepurposes and means?ProcessorArt. 4(8)The Art. 28(3) contract shall stipulate, in particular:(a) only on your documented instructions(b) confidentiality of its staff(c) the security measures of Art. 32(d) conditions for engaging another processor(e) assistance with data subjects' rights(f) assistance with Arts. 32 to 36(g) deletion or return, at your choice(h) information and auditsJoint controllersArt. 26(1)Controller of that processingit sets the purposes and meansArt. 4(7)Articles 4, 26 and 28 of Regulation (EU) 2016/679 (GDPR)
The vendor's role turns on who sets the purposes and means of each processing operation. If it processes the data on your company's behalf, it is a processor and the Article 28(3) contract covers the eight points; if it sets them jointly with your company, you are joint controllers; if it sets them itself, it is the controller of that processing.

The figure walks through the question in two steps. If the vendor processes the data on your company's behalf, it is a processor (Article 4(8)), and the Article 28(3) contract shall stipulate, in particular, the eight points from (a) to (h), which the figure summarises. If it does not process them on your behalf and you jointly set the purposes and means, you are joint controllers (Article 26(1)); if it sets them alone, it is the controller of that processing (Article 4(7)). A dashed line runs from processor to controller: a processor that sets the purposes and means on its own becomes the controller of that processing (Article 28(10)).

The role is decided processing by processing: the same service can be a processor for what it does to provide you with the service and the controller of another processing operation it decides itself, such as training its own models on those data. So the first question to put to the vendor is what it does with your company's data and who decides it.

Nor is it the AI Act role. The AI Act assigns other roles — provider and deployer — on other criteria: fine-tuning an open model can turn your company into a provider for AI Act purposes, and Article 28 GDPR does not answer that question.

Before the contract: whom you choose

Article 28 starts before you sign. Its paragraph 1 says that "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures". The burden sits with whoever chooses: if the vendor cannot explain where it processes the data, who has access to them or what it does with them when the contract ends, it has given you nothing to weigh. The ten questions of a proper due diligence are there for that, and their answers end up in the contract.

Sub-processors

An AI service almost always relies on others — the cloud, a third party's model, email — and each of them that processes your data is another processor. Paragraph 2 sets the rule: "The processor shall not engage another processor without prior specific or general written authorisation of the controller." Where the authorisation is general, "the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes".

And paragraph 4 binds the sub-processor by "the same data protection obligations as set out in the contract or other legal act between the controller and the processor", and if it fails, "the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations".

In practice: a list of sub-processors you can check, notice before each change and a period in which to object. Alethexis, for example, publishes its own on the sub-processors page and gives 30 days' notice.

The contract, point by point

Paragraph 3 requires the processing to be governed by "a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller". It then lists eight points that the contract shall stipulate, in particular. The table goes through them with a worked example: how the Alethexis data processing agreement, the one we know from the inside, covers each point.

PointWhat the contract must stipulateExample: the Alethexis data processing agreement
(a) InstructionsProcessing only on documented instructions, including for transfers to third countriesClause 6.1: the agreement and its annexes, the accepted terms, the customer's configuration in the service and anything it sends in writing to [email protected]
(b) ConfidentialityA commitment to confidentiality, or a statutory obligation, for authorised personsClause 6.2: a confidentiality undertaking, training and access only where necessary
(c) SecurityThe measures required by Article 32Clause 6.3: refers to Annex III of the agreement, which may be updated without reducing the level of protection
(d) Sub-processorsThe conditions of paragraphs 2 and 4Clause 6.4: general authorisation, a public list, 30 days' notice and a right to object
(e) RightsAssisting the controller with people exercising their rightsClause 6.5: access, export and deletion within the service itself, and technical assistance where they are not enough
(f) Articles 32 to 36Assistance with security, personal data breaches, the impact assessment and prior consultationClause 6.6: Annex III, notification of personal data breaches under clause 8 and information for the impact assessment
(g) End of the serviceDeleting or returning the data at the end, at the controller's choiceClause 6.7: under clause 10, with deletion staged across five levels
(h) AuditsInformation to demonstrate compliance, and audits, including inspectionsClause 6.8: information and audits under clause 9

The paragraph ends with an obligation that has no letter: "the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions". The Alethexis agreement covers it in clauses 6.1 and 6.8.

If a point is missing from a vendor's contract, or appears only as a generic promise to respect the law, that is the conversation still to be had before signing.

When the vendor is not a processor

There are three other outcomes, and the figure draws them.

Joint controllers. "Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers." This happens when the vendor decides with you why and how the data are processed: the relationship is then between two controllers, and the instrument is not the Article 28 contract.

Controller of its own processing. If the vendor uses the data for purposes it decides itself — training its models, improving other products — it is the controller of that processing, because it is the one setting the purposes and means. Which data that use reaches, and whether the contract allows it or rules it out, is the first thing to check.

The processor that steps out of its role. Article 28(10) provides for this case: "Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing." It is not an exit the contract offers, but the consequence of stepping outside it.

If the service is an agent connected to other tools, the question repeats for every service it opens access to; we cover it in the article on the AEPD guidance.

Transfers outside the European Economic Area

Point (a) of paragraph 3 includes transfers among the things the processor only does on documented instructions: the contract shall stipulate that it processes the data that way, "including with regard to transfers of personal data to a third country or an international organisation". And Article 44 only allows a transfer if "the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers": those made from that third country or international organisation to another.

The practical question is where the vendor and each sub-processor process the data; a good sub-processor list says so, with the mechanism for each one.

What to have in writing

For each AI vendor that processes your company's personal data, five answers:

  1. What role it has in each processing operation, not only in the service it provides.
  2. Which contract governs it, and whether it covers what paragraph 3 requires, with its eight points.
  3. Which sub-processors it uses, where the list is and how it notifies you of changes.
  4. What it does with the data outside the service, starting with whether it trains models on them.
  5. Where the data are processed, and under which mechanism if they leave the European Economic Area.

Article 28 is one of the five GDPR articles that already bind your AI, and it does not wait for any AI Act date.

Content in accordance with Articles 4, 26, 28 and 44 of Regulation (EU) 2016/679, cited from the text published in OJ L 119 of 4.5.2016.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Is a generative AI SaaS a processor or a controller?

It depends on the processing, not on the product. For what it does with your company's data to provide you with the service, on your behalf and on your instructions, it is a processor. If it also uses the data for purposes it decides itself, such as training its models, it sets the purposes and means of that processing and is its controller. That is why the contract should say what it does with your data and what it does not.

What if the vendor will not sign a DPA?

Article 28(3) does not require a document with that name: it requires the processing to be governed by a contract or other legal act that is binding on the processor and covers what the Article says, and it may sit within the terms of service. If the vendor offers nothing equivalent, there is no contract to review, and Article 28(1) only allows you to use processors that meet the test it sets.

What if the data leave the European Economic Area?

Point (a) of Article 28(3) includes transfers to third countries among the things the processor only does on your documented instructions, and Article 44 requires controller and processor to meet the conditions of Chapter V of the GDPR, onward transfers included. Ask the vendor for its list of sub-processors, the country where each one processes the data, and under which mechanism.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.