Does every vendor need a GDPR contract?
No. Article 28 applies when a separate vendor processes personal data on behalf of the controller. If the vendor determines its own purposes and essential means for a separate processing activity, the team should assess controller or joint-controller roles instead of using terms as a shortcut.