BLOG · GUIDE ·

GDPR cloud hosting: what the Article 28 DPA, the subprocessor list and transfer terms must cover

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • A company that hosts personal data with a cloud or hosting provider is normally the controller and the provider its processor; in the EDPB’s example even a host that only stores encrypted data is a processor, because storage is processing
  • Article 28(3) GDPR requires a written contract, the data processing agreement, that describes the processing and binds the provider to documented instructions, confidentiality, Article 32 security, the conditions for engaging another processor, assistance to the controller, deletion or return at the end and audits
  • Engaging another processor (a subprocessor) needs the controller’s prior specific or general written authorisation; under a general one the provider must flag each intended change so the controller can object, and the EDPB finds a list updated from time to time without such notice insufficient
  • For the EDPB, remote access from a third country, for example for support, is a transfer just as storage outside the EEA is, and it needs a basis in Chapter V, such as an adequacy decision or the Commission’s standard contractual clauses of 4 June 2021
  • Transfers to US organisations participating in the EU-US Data Privacy Framework need no further authorisation; the General Court dismissed an action against that adequacy decision on 3 September 2025, and as of 6 October 2026 we found no judgment in the appeal, Case C-703/25 P, and could not confirm its status on the Court’s own website

Eurokommerz × Vixen.UNO: EU Cloud  Talk to an expert →

GDPR cloud hosting: controller, processor and the Article 28 contract

When a company stores personal data with a hosting or cloud provider, the company is normally the controller and the provider a processor, and Article 28 GDPR requires a binding written contract between them, the data processing agreement (DPA). The provider may engage another processor (a subprocessor) only with the company’s prior specific or general written authorisation, and storing the data outside the EEA (the EU plus Iceland, Liechtenstein and Norway), or reaching it from there, has to meet the transfer rules of Chapter V. Under Article 5(2) the controller “shall be responsible for, and be able to demonstrate compliance with” the principles of Article 5(1), security among them.

Article 4(8) defines a processor as a person or body that “processes personal data on behalf of the controller”, the controller being the one that determines the purposes and means of the processing (Article 4(7)). In the example “Hosting services” of the EDPB’s Guidelines 07/2020 on the concepts of controller and processor (version 2.1, adopted on 7 July 2021), a host that only stores an employer’s encrypted data on its servers is a processor, because “storage is one example of a personal data processing activity”.

Under Article 28(1) the controller may use only processors “providing sufficient guarantees to implement appropriate technical and organisational measures”. With IaaS the provider’s measures cover hosts, hypervisor, storage and network, while guest operating systems and applications remain your responsibility, as our comparison of IaaS, private cloud and hybrid sets out.

What Article 28(3) requires in a data processing agreement

Article 28(3) requires a contract or other legal act, binding on the processor, that sets out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects and the controller’s obligations and rights, in writing, “including in electronic form” (Article 28(9)). It has to stipulate, in particular, points (a) to (h) below. In the EDPB’s guidelines, the agreement “should not, however, merely restate the provisions of the GDPR” but state how each requirement will be met.

ARTICLE 28(3)WHAT IT MUST SAYWHAT TO CHECK
(a) Instructionsonly your documented instructions, transfers included, unless Union or Member State law requires otherwise, with prior notice to you where that law allowsstorage and access locations; a legal exception limited to EU and Member State law
(b) Confidentialityeveryone authorised to process the data is bound to confidentialityoperations, support and subprocessors’ staff included
(c) Securityall measures required by Article 32a measures annex for this service, your approval before changes, regular review
(d) Subprocessorsthe conditions of Article 28(2) and (4) for engaging another processora named list, notice before each change, a right to object
(e) Data subject rightsassistance with requests, as far as the processing allowshow one person’s data is found, exported and erased
(f) Articles 32 to 36assistance with security, breach notification, impact assessments and consulting the authoritybreach notice within a set number of hours, contact point, minimum content
(g) End of contractdeletion or return at your choice, deletion of copiesbackups and snapshots included, return format, written confirmation
(h) Information, auditsinformation to demonstrate compliance; audits and inspectionswhich reports and certificates, their scope, on-site audit terms

GDPR Article 28(3); EDPB Guidelines 07/2020, version 2.1, paragraphs 126, 128 and 135 to 137. The right-hand column is our reading.

