Glossary | GDPR & Data Privacy
Data Processor
What is a Data Processor?
A Data Processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of a Data Controller. Under Regulation (EU) 2016/679 (GDPR), processors act under the instruction of a controller and may only process personal data in ways that have been authorised by that controller.
Why It Matters
Many businesses rely on third-party services — such as cloud platforms, payment providers, or marketing tools — that handle personal data on their behalf. Each of these relationships may involve a Data Processor arrangement, and the GDPR places clear obligations on both parties to formalise and manage that relationship correctly.
For organisations acting as processors, the GDPR introduced direct legal obligations for the first time — processors can now be held accountable and fined by supervisory authorities for breaches that fall within their responsibility. For controllers, selecting and managing processors carefully is a key part of maintaining overall compliance.
For businesses of all sizes, understanding the processor role is essential for structuring third-party data relationships lawfully under the GDPR.

Key Requirements
Who Is Considered a Data Processor?
An organisation or individual is considered a Data Processor when they:
- Process personal data on behalf of another organisation, and
- Do so under the instructions of that organisation rather than for their own purposes.
This role is defined under:
- Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR)
Where a processor begins to determine the purposes or means of processing independently, they may assume the responsibilities of a Data Controller for that activity.
Responsibilities of a Data Processor
While specific obligations depend on the nature and scale of processing, responsibilities commonly include:
- Processing personal data only on documented instructions from the Data Controller
- Ensuring that authorised personnel are bound by confidentiality obligations
- Implementing appropriate technical and organisational security measures
- Assisting the controller in meeting data subject rights requests and breach notification obligations
- Deleting or returning personal data to the controller at the end of the contract
- Making available all information necessary to demonstrate compliance
- Entering into a binding Data Processing Agreement (DPA) with the controller
Data Processor vs. Data Controller
These roles are distinct under the GDPR. A Data Controller determines why and how personal data is processed and carries primary accountability for compliance. A Data Processor acts solely on the controller’s instructions and may not use the data for its own purposes.
Both roles carry direct obligations under the GDPR. Where a processor acts outside the controller’s instructions, they may assume controller-level liability for that processing activity.
Frequently Asked Questions
Yes. The GDPR requires that processing by a processor is governed by a binding contract or other legal act — commonly referred to as a Data Processing Agreement (DPA). This must set out the subject matter, duration, nature, and purpose of the processing, among other requirements.
Yes, but only with the prior written authorisation of the Data Controller. Sub-processors must be bound by the same data protection obligations as those set out in the agreement between the controller and the processor.
Yes. Unlike under previous EU data protection law, the GDPR introduced direct liability for processors. Supervisory authorities can impose fines of up to €10 million or 2% of total global annual turnover for processor-specific obligations, and up to €20 million or 4% for broader GDPR infringements.
Need GDPR Representative Services?
Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.
Related Terms
Further Reading