The data processing agreement is signed, filed and untouched ever since. In many shops that is exactly where processor management ends, and it is exactly where the part begins that Article 28 GDPR actually means: controlling the vendor and documenting that the control took place. This article shows which duties follow from the contract, which vendors in a shop are affected, what an audit looks like that holds up when someone asks, and which records should be on file. If the control part has been skipped so far, you will find the order in which it can be caught up here – from taking stock to the audit minutes, supported on request by our privacy consulting.
The contract exists, the control does not
In 2025 the German Federal Commissioner for Data Protection and Freedom of Information imposed a fine of 15 million euros on Vodafone GmbH because the company had not checked and monitored the partner agencies working for it as processors to a sufficient degree under data protection law (BfDI). Together with a second notice from the same proceedings, the fines added up to 45 million euros (BfDI). What matters here is less the amount than the allegation: it is not aimed at a missing contract but at missing control. Vendors had been engaged; too little had been checked.
The framework for this sits in Article 83(4) GDPR. Infringements of the obligations under Article 28 fall into that tier: fines of up to 10 million euros or up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher (EUR-Lex). The two values are not an alternative to choose from, and they are not standard penalties either: the higher amount applies, and both figures are upper limits. For most shops the absolute amount therefore sets the ceiling, because 2% of their annual turnover falls below it. What a supervisory authority actually imposes depends on the nature, gravity and duration of the infringement.
The contract under Article 28(3) GDPR is the first duty. The second is the ongoing assurance that the vendor does what the contract says. The first can be completed in an afternoon; the second runs alongside the entire business relationship. Anyone who only completes the first has filled a folder but has not produced the evidence.
What Article 28 requires and where the blind spot sits
Article 28(3) GDPR lists eight points that a data processing agreement has to cover, from acting on documented instructions through confidentiality to the return or deletion of data at the end of the engagement. The last point, letter (h), governs evidence and oversight: the processor makes available to the controller all information necessary to demonstrate compliance and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller (EUR-Lex). The right to audit is therefore secured by contract. Whether the controller uses it is its own decision. Whether it can demonstrate compliance is decided by that decision.
The purpose of such audits is to ensure that the controller has all the information about the processing activity carried out on its behalf and about the guarantees offered by the processor.
European Data Protection Board, Guidelines 07/2020, margin no. 144
The German supervisory authorities set out the core of this early on in their joint short paper on processing on behalf of a controller: the overall responsibility for the processing and the controller's duty to demonstrate compliance under Article 5(2) GDPR also cover the processing carried out by the processor (German Data Protection Conference). Accountability cannot be outsourced along with the work. It travels with the data and does not stop at the interface to the data centre, the shipping service or the agency.
Three duties that follow from one contract
- Duty of selection: before engaging a vendor, the controller checks whether it provides sufficient guarantees for appropriate technical and organisational measures. That is a check before signature, not after it.
- Duty of control: during the engagement, the controller satisfies itself that the agreed measures are in place. Article 28(3)(h) GDPR provides the contractual tool for this (EUR-Lex).
- Duty of evidence: the controller has to be able to document both. A phone call without minutes is not an audit in the sense of accountability; it is a phone call.
Which vendors in a shop are affected
In an average online shop the list is longer than most operators expect. A processor is anyone who processes personal data on behalf of and on the instructions of the controller, regardless of how much they charge for it and whether processing is their main purpose. The hosting provider belongs on the list, the shipping service does in many constellations, and so do the newsletter tool, the review system, the agency with backend access and the outsourced support desk. Anyone compiling this list in full for the first time usually finds services nobody had in mind any more, and contracts whose deletion periods do not match their own deletion concept.
Hosting and operations
The server the shop runs on processes every order along the way. Supervisory authorities have audited the data processing agreements of web hosts for precisely that reason (Berlin Data Protection Authority).
Payment and fraud prevention
Payment services usually act as controllers in their own right for settlement. Check the role before the contract, otherwise you end up with a document for the wrong constellation.
Shipping and returns
Address, contact and consignment data leave the shop. Where the vendor acts on instructions, Article 28 applies; where it fulfils its own legal duties, it does not.
Marketing and analysis
Newsletters, reviews and campaigns touch contact data. The connection to Google Ads belongs in the inventory as well.
Agency and development
Every backend login is access to real customer data. The contract belongs with the access, not with the end of the project.
Support and day-to-day operations
Ticket systems, telephony and remote maintenance see orders and accounts. Even short-lived access can be processing on behalf of the controller if access to personal data cannot be ruled out.
