Certix

Freelancer and processor: the art. 28 GDPR contract your client expects (and the AEPD requires)

Certix
Certix®
· 2 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

The independent professional providing services to companies frequently accesses personal data of which their client is the controller: blog subscribers, CRM contacts, form leads, registered users of the website, end customers in invoicing, private social messages. The moment the freelancer accesses that data on the client's behalf, they become a processor within the meaning of art. 28 of the GDPR (Regulation (EU) 2016/679), and their relationship with the client must be governed by a specific contract.

This guide explains when the figure applies, what minimum content the contract must have under GDPR and the LOPDGDD (Spain's Organic Law 3/2018), and how all of this translates to the typical scenarios of the web designer, the bespoke developer and the marketing or business consultant.

When the freelancer is a processor

The processor figure appears when someone processes personal data on behalf of a controller, following their instructions, without determining their own purposes. It does not depend on the contractual title (consultant, collaborator, self-employed) but on actual access to the client's personal data.

Freelance profile Data accessed Usual figure
Web designer Client CMS dashboard, forms, subscriber list, comments. Processor
Developer (web or app) Production database, logs with IPs, registered users, backups. Processor
Marketing consultant CRM, email tool, advertising audiences, client leads. Processor
Community manager Private messages, comments, campaign data, followers. Processor
Copywriter without list access Commercial copy only, no recipient data. Not a processor
Graphic designer (logo, branding) No access to personal data of third parties. Not a processor

Minimum content of the art. 28 GDPR contract

Art. 28.3 GDPR lists the mandatory content of the contract between controller (client) and processor (freelancer). Summarised in practical blocks:

  • Subject-matter and scope: what service is provided, what specific processing it involves (CMS access, newsletter management, database maintenance...).
  • Duration: tied to the main services contract.
  • Nature and purpose: functional description, without abstractions.
  • Type of data and categories of data subjects: end customers, subscribers, controller's employees, etc.
  • Processing data only on documented instructions from the client.
  • Confidentiality of the freelancer and any person authorised under their responsibility.
  • Security measures technical and organisational (art. 32 GDPR) proportionate to the risk.
  • Sub-processors: authorisation and notification regime.
  • Assistance to the controller with data subject rights (access, rectification, erasure, objection, portability).
  • Assistance with breaches: notification to the client without delay and cooperation in the assessment.
  • Return or deletion of data at the end of the service. The priority obligation is to return them to the client; destruction comes afterwards and only when confirmed by the client.
  • Information to demonstrate compliance: the freelancer must be able to evidence the above if the client needs it during an inspection.

"The freelancer who signs an art. 28 GDPR contract with their client is not adding paperwork: they are setting out what they can and cannot do with that data, and shielding themselves for the day the client receives an inspection. It is bilateral protection, not administrative burden."

Mario P. Talamillo · Managing Partner, Certix®

Typical cases for the web designer, developer and consultant

Some usual scenarios and how the art. 28 GDPR contract regulates them:

  • Web designer with access to the client's CMS: documented instructions on what they may touch (templates, content) and what they may not (subscriber list, orders, users). If they download a local copy of the site with real data, the contract sets out that it must be deleted at the end.
  • Developer with access to a production database: minimisation (preferring staging environments with anonymised data), prohibition on exporting data to personal devices without encryption, access logging.
  • Consultant operating the client's email marketing tool: individual user accounts (not shared), instructions on segmentation, prohibition on exporting the list to other environments.
  • Professional using generative AI: the contract must address this expressly. Uploading the client's personal data to an LLM without authorisation is unauthorised sub-processing.
  • End of the relationship: return of credentials, export of data to the client, deletion of local copies, removal of shared access.

Sub-processors: what is almost always overlooked

Art. 28.2 and 28.4 GDPR govern subcontracting. For the freelancer, the most relevant points:

  • They need prior authorisation from the client, specific or general (with an obligation to inform of changes).
  • Each sub-processor (another freelance collaborator, a SaaS tool where personal data is uploaded, an external backup service) must accept the same obligations in writing as the freelancer towards the client.
  • The freelancer remains liable to the client for the sub-processor's compliance.
  • Common SaaS tools (Notion, Airtable, Trello, AI platforms, cloud storage) are typical sub-processors and must be authorised and documented.

Minimum security for the independent professional

Art. 32 GDPR requires appropriate technical and organisational measures. For a freelancer, without over-engineering:

  • Individual passwords and a password manager (do not share credentials by email or WhatsApp).
  • Two-factor authentication on all accounts with access to client data.
  • Disk encryption on laptop and mobile.
  • Encrypted backup of ongoing projects.
  • Clear separation between client data and the freelancer's own data.
  • Deletion policy at project closure (local folders, shared access, downloads).
  • Do not use WhatsApp or social media to send databases or end-customer lists.

Freelancer checklist

  • Identify which clients you act as processor for and which you do not.
  • Have your own art. 28 GDPR contract template, adaptable to each relationship.
  • Attach the contract to the services agreement and archive it signed by both parties.
  • List the SaaS tools that touch client data (sub-processors) and ensure authorisation.
  • Document the actual security measures (without inventing).
  • Return-and-deletion protocol at project closure.
  • Breach protocol: who to notify, within what timeframe, with what minimum information.
  • Review the contract if the service scope changes or new tools are introduced (especially AI).

Frequently asked questions

When is a freelancer a processor of their client?

When, in the course of providing a service, they access the client's personal data and process it on the client's behalf and instructions. It is the usual situation of the web designer with CMS access, the developer touching the production database, the consultant operating the CRM or email tool, the community manager with access to private messages.

What art. 28 GDPR contract should a freelancer sign with their client?

A contract (or annex / DPA) with the minimum content of art. 28.3 GDPR: subject-matter, duration, nature, type of data, instructions, confidentiality, security, sub-processor regime, assistance with rights and breaches, return or deletion of data at the end of the service, and information to demonstrate compliance.

Can a freelancer subcontract tasks involving client data without notifying them?

No. Art. 28.2 GDPR requires prior authorisation from the client, specific or general. It applies to collaborators, SaaS tools where client data is uploaded, external backups and use of generative AI with personal data. Each sub-processor takes on the same obligations and the freelancer remains liable to the client.

What happens if the freelancer does not sign an art. 28 GDPR contract with the client?

It is a standalone GDPR infringement for both parties. It also leaves the professional without a framework for breaches, inspections or commercial disputes: there are no clear rules on return, retention, reuse for portfolio or sub-processor regime. The contract is bilateral protection.

This content is informational and educational in nature and does not constitute specialised legal advice. Applying the regulation to a specific case requires individual analysis. Spanish regional and sector-specific rules may extend or modify timeframes and requirements.

Working as a freelancer and handling client data?

At Certix we help you set up an art. 28 GDPR contract and a realistic security scheme, without over-engineering your activity.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →