Data processor
Also known as: processor
An outside party that handles personal data on behalf of another organisation and only as that organisation instructs.
Draft - this entry has not been reviewed yet.
Formal
Under GDPR Article 4(8), a person or body that processes personal data on behalf of a controller; it may act only on the controller's documented instructions and has its own duties to keep the data secure.
In plain English
Like a laundry that washes a hotel's sheets - it takes good care of them and sends them back, but it has no say in what the hotel uses them for.
In practice
A Danish payroll bureau runs salaries for 200 small firms; for each of them it is a processor, allowed to use staff data only for payroll and not, say, to sell insurance offers to the employees.
Why it matters
If a processor starts using the data for its own ends, it becomes a controller in its own right and answers for that use; the role stops handing work to outsiders from becoming a loophole.
Technical deep dive
A processor under GDPR Art. 4(8) must be a legally separate entity from the controller that processes personal data on the controller's behalf; an employee or internal department is not a processor. The status is determined per processing activity by the facts, following the EDPB Guidelines 07/2020: a processor may choose non-essential means such as the technical stack, hosting location within agreed limits and security tooling, but it may not decide the purposes or the essential means. Typical processors are cloud IaaS and SaaS providers, payroll bureaus, IT outsourcing and managed security providers, call centres and shredding companies. Pure transmission providers or professionals acting under their own professional duties, such as auditors or lawyers, are usually not processors.
The core obligations are in Arts. 28-33. The processor may process only on documented instructions from the controller, including for transfers to third countries, unless EU or member-state law requires otherwise (Art. 28(3)(a) and Art. 29), and it must immediately tell the controller if an instruction in its opinion infringes data protection law. It must bind its staff to confidentiality, implement Art. 32 security measures, keep its own record of processing (Art. 30(2)), notify the controller of a personal data breach without undue delay (Art. 33(2)), assist the controller with data subject requests, DPIAs and prior consultation, delete or return data at the end of the service, and make available all information needed to demonstrate compliance, including allowing audits and inspections.
Sub-processing is controlled by Art. 28(2) and 28(4). The processor needs prior specific or general written authorisation from the controller; under a general authorisation it must inform the controller of intended changes so the controller can object. The same data protection obligations must be flowed down contractually, and the original processor remains fully liable to the controller for the sub-processor's performance. Large cloud providers typically publish a sub-processor list with a notification mechanism, and objection often means termination rather than a veto.
Art. 28(10) is the key escalation rule: a processor that determines purposes and means itself becomes a controller for that processing and carries the full controller obligations. Processors are directly subject to fines under Art. 83 and liable for damages under Art. 82(2) when they breach their own obligations or act outside or contrary to lawful instructions. In Denmark, controllers commonly verify processors through ISAE 3000 assurance reports on GDPR compliance or ISAE 3402 reports on general IT controls issued by auditors, supplemented by questionnaires or on-site inspection for high-risk processing. A frequent gap is failing to map the processor's own processing, for example telemetry or product analytics, which may make it a controller for that part.
What to learn first
Everything this builds on, foundations first.
- Confidentiality
- →Personal data
- →GDPR
- →Data processor
Relationships
- Requires
- GDPR
- Don't confuse with
- Data controller
Sources & further reading
Standards & official texts
- Regulation (EU) 2016/679 (GDPR), Article 4(8) and Article 28 · European Union
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…