How much processing has been outsourced is visible in the annual survey on the use of information and communication technologies by the German Federal Statistical Office: 54% of companies in Germany with at least 10 employees used paid cloud services over the internet in 2025 (Destatis). Broken down by size class, the figure was 51% for small companies with 10 to 49 employees and 86% for large companies (Destatis). Every one of these services is a candidate for a data processing agreement as soon as personal data ends up in it, and every agreement brings the duty of control with it.
Payment service providers usually act as controllers in their own right for the settlement of a payment, because they are subject to their own regulatory duties. Article 28 GDPR does not apply to them, but clear information for customers about the transfer does. The classification belongs before the contract: signing a data processing agreement with a separate controller gets you a document, but not the right one. For cloud operations the classification is usually clear, because the provider processes on instructions there.
Sub-processors: the strand that branches off
A hosting provider rarely runs the server alone. It rents space in a data centre, has backups created by another service and brings in support for database maintenance. Each of these steps creates a sub-processor. Article 28(4) GDPR requires the processor to impose on that sub-processor the same data protection obligations as are set out in the original contract. In its Opinion 22/2024 the European Data Protection Board made clear that this does not relieve the controller: even where the processor passes the obligations on, the controller remains responsible for ensuring and demonstrating compliance with Article 28(1) and Article 24(1) GDPR (European Data Protection Board).
In practice this means the list of sub-processors belongs in the contract or at a named location the controller knows and can retrieve. If it changes, either prior specific authorisation or general written authorisation with a right to object applies. A general authorisation without effective notification runs empty, because anyone who does not learn about a new sub-processor cannot object. Where data is held across several countries, the chain also becomes a question of jurisdiction; we worked through that using the example of the sovereign cloud.
- Name, address and country of establishment of the sub-processor, plus the service it provides
- The basis of the authorisation: prior specific authorisation or general written authorisation with a period for objection
- The channel through which changes are announced and the period within which an objection is possible
- Evidence that the data protection obligations from the original contract were passed on (Article 28(4) GDPR)
- The categories of personal data that actually reach the sub-processor, which is often less than at the main vendor
A register that only knows the first level describes the processing incompletely. Record the second level as well, even though it comes from the vendor rather than from your own organisation. Anyone planning to change providers later needs the chain anyway: switching cloud providers requires knowing where which data sits and who touches it.
The audit itself: what counts and what does not
What an audit looks like in practice was described by the European Data Protection Board in its report on the coordinated enforcement action on cloud use, although for public bodies rather than for companies. The report states that most of the public stakeholders surveyed carry out periodic checks through the annual verification of certification reports and the documentation published by the provider but generally do not carry out their own audits, including inspections, at their cloud providers (European Data Protection Board). The finding describes the situation in the public sector and cannot simply be transferred to companies. It does, however, mark exactly the line between a paper review and an on-site inspection.
The reach of that action is modest and instructive for that very reason: around 100 public bodies from areas such as health, finance, tax and education were addressed across the European Economic Area in 2022, including EU institutions (European Data Protection Board). The investigation was carried out by 22 supervisory authorities across the EEA acting in a coordinated way (European Data Protection Board). For a shop whose cloud operations sit with a large provider, a sober expectation follows: the provider will rarely grant an individual on-site inspection, whereas an audit report and a documented evaluation of it are within reach.
The finding on cloud use comes from a survey of public bodies, not from a survey of companies. It says nothing about how many online shops audit their processors. Transferring the statement confuses two populations. For your own work a different question counts anyway: what is documented here, and how old is the document?
Four audit depths and when each one is enough
| Audit depth | What you end up holding | When it is appropriate |
|---|---|---|
| Self-assessment | Completed questionnaire, dated and signed | Services without access to order data, low risk |
| Document review | Description of technical and organisational measures, sub-processor list, deletion concept | Standard services with a limited data scope |
| Third-party audit report | Valid audit report or certificate with scope and audit period | Large providers where an individual audit is not available |
| Own audit including inspection | Audit minutes with date, auditor, questions, answers and findings | Hosting, shipping and support with the full order record |
Which depth is appropriate depends on the risk to the individuals concerned, not on the size of the vendor. A small tool that sees complete order records including addresses calls for more than a large service that only processes pseudonymous identifiers. Services that would like to use data beyond the pure performance of the contract deserve particular attention: with AI features in a shop that is the decisive question, because further processing for the vendor's own purposes takes it out of the role of a processor.
Who pays for the audit
The question comes up by the second appointment at the latest. Guidelines 07/2020 of the European Data Protection Board answer it briefly in margin no. 145: the question of how costs are allocated between a controller and a processor in connection with audits falls outside the GDPR and is subject to economic considerations (European Data Protection Board). That is not a licence for arbitrary pricing, though. The same margin number draws the line: the parties should not agree clauses that have clearly unreasonable or disproportionately high costs and fees as their subject matter and would thereby have a deterrent effect on one of the parties (European Data Protection Board).
