Processor
In data protection law, a processor is an organization or person that handles personal data on behalf of, and under the instructions of, another party (the controller). The processor does not decide why or how the data is used; it acts on the controller's directions. This is a distinct role from the controller, who determines the purposes and means of the processing.
Under the GDPR, a processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. A processor must act only on documented instructions from the controller, and the relationship is typically governed by a binding contract or other legal act (commonly referred to as a Data Processing Agreement) that sets out the required subject matter, duration, nature, and purpose of processing, among other mandated terms. Determining whether an entity is a processor rather than a controller (or joint controller) depends on a factual assessment of who determines the purposes and means of processing; regulator guidance and case law inform this classification, and an entity that exceeds a controller's instructions may be treated as a controller in its own right. The evidence packet supplied contains only material on computing processors (CPUs) and does not address the data protection meaning; readers should verify the definition and any cited article numbers against the current official GDPR text and applicable regulator guidance.
Why it matters
The processor role is central to how accountability is allocated in data protection law. Because a processor handles personal data on behalf of, and under the instructions of, a controller, correctly identifying which party is the controller and which is the processor determines who bears which obligations. Misclassifying the relationship can leave gaps in compliance, because the controller and processor carry different responsibilities and the contract between them is expected to reflect the correct roles.
The distinction also matters because it is a factual assessment rather than a matter of labelling. An entity described in a contract as a processor may nonetheless be treated as a controller in its own right if it exceeds the controller's instructions and begins to determine the purposes and means of processing. Organizations that assume a role without analysing the underlying facts risk operating under the wrong set of obligations. Regulator guidance and case law inform this classification, so the position can develop over time and should be reviewed rather than fixed once.
Because the processor relationship is typically governed by a binding contract or other legal act, weaknesses in that arrangement can have downstream consequences for both parties. Where the required mandated terms are absent or the instructions are unclear, it becomes harder to demonstrate that processing is being carried out lawfully and under proper control. The evidence supplied here does not address the data protection meaning of processor, so specific article numbers and mandated terms should be verified against the current official GDPR text and applicable regulator guidance.
Who it's relevant to
Inside Processor
Common questions
Answers to the questions practitioners most commonly ask about Processor.