GDPR Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures the data, assists with data subject requests, deletes or returns data at the end, and allows audits.

Checked 2026-10-01

Vendor
not restricted
Product
not restricted
Subsystem
processors
Deployment
multi-tenant
Region
eu-eea
Release range
current as of 2026-10-01
Checked
2026-10-01

Sources

Cite this note

APA

WarmTransfer. (2026, October 1). GDPR for contact centers and call recording: source note gdpr-contact-center-processor-contract-terms. WarmTransfer. https://warmtransfer.net/knowledge/claims/gdpr-contact-center-processor-contract-terms

BibTeX

@misc{warmtransfer-claim-gdpr-contact-center-processor-contract-terms,
  title  = {GDPR for contact centers and call recording: source note gdpr-contact-center-processor-contract-terms},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/gdpr-contact-center-processor-contract-terms},
  note   = {Source note gdpr-contact-center-processor-contract-terms, checked 2026-10-01}
}

Read in context