For contract negotiations this yields a usable position: an audit fee is permissible, an audit blockade through the back door is not. Anyone finding a flat fee in a draft contract that clearly exceeds the effort of an audit has an argument in hand. It also helps to record in the contract how many audits per year are possible without separate charges and what an additional appointment costs. In our shop check we look at these clauses together with the technical measures, because both sides answer the same question: what has actually been implemented?
Not every audit is an on-site appointment. A structured questionnaire that demands evidence, a video call with screen sharing on the logs and a written confirmation of the answers fulfil the purpose the guidelines describe: giving the controller all the information about the processing and the guarantees offered (European Data Protection Board). What matters is that a dated set of minutes exists at the end, recording the course of the audit and its findings.
What supervisory authorities actually look at
On 19 July 2022 several German data protection supervisory authorities announced a coordinated audit of the data processing agreements used by web hosts. Alongside the Berlin authority, five further state data protection authorities took part, namely those of Lower Saxony, Rhineland-Palatinate, Saxony, Saxony-Anhalt and Bavaria (Berlin Data Protection Authority). As the reason for the audit they stated that many data processing agreements do not provide for sufficient evidence from the web host that it implements the agreed data protection measures (Berlin Data Protection Authority). The audit itself was carried out on the basis of a checklist for data processing agreements developed specifically for it (Berlin Data Protection Authority). According to the authorities, the trigger was enquiries from controllers who considered the agreements offered to be inadequate; their previous reviews had repeatedly confirmed that impression, for instance regarding the missing evidence (Berlin Data Protection Authority). We have not found a published overall result of the coordinated audit.
How much audit capacity exists at all can be read from the annual activity reports. The German Federal Commissioner for Data Protection and Freedom of Information recorded a total of 11,824 submissions in 2025, including complaints and enquiries (BfDI). In the same year the authority carried out 80 on-site inspections and 40 written checks (BfDI) and took a total of 129 supervisory measures (BfDI). These figures relate to the federal remit; online shops fall under the supervisory authorities of the German states.
There the numbers are climbing noticeably. At the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, submissions rose from 12,490 in 2024 to 18,062 in 2025 (LDI NRW); the data protection complaints they contain grew from 7,539 to 12,592 (LDI NRW). In Baden-Württemberg the State Commissioner recorded a record 7,673 complaints in 2025 (Baden-Württemberg Data Protection Commissioner), issued 101 fine notices totalling 308,850 euros (Baden-Württemberg Data Protection Commissioner) and opened 314 fine proceedings, up from 243 the year before (Baden-Württemberg Data Protection Commissioner). The number of reported data breaches there rose from 3,559 in 2024 to 4,059 in 2025 (Baden-Württemberg Data Protection Commissioner). Part of such reports originates not in your own organisation but at a vendor, which is why account takeover defence and the reporting channels need to be settled together with the processors.
None of the activity reports quoted breaks complaints, inspections or fines down by GDPR article. The figures therefore do not allow any conclusion about how many proceedings concerned processing on behalf of a controller. They describe the overall workload of the supervisory authorities, not the share attributable to Article 28. Reading them differently builds a statement on a figure that does not carry it.
Records that hold up when it matters
An audit nobody wrote down does not exist when someone asks. The evidence consists of three parts: the register recording who processes which data for which purpose; the audit plan setting out when who audits at which depth; and the minutes recording what came out of it. The register also covers who inside your own organisation has access to the vendor's administration interface: the question of backend roles and permissions comes up again with every external account.
- The signed contract covering all eight points of Article 28(3) GDPR and the date of the latest version
- The description of the technical and organisational measures, dated and attached to the contract as an annex
- The current list of sub-processors including the authorisation route and the period for objection
- Evidence of the selection check: what was examined before the engagement and with what result
- The minutes of the last audit with date, auditor, questions asked, answers and open points
- The date of the next audit due and the person responsible for it
A register that tracks deadlines
{
"vendor": "Hosting provider (placeholder)",
"role": "processor",
"purpose": "operation of the shop instance, the database and the backups",
"data_categories": ["customer accounts", "order data", "payment status", "server logs"],
"contract": {
"version": "2026-02-01",
"article_28_3": ["a", "b", "c", "d", "e", "f", "g", "h"],
"tom_annex": "annexes/tom-hosting-2026-02-01.pdf",
"sub_processing": "general authorisation, 30 days to object"
},
"sub_processors": [
{"service": "data centre space and power", "country": "DE", "as_of": "2026-02-01"},
{"service": "backup copies", "country": "DE", "as_of": "2026-02-01"}
],
"audit": {
"depth": "document review",
"last_audit": "2026-03-12",
"next_audit": "2027-03-12",
"minutes": "minutes/2026-03-12-hosting.pdf",
"open_findings": 0,
"owner": "data protection coordination"
}
} Two fields make the difference between a list and a working tool: the date of the last audit and the date of the next one. Without them the register is a snapshot; with them it becomes a reminder system. It has proven useful to keep the files in the same location as the other operating documents and to update them with every contract change. Anyone working with copies of production data should apply the same care to the test environment; how to build staging without customer data is something we have described separately.