The contract may be based on standard contractual clauses of the Commission (Article 28(6) and (7)), and those of Implementing Decision (EU) 2021/915 of 4 June 2021 “fulfil the requirements for contracts between controllers and processors in Article 28(3) and (4)”.

Point (a) permits processing beyond your instructions only where “Union or Member State law” requires it. In Opinion 22/2024 of 7 October 2024 the EDPB calls including those words “highly recommended but not mandatory” and leaves broader variants, such as “unless required to do so by law or binding order of a governmental body”, to the parties’ contractual freedom. For data transferred outside the EEA, however, it considers such a variant unlikely to satisfy Article 28(3)(a) read with Chapter V on its own.

GDPR subprocessors: authorisation and flow-down under Article 28(2) and (4)

Article 28 calls a subprocessor “another processor”, and its paragraph 2 reads: “The processor shall not engage another processor without prior specific or general written authorisation of the controller.” With a general authorisation, the processor informs the controller of any intended addition or replacement of other processors, “thereby giving the controller the opportunity to object to such changes”. The EDPB reads this as a duty to actively flag each change and adds in a footnote that access to a list of subprocessors “which might be updated from time to time, without pointing to each new sub-processor envisaged” is not sufficient. A subprocessor web page therefore does not replace a notice to the controller for each change.

Clause 7.7(a) of the Commission’s Article 28 clauses offers two options, prior specific authorisation or a general authorisation for subprocessors “from an agreed list” with written notice of intended changes “at least [SPECIFY TIME PERIOD] in advance” and the information needed to object. Article 28(4) requires the same data protection obligations to be imposed on the other processor by a contract or other legal act, and if it fails to fulfil them, “the initial processor shall remain fully liable to the controller”.

Opinion 22/2024 adds that controllers should have “the information on the identity (i.e. name, address, contact person) of all processors, sub-processors etc. readily available at all times”, whatever the risk, and that the processor should provide it proactively. Customers in scope of NIS2 ask suppliers about subcontractors too, as our guide to NIS2 supplier requirements explains.

Our contracts name Vixen.UNO for engineering and Baltneta for hosting, and if a project needs anyone else, you hear about it before it happens. Tell us which processor terms your legal department requires.

Article 32 security measures in the hosting contract

Article 32(1) requires controller and processor to ensure “a level of security appropriate to the risk”, including, as appropriate, pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, the ability to restore availability and access to personal data “in a timely manner” after a physical or technical incident, and regular testing of the measures. For the contract, the EDPB expects information on the measures, the processor’s obligation to obtain your approval before changing them and a regular review “so as to ensure their appropriateness with regard to risks, which may evolve over time”.

Ask for an annex that names the service, its encryption at rest and in transit, administrative access and its logging, and the backup and restore arrangements. An ISO/IEC 27001 certificate covers the entity and scope written on it, so check whether it belongs to the company you sign with or to its data-centre operator.

Transfers outside the EEA: adequacy, the Data Privacy Framework and SCCs

Article 44 allows transfers to a third country only under the conditions of Chapter V, “including for onward transfers”. The EDPB’s Recommendations 01/2020 on measures that supplement transfer tools (version 2.0, adopted on 18 June 2021) state that “remote access from a third country (for example in support situations) and/or storage in a cloud situated outside the EEA offered by a service provider, is also considered to be a transfer”. For an international cloud infrastructure, the EDPB expects you to assess whether and where data will be transferred, onward transfers to subprocessors included, unless the provider is established in the EEA and clearly states in its contract that the data will not be processed in third countries at all. Without instructions that allow transfers, a processor may not “have the data processed in one of his non-EU divisions”, the controller and processor guidelines add.

