Skip to content
Legiscope
Menu
Data Privacy

What Is a Data Processor Under GDPR?

Art. 4(8) GDPR defines data processors as entities processing personal data on behalf of controllers. Learn their duties, Art. 28 contracts, and enforcement risks.

A third party is a GDPR processor when it processes personal data on behalf of a controller. Outsourcing does not always create that relationship: a supplier may be an independent controller, a joint controller or a processor for different operations. The first task is to identify the service and who decides its purposes and essential means, before selecting the contract and operational controls.

Key Takeaways

  • A data processor under GDPR is any entity that processes personal data on behalf of a controller, as defined in Art. 4(8).
  • Controllers determine purposes and essential means; processors may choose non-essential technical means within the controller’s instructions.
  • Art. 28(3) GDPR requires a binding contract or other legal act, in writing including electronic form, covering subject matter, duration, nature, purpose, data types, and data subject categories.
  • Processors carry direct liability under Art. 82(2) and can be fined independently under Art. 83 ; the ICO’s 2025 Advanced case illustrates security enforcement under the separate UK GDPR.
  • Missing or deficient DPAs are themselves an infringement, with fines up to EUR 10 million or 2% of worldwide turnover.

Art. 4(8) GDPR: The Data Processor Definition

The GDPR assigns distinct roles to entities involved in personal data processing. Article 4(8) defines a data processor as “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.”

The critical phrase is “on behalf of.” A data processor GDPR does not determine the purposes or essential means of processing. It executes instructions.

The EDPB’s Guidelines 07/2020 introduced a distinction between “essential means” and “non-essential means.” A processor may make decisions about non-essential means — specific hardware, software, or security configurations. However, decisions about essential means remain with the controller: the types of data collected, the duration of processing, the categories of data subjects, and the purposes of processing.

Common Examples of Data Processors

Processor Type What They Do Why They Are Processors
Cloud hosting provider (AWS, Azure, GCP) Stores customer databases on behalf of clients Does not determine processing purposes; acts on controller instructions
Payroll service provider (ADP, Sage) Processes employee salary data for the client Processes data strictly for the employer’s defined purpose
Email marketing platform (Mailchimp, Brevo) Sends communications on the company’s behalf Follows the controller’s mailing lists, content, and schedules
CRM vendor (Salesforce, HubSpot) Stores and organises customer relationship data Provides the tool; the controller decides which data enters it
IT support / managed