What 2026 and 2027 add to the picture
The supervisory authorities work together in coordinated enforcement actions and pick a focus topic for each year. In 2026, 25 data protection authorities are taking part in the joint action of the European Data Protection Board (European Data Protection Board). This time the subject is the transparency and information obligations under Articles 12, 13 and 14 GDPR, that is, how understandably individuals are informed about processing, and not processing on behalf of a controller under Article 28. During the second half of the year the participating authorities intend to bring their findings together; a consolidated report is to be drafted from them and submitted for adoption by the Board (European Data Protection Board). For shops this matters indirectly, because only those who know their vendors can keep a privacy notice complete.
On the procedural side there is movement as well. Regulation (EU) 2025/2518 lays down additional procedural rules for the enforcement of the GDPR and applies from 2 April 2027 (Official Journal of the European Union). It harmonises how cross-border proceedings run between supervisory authorities. No substantive obligation under Article 28 changes as a result, but the speed at which a case can be handled across borders does. Anyone who has put the records on their processors in order by then only has to pull them out when the occasion arises.
How we approach this
We start by taking stock: which services touch personal data, which contracts exist, which are missing and which no longer match the actual processing. We then sort the vendors by risk and define the audit depth for each group. That classification produces an audit plan with dates and named owners, a register that tracks deadlines and templates for questionnaires and minutes. Our privacy consulting handles the classification and the documentation, and we review the technical side in the same pass. Where contracts in B2B business hang on framework agreements, we align the terms with each other; how framework agreements and call-off orders are mapped in a shop is a topic of its own.
The figures and legal references in this article come from press release 6/2025 of the German Federal Commissioner for Data Protection and Freedom of Information, its press release on the 34th activity report, the press release on the 2025 data protection activity report of the Baden-Württemberg State Commissioner, the notice on the 31st activity report of the North Rhine-Westphalia State Commissioner, press release no. 416 of the German Federal Statistical Office, Guidelines 07/2020 and Opinion 22/2024 of the European Data Protection Board, its report on the coordinated enforcement action on cloud use in the public sector and its notice on the 2026 coordinated action, short paper no. 13 of the German Data Protection Conference, the press release of the Berlin Data Protection Authority on the audit of web hosts' data processing agreements, and the text of Regulation (EU) 2016/679 and Regulation (EU) 2025/2518. All sources were verified at origin on 14 September 2026.
The contract is one half, the control is the other. Article 28(3)(h) GDPR obliges the processor to allow for and contribute to audits, including inspections (EUR-Lex). The overall responsibility and the controller's duty to demonstrate compliance under Article 5(2) GDPR also cover the processing carried out by the processor (German Data Protection Conference). Without a documented audit the evidence is missing.
The GDPR does not name an interval. A risk-based staggering has proven workable in practice: services with the full order record annually, services with a limited data scope every two years, plus an ad-hoc appointment after incidents, contract changes or a change of sub-processor. What matters is that the chosen rhythm is justified, documented and kept to.
As a rule, no. The purpose of an audit is to give the controller all the information about the processing and the guarantees offered (European Data Protection Board). That is often achieved through a structured questionnaire demanding evidence, the evaluation of an audit report and a video call. An on-site inspection remains the instrument for high-risk vendors or where there are concrete doubts.
The allocation of costs between controller and processor falls outside the GDPR and is subject to economic considerations (European Data Protection Board). The same margin number of Guidelines 07/2020 draws a line, though: the parties should not agree clauses covering clearly unreasonable or disproportionately high costs and fees that would have a deterrent effect on one of them (European Data Protection Board). An audit fee is therefore possible, an audit blockade through pricing is not.
Under Article 28(4) GDPR the processor has to impose on them the same data protection obligations as are set out in the original contract. That does not relieve the controller: it remains responsible for ensuring and demonstrating compliance with Article 28(1) and Article 24(1) GDPR (European Data Protection Board). In practice this means keeping a list, defining the authorisation route and documenting changes in a traceable way.
The range is up to 10 million euros or up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher (EUR-Lex). Both values are upper limits. That the provision is applied is shown by the 2025 proceedings in which a fine of 15 million euros was imposed for insufficient checking and monitoring of partner agencies (BfDI).