Article 45(1) allows transfers to a country the Commission has found adequate, and “Such a transfer shall not require any specific authorisation.” As of October 2026 the Commission’s list includes Switzerland, the United Kingdom and Japan, among others, and for the United States the commercial organisations participating in the EU-US Data Privacy Framework. Under Implementing Decision (EU) 2023/1795 of 10 July 2023 these organisations certify and re-certify every year, and the US Department of Commerce keeps a public list of them, so check the entry of each US subprocessor. On 3 September 2025 the General Court dismissed an action for annulment of the decision (Case T-553/23). An appeal, Case C-703/25 P, was brought on 31 October 2025; as of 6 October 2026 we found no judgment in it and could not confirm its status on the Court’s own website. Our article on the CLOUD Act and EU data residency covers US law and GDPR Article 48.

Without an adequacy decision, Article 46 requires appropriate safeguards, among them standard data protection clauses adopted by the Commission (Article 46(2)(c)). The current set, Implementing Decision (EU) 2021/914 of 4 June 2021, serves importers whose processing is not subject to the GDPR. A company that hosts directly with such a provider uses Module Two, “Transfer controller to processor”, and a provider in the EU that passes data to such a subprocessor uses Module Three, “Transfer processor to processor”. In both modules, Clause 9 offers the same two options for subprocessors as Clause 7.7. Under Clause 14 the parties warrant that they have “no reason to believe” that the destination’s laws and practices prevent the importer from fulfilling its obligations, and they document that assessment and make it available to the supervisory authority on request. Contracts on the older clauses of Decision 2010/87/EU were deemed to provide appropriate safeguards only until 27 December 2022, so a DPA that still cites them is out of date.

Article 49(1) adds derogations for specific situations, such as explicit consent; its last resort requires, among other conditions, a transfer that “is not repetitive” and “concerns only a limited number of data subjects”. Which tool fits a given provider and data set is a legal assessment for your legal department. Our guide to sovereign cloud in the EU treats location, operator and administrative access as sovereignty questions.

Records of processing, erasure and the end of the contract

Under Article 30(1) the controller’s record of processing activities names “the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries” and any transfers, with “the identification of that third country”. The provider’s subprocessor list and access locations belong in those entries, so update the record with each change notice.

Article 17(1) obliges the controller to erase personal data “without undue delay” where one of its grounds applies, and point (e) of Article 28(3) has the provider assist. At the end, point (g) has the provider delete or return all data at your choice and delete existing copies “unless Union or Member State law requires storage of the personal data”, so ask how backups and snapshots expire. Exit periods under the Data Act are set out in our guide to Data Act cloud switching.

How to review a hosting provider’s DPA and subprocessor list

  1. List the systems to be hosted, their data classes and categories of data subjects, special categories under Article 9(1), such as data concerning health, included.
  2. Compare the DPA with points (a) to (h) of Article 28(3) and with the clauses of Decision (EU) 2021/915, and mark points that only repeat the Regulation.
  3. Check the legal exception and transfer terms in the instructions clause, and change approval and review in the security annex.
  4. Ask for the subprocessor list with names, addresses, roles and locations, and for the notice period and channel for changes.
  5. Ask from which countries the provider’s and each subprocessor’s staff can reach systems or data, support included, which transfer tool covers each, and, for standard contractual clauses, the module and the documented Clause 14 assessment.
  6. Check the breach notification time, the audit terms, and deletion and return, backups included.

We fill in supplier questionnaires and provide our data processing agreement on request at proposal stage, with subprocessors listed. Send us the checklist your legal department uses through the form below.

General information on EU law as of October 2026, not legal advice for an individual case.

