Skip to main content
Category: Controller & Processor Roles

Processor

Simply put

In data protection law, a processor is an organization or person that handles personal data on behalf of, and under the instructions of, another party (the controller). The processor does not decide why or how the data is used; it acts on the controller's directions. This is a distinct role from the controller, who determines the purposes and means of the processing.

Formal definition

Under the GDPR, a processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. A processor must act only on documented instructions from the controller, and the relationship is typically governed by a binding contract or other legal act (commonly referred to as a Data Processing Agreement) that sets out the required subject matter, duration, nature, and purpose of processing, among other mandated terms. Determining whether an entity is a processor rather than a controller (or joint controller) depends on a factual assessment of who determines the purposes and means of processing; regulator guidance and case law inform this classification, and an entity that exceeds a controller's instructions may be treated as a controller in its own right. The evidence packet supplied contains only material on computing processors (CPUs) and does not address the data protection meaning; readers should verify the definition and any cited article numbers against the current official GDPR text and applicable regulator guidance.

Why it matters

The processor role is central to how accountability is allocated in data protection law. Because a processor handles personal data on behalf of, and under the instructions of, a controller, correctly identifying which party is the controller and which is the processor determines who bears which obligations. Misclassifying the relationship can leave gaps in compliance, because the controller and processor carry different responsibilities and the contract between them is expected to reflect the correct roles.

The distinction also matters because it is a factual assessment rather than a matter of labelling. An entity described in a contract as a processor may nonetheless be treated as a controller in its own right if it exceeds the controller's instructions and begins to determine the purposes and means of processing. Organizations that assume a role without analysing the underlying facts risk operating under the wrong set of obligations. Regulator guidance and case law inform this classification, so the position can develop over time and should be reviewed rather than fixed once.

Because the processor relationship is typically governed by a binding contract or other legal act, weaknesses in that arrangement can have downstream consequences for both parties. Where the required mandated terms are absent or the instructions are unclear, it becomes harder to demonstrate that processing is being carried out lawfully and under proper control. The evidence supplied here does not address the data protection meaning of processor, so specific article numbers and mandated terms should be verified against the current official GDPR text and applicable regulator guidance.

Who it's relevant to

Data protection officers and compliance leads
Those responsible for compliance need to classify each processing relationship correctly, since the processor and controller roles carry distinct obligations. Because classification depends on a factual assessment of who determines the purposes and means, this typically involves reviewing the actual arrangement rather than relying on contractual labels alone.
Lawyers and contract drafters
Legal advisers drafting or reviewing arrangements between parties need to ensure that where a processor relationship exists, it is governed by a binding contract or other legal act addressing the mandated terms, such as the subject matter, duration, nature, and purpose of processing. They should also flag where a party's conduct might, subject to assessment, cause it to be treated as a controller.
Service providers and vendors
Organizations that handle personal data on behalf of clients often act as processors and are expected to process only on documented instructions. They should be aware that exceeding those instructions and determining purposes or means themselves may result in being treated as a controller in their own right, with the different obligations that follow.
Engineers and product teams
Technical teams implementing systems that handle personal data on behalf of a controller should ensure that processing remains within the controller's documented instructions, since deviations can affect the legal classification of the relationship and the associated responsibilities.

Inside Processor

Definition (Article 4(8) GDPR)
A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. The defining feature is that the processor acts on the controller's instructions rather than determining the purposes and means of processing itself.
Processing on documented instructions
A processor generally acts only on the documented instructions of the controller, including in relation to international transfers, unless required to do otherwise by EU or member state law. Where a processor determines purposes and means of its own, it typically becomes a controller for that processing under Article 28(10).
Article 28 obligations
The relationship between controller and processor must generally be governed by a binding contract or other legal act (commonly a Data Processing Agreement). Article 28 sets out required content, such as duties of confidentiality, security measures, conditions for engaging sub-processors, assistance to the controller, and provisions on return or deletion of data at the end of the engagement. Readers should verify specific requirements against the current official text.
Direct statutory duties
In addition to contractual obligations, a processor has certain direct obligations under the GDPR, which may include maintaining records of processing activities, implementing appropriate security measures, cooperating with supervisory authorities, and in some cases designating a data protection officer or a representative. The precise scope depends on the circumstances and should be assessed case by case.
Sub-processors
A processor generally may not engage another processor (a sub-processor) without prior specific or general written authorisation from the controller. Where sub-processors are used, comparable data protection obligations are typically flowed down, and the initial processor commonly remains responsible to the controller for the sub-processor's performance.
Relationship to the controller role
The controller determines the purposes and means of processing; the processor executes processing on the controller's behalf. Roles are assessed by reference to the factual reality of the arrangement rather than solely by contractual labels, and a single entity may be a controller for some activities and a processor for others.

Common questions

Answers to the questions practitioners most commonly ask about Processor.

Does a processor decide how personal data is used?
Generally no. A processor acts on behalf of and under the documented instructions of the controller, and it is the controller that determines the purposes and means of the processing. A party that begins to determine its own purposes or the essential means of processing may, in substance, be acting as a controller for that activity, regardless of what a contract labels it. Regulatory guidance treats the assessment as factual rather than driven solely by contractual wording, so the reader should assess each processing activity on its facts.
Is a processor free of direct legal obligations because the controller is responsible?
No. While the controller bears primary responsibility for lawfulness of processing, the GDPR imposes certain direct obligations on processors, and a processor can face liability in its own right in defined circumstances. The precise allocation of responsibility depends on the roles, the arrangement between the parties, and the facts of the processing, so this should not be read as the controller absorbing all accountability.
What terms typically need to be in place before a processor starts processing on a controller's behalf?
In most cases a written arrangement governing the processing is required between the controller and processor, setting out matters such as the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, and the obligations of each party. The specific mandatory content is set by the GDPR provision governing controller-processor relationships (commonly implemented as a Data Processing Agreement), which the reader should verify against the current official text before relying on any checklist.
Can a processor engage another organization to help carry out the processing?
Subject to the arrangement with the controller, a processor may engage a further party (often described as a sub-processor) to perform part of the processing, but this is typically conditioned on authorisation from the controller and on flowing down equivalent obligations to that further party. The exact authorisation mechanism and the processor's residual responsibility depend on the terms agreed and the applicable provisions, so verify the current requirements rather than assuming a general permission.
What should a processor do when it receives a data subject request directly?
Because the controller generally holds primary responsibility for responding to data subject rights, a processor will typically assist the controller rather than respond independently, in line with the instructions and the arrangement in place. The precise cooperation and assistance duties, and how requests are routed, should be defined in the controller-processor arrangement and assessed against the applicable provisions.
How do international transfers affect a processor's role?
Where a processor transfers personal data outside the relevant jurisdiction, or engages a party that does, a valid transfer basis is generally needed, and the available mechanisms, adequacy positions, and any supplementary measures can evolve over time. Because the position is context dependent and subject to change, the applicable transfer tool and safeguards should be assessed for each transfer and verified against current guidance rather than treated as settled.

Common misconceptions

A processor has no direct liability under the GDPR because it only follows the controller's instructions.
While much of the processor's position is defined by the controller relationship, a processor carries certain direct statutory obligations and can be subject to enforcement and liability in its own right where it breaches those obligations or acts outside documented instructions. The specific consequences are context dependent and should be assessed against the current text and relevant guidance.
The label used in a contract determines whether an organisation is a controller or a processor.
Controller and processor status is generally assessed on the factual reality of who determines the purposes and means of processing, not on contractual labelling alone. An entity described as a processor that in fact determines purposes and means may be treated as a controller for that processing.
Any vendor or supplier handling personal data is automatically a processor.
Whether a third party is a processor depends on the nature of the arrangement. Some recipients act as independent or joint controllers rather than processors, and the correct characterisation requires a case-by-case assessment of who decides why and how the data is processed.

Best practices

Assess controller versus processor status based on the factual reality of who determines the purposes and means of the processing, not solely on how the contract labels the parties, and document that assessment.
Put in place a written contract or other binding legal act that addresses the content required under Article 28, and verify the required elements against the current official text rather than relying on a generic template.
Ensure processing is carried out on documented instructions, and establish a clear process to escalate or query any instruction that appears to conflict with applicable law.
Manage sub-processors through the appropriate authorisation mechanism, flow down comparable data protection obligations, and maintain an up-to-date record of engaged sub-processors.
Confirm which direct statutory obligations apply to your organisation as a processor, such as records of processing, security measures, and cooperation with supervisory authorities, and assess whether a data protection officer or representative is required in your circumstances.
Where the same organisation acts as a controller for some activities and a processor for others, map these roles separately so that the correct obligations are applied to each processing activity.