This article is for anyone contracting an AI service — an assistant, a transcription tool, an agent — that will process personal data about their company's customers, employees or candidates, and who has a set of terms and a data protection annex in front of them to sign. Before reading them, it helps to know what role the vendor plays, because that role determines what the contract has to say.
In most cases the answer is the same. Your company decides what the data are used for and the vendor processes them to provide you with the service: your company is the controller and the vendor, the processor. The GDPR defines a processor as a person or body "which processes personal data on behalf of the controller", and a controller as whoever, "alone or jointly with others, determines the purposes and means of the processing of personal data".
First, the role
The figure walks through the question in two steps. If the vendor processes the data on your company's behalf, it is a processor (Article 4(8)), and the Article 28(3) contract shall stipulate, in particular, the eight points from (a) to (h), which the figure summarises. If it does not process them on your behalf and you jointly set the purposes and means, you are joint controllers (Article 26(1)); if it sets them alone, it is the controller of that processing (Article 4(7)). A dashed line runs from processor to controller: a processor that sets the purposes and means on its own becomes the controller of that processing (Article 28(10)).
The role is decided processing by processing: the same service can be a processor for what it does to provide you with the service and the controller of another processing operation it decides itself, such as training its own models on those data. So the first question to put to the vendor is what it does with your company's data and who decides it.
Nor is it the AI Act role. The AI Act assigns other roles — provider and deployer — on other criteria: fine-tuning an open model can turn your company into a provider for AI Act purposes, and Article 28 GDPR does not answer that question.
Before the contract: whom you choose
Article 28 starts before you sign. Its paragraph 1 says that "the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures". The burden sits with whoever chooses: if the vendor cannot explain where it processes the data, who has access to them or what it does with them when the contract ends, it has given you nothing to weigh. The ten questions of a proper due diligence are there for that, and their answers end up in the contract.
Sub-processors
An AI service almost always relies on others — the cloud, a third party's model, email — and each of them that processes your data is another processor. Paragraph 2 sets the rule: "The processor shall not engage another processor without prior specific or general written authorisation of the controller." Where the authorisation is general, "the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes".
And paragraph 4 binds the sub-processor by "the same data protection obligations as set out in the contract or other legal act between the controller and the processor", and if it fails, "the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations".
In practice: a list of sub-processors you can check, notice before each change and a period in which to object. Alethexis, for example, publishes its own on the sub-processors page and gives 30 days' notice.
The contract, point by point
Paragraph 3 requires the processing to be governed by "a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller". It then lists eight points that the contract shall stipulate, in particular. The table goes through them with a worked example: how the Alethexis data processing agreement, the one we know from the inside, covers each point.
| Point | What the contract must stipulate | Example: the Alethexis data processing agreement |
|---|---|---|
| (a) Instructions | Processing only on documented instructions, including for transfers to third countries | Clause 6.1: the agreement and its annexes, the accepted terms, the customer's configuration in the service and anything it sends in writing to [email protected] |
| (b) Confidentiality | A commitment to confidentiality, or a statutory obligation, for authorised persons | Clause 6.2: a confidentiality undertaking, training and access only where necessary |
| (c) Security | The measures required by Article 32 | Clause 6.3: refers to Annex III of the agreement, which may be updated without reducing the level of protection |
| (d) Sub-processors | The conditions of paragraphs 2 and 4 | Clause 6.4: general authorisation, a public list, 30 days' notice and a right to object |
| (e) Rights | Assisting the controller with people exercising their rights | Clause 6.5: access, export and deletion within the service itself, and technical assistance where they are not enough |
| (f) Articles 32 to 36 | Assistance with security, personal data breaches, the impact assessment and prior consultation | Clause 6.6: Annex III, notification of personal data breaches under clause 8 and information for the impact assessment |
| (g) End of the service | Deleting or returning the data at the end, at the controller's choice | Clause 6.7: under clause 10, with deletion staged across five levels |
| (h) Audits | Information to demonstrate compliance, and audits, including inspections | Clause 6.8: information and audits under clause 9 |
The paragraph ends with an obligation that has no letter: "the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions". The Alethexis agreement covers it in clauses 6.1 and 6.8.
If a point is missing from a vendor's contract, or appears only as a generic promise to respect the law, that is the conversation still to be had before signing.
When the vendor is not a processor
There are three other outcomes, and the figure draws them.
Joint controllers. "Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers." This happens when the vendor decides with you why and how the data are processed: the relationship is then between two controllers, and the instrument is not the Article 28 contract.
Controller of its own processing. If the vendor uses the data for purposes it decides itself — training its models, improving other products — it is the controller of that processing, because it is the one setting the purposes and means. Which data that use reaches, and whether the contract allows it or rules it out, is the first thing to check.
The processor that steps out of its role. Article 28(10) provides for this case: "Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing." It is not an exit the contract offers, but the consequence of stepping outside it.
If the service is an agent connected to other tools, the question repeats for every service it opens access to; we cover it in the article on the AEPD guidance.
Transfers outside the European Economic Area
Point (a) of paragraph 3 includes transfers among the things the processor only does on documented instructions: the contract shall stipulate that it processes the data that way, "including with regard to transfers of personal data to a third country or an international organisation". And Article 44 only allows a transfer if "the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers": those made from that third country or international organisation to another.
The practical question is where the vendor and each sub-processor process the data; a good sub-processor list says so, with the mechanism for each one.
What to have in writing
For each AI vendor that processes your company's personal data, five answers:
- What role it has in each processing operation, not only in the service it provides.
- Which contract governs it, and whether it covers what paragraph 3 requires, with its eight points.
- Which sub-processors it uses, where the list is and how it notifies you of changes.
- What it does with the data outside the service, starting with whether it trains models on them.
- Where the data are processed, and under which mechanism if they leave the European Economic Area.
Article 28 is one of the five GDPR articles that already bind your AI, and it does not wait for any AI Act date.
Content in accordance with Articles 4, 26, 28 and 44 of Regulation (EU) 2016/679, cited from the text published in OJ L 119 of 4.5.2016.
This article is for informational purposes only and does not constitute legal advice.