What we do

Our EU Cloud service hosts IaaS or a private cloud in Baltneta’s Tier-3 data centres in Lithuania, certified to ISO 27001 and PCI DSS Level 1, and data and backups stay in the EU. Baltneta operates the platform, engineering is delivered by our engineering partner Vixen.UNO, and both are named in the contract. Our security and compliance page lists what we sign, including an NDA before technical detail and a data processing agreement under Article 28 GDPR on request. The first call is free of charge, and the price of the technical assessment is fixed before work begins.

FAQ

Is a cloud hosting provider a processor under the GDPR?
Where a provider stores or otherwise processes personal data on a customer’s behalf, the customer is normally the controller and the provider a processor under Article 4(7) and (8) GDPR, and Article 28 requires a written contract between them. The EDPB’s Guidelines 07/2020 give the example of a hosting service that only stores an employer’s encrypted data on its servers and is still a processor, because storage is processing. A processor that infringes the Regulation by determining the purposes and means of a processing itself is considered a controller for that processing under Article 28(10).
What must a data processing agreement under Article 28 GDPR contain?
Article 28(3) requires the contract to set out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects and the controller’s obligations and rights. The processor must commit to act only on documented instructions, including on transfers, to confidentiality, to the security measures of Article 32, to the conditions for engaging another processor, to assisting with data subject requests and with Articles 32 to 36, to deleting or returning the data at the end and to supporting audits. The EDPB expects the agreement to say how each point will be met rather than restate the Regulation.
How does subprocessor approval work under the GDPR?
Article 28(2) lets a processor engage another processor only with the controller’s prior specific or general written authorisation. Under a general authorisation the processor must inform the controller of any intended addition or replacement of other processors so that the controller can object, and the EDPB considers a list that is updated from time to time without pointing to each new subprocessor insufficient. Article 28(4) requires the same data protection obligations to be imposed on that other processor by a contract or other legal act, and the initial processor remains fully liable to the controller for the performance of that other processor’s obligations.
Is remote support access from outside the EU a data transfer under the GDPR?
The EDPB’s Recommendations 01/2020 on measures that supplement transfer tools, version 2.0 adopted on 18 June 2021, state that remote access from a third country, meaning one outside the EEA, for example in support situations, is also considered a transfer. Such access needs a basis in Chapter V, such as an adequacy decision for the country or standard contractual clauses, and under Article 28(3)(a) the processor may transfer data only on the controller’s documented instructions. Ask each provider from which countries its own staff and its subprocessors’ staff can reach systems or data.
Which standard contractual clauses apply to cloud hosting?
Two sets of Commission clauses of 4 June 2021 are relevant to hosting. Implementing Decision (EU) 2021/915 covers the Article 28 contract between controller and processor, and Implementing Decision (EU) 2021/914 covers transfers to importers outside the EEA whose processing is not subject to the GDPR in four modules, among them Module Two for a company that hosts directly with such a provider and Module Three for a provider in the EU that uses such a subprocessor. Under Clause 14 of the transfer clauses the parties warrant that they have no reason to believe the destination’s laws and practices prevent the importer from fulfilling its obligations, and they document that assessment.
What makes cloud hosting GDPR compliant?
Under Article 5(2) the controller remains responsible for the processing and must be able to demonstrate compliance, so a hosting provider supplies the processor’s share: sufficient guarantees under Article 28(1), a contract with the contents of Article 28(3), security measures under Article 32 and transfers that meet Chapter V. Check the subprocessor list and change process, the countries from which data can be reached, the breach notification and audit terms, and deletion at the end of the contract. Certificates count as evidence only for the entity and scope written on them.

Send us the systems and data classes you plan to host, your legal department’s requirements for the processor contract and the supplier questionnaire you use. We reply within one business day to arrange a first call, from which you leave with two or three configuration options and an indicative monthly invoice; our data processing agreement under Article 28 GDPR is available on request at proposal stage. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna