Third-Party Processor
A third-party processor is an outside service that helps a business accept and handle payments, such as card and online transactions, without the business needing its own individual merchant account. It sits between the customer, the business, and the banking system to move payments through. In this payments context, the term refers to a commercial payment-handling role rather than a data protection role.
A third-party payment processor (TPPP) is a merchant service provider that aggregates and processes payment transactions on behalf of businesses, originating transactions for consumers or businesses and facilitating card and online payments without requiring the business to hold an individual merchant account. Typical offerings include point-of-sale (POS) systems, card readers, and mobile payment acceptance tools. Note: the evidence provided describes 'third-party processor' exclusively in the payments/merchant-services sense; it does not address the GDPR concept of a 'processor' under Article 28, and readers should not conflate this commercial payments role with the data protection role of a processor acting on behalf of a controller.
Why it matters
The term "third-party processor" carries a significant risk of confusion in privacy and compliance work because it names a commercial payments role that sounds nearly identical to the data protection concept of a "processor." In the payments context described here, a third-party payment processor is a merchant service provider that helps a business accept card and online payments without holding its own individual merchant account. This is a financial-services and merchant-services function, not a defined role under the GDPR, and treating the two as interchangeable can lead to material errors in contracts, records, and risk assessments.
For teams building compliance programs, precision here matters practically. A payment processor may, depending on the facts, also act as a processor or as an independent or joint controller for data protection purposes, but that characterisation must be assessed separately against the applicable data protection framework and is not established simply by the commercial "third-party processor" label. The evidence provided describes this term exclusively in the payments and merchant-services sense; it does not address the GDPR concept of a processor or any related contractual instrument. Readers should therefore confirm the data protection role of any payment provider on its own facts rather than inferring it from the payments terminology.
Who it's relevant to
Inside Third-Party Processor
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Processor.