Article 28(3)(h) of the General Data Protection Regulation (GDPR) requires the processor to make available to the controller all information necessary to demonstrate compliance with Article 28, and to allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
Two rights sit inside that sentence, and they behave very differently in practice. The information right is exercised constantly and is where most of the value lies. The inspection right is exercised rarely, is heavily qualified in standard contracts, and is where most of the negotiation happens.
This article covers what the provision actually gives you, how suppliers narrow it, what to negotiate, and how to use the right you have.
The information right is the useful one
The first limb obliges the processor to make available the information necessary to demonstrate compliance with Article 28. That is a standing obligation, not an annual event, and it is the right you will exercise most.
In practice it supports requests such as:
- The current sub-processor list, with entities and locations.
- A description of technical and organizational measures specific enough to assess.
- Independent assurance reports, including scope and exceptions.
- Confirmation of where support and administrative access originates.
- Evidence of deletion at the end of a service.
- The information needed to run and maintain a transfer assessment.
Framing a request under the information right rather than as an audit demand usually produces a faster and better response, because it asks the supplier for something it already has rather than for access to its estate.
How standard contracts narrow the inspection right
Suppliers qualify the second limb heavily, and most of the qualifications are commercially reasonable. It is still worth knowing which ones you have accepted.
Common restrictions include:
- Frequency limits, often once in any twelve-month period absent an incident.
- Notice periods, commonly thirty days or more.
- A requirement to use the supplier's existing third-party audit report in place of an on-site exercise.
- Confidentiality obligations on the auditor and on findings.
- A prohibition on auditors who compete with the supplier.
- Cost allocation to the controller, sometimes including the supplier's own time.
- Scope limits excluding multi-tenant infrastructure or other customers' environments.
Several of these are unavoidable. A supplier serving thousands of customers cannot accommodate thousands of on-site inspections, and the European Data Protection Board's Guidelines 07/2020 on the concepts of controller and processor recognise that audits can be satisfied in proportionate ways.
The clauses worth resisting are those that make the right unusable rather than merely bounded: an absolute substitution of a report for any inspection, notice periods long enough to defeat the purpose, or cost provisions that make exercise prohibitive regardless of cause.
What to negotiate
Focus on four things rather than fighting the whole clause.
An incident trigger
Frequency limits should not apply where there has been a personal data breach affecting your data or a material change in the supplier's processing. Without this carve-out, the right is least available exactly when you need it.
A report that is actually adequate
If the contract substitutes a third-party report for inspection, specify what makes the report adequate: current, covering the services you use, with scope and exceptions disclosed, and provided within a defined period of request. A report you cannot read, or that covers a different service line, is not a substitute.
Sub-processor reach
Your audit right against the supplier is of limited use if the risk sits one layer down. Article 28(4) requires the processor to impose the same obligations on its sub-processors and leaves it fully liable to you for their performance. Ask for a commitment that the supplier will exercise its own rights against a sub-processor at your reasonable request, and report the outcome.
Cost that follows fault
A reasonable position is that the controller bears the cost of a routine exercise, and the supplier bears it where the audit identifies material non-compliance. That aligns incentives without making routine assurance free.
Using the right well
An audit right exercised badly damages the relationship and produces little. Three habits help.
Ask narrowly. A request for specific information about a specific concern gets answered. A request for everything gets escalated to legal and slowed down.
Ask in writing, through the contractual channel, and record what came back. The exchange is itself accountability evidence under Article 5(2), and it is the kind of record that is hard to reconstruct later.
Read what you receive. Assurance reports are frequently obtained and rarely read. The exceptions section is the part that matters, and a supplier that discloses exceptions candidly is usually a better counterparty than one whose report has none.
When the right is your only lever
Where a supplier resists disclosure, the audit and information provision is often the strongest contractual instrument you hold. A written request under Article 28(3)(h), referencing the specific information necessary to demonstrate compliance, is materially harder to ignore than an email asking for a document.
Use it sparingly and precisely. Its value depends on not being routine.
Frequently asked questions
Do we have to conduct audits?
No. The GDPR gives the controller a right, and requires the processor to allow for and contribute to audits. Whether to exercise it is a risk-based decision, and for most vendors the information right plus published disclosures is proportionate.
Is accepting a third-party report instead of an inspection acceptable?
Commonly yes, provided the report covers the relevant services and you can read it. Record why the substitution is adequate for that vendor, so the decision is visible later.
Can we audit a sub-processor directly?
Usually not. Your contract is with the supplier, which remains fully liable under Article 28(4). Work through the supplier's rights rather than seeking a direct relationship.
What if the supplier refuses a reasonable request?
Record the request, the refusal, and its reasoning, then treat it as a finding in the risk assessment. A documented refusal is significant evidence if the arrangement is later questioned. Our article on audit-ready vendor evidence covers how to hold it.
Where DPAFlow fits in
Much of what an audit would establish is published continuously by the supplier and simply not watched: the sub-processor list, the Data Processing Agreement terms, and the trust-center disclosures. DPAFlow checks those pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts. Detected changes enter a review workflow where your team documents its assessment.
That gives an information-rights conversation something concrete to start from. DPAFlow does not conduct audits and does not provide legal advice. The evidence model is described on the evidence page, and the clause-level contract read is covered in our Data Processing Agreement review checklist.
This article explains a contractual right in general terms. It is not legal advice, and the negotiation calls belong to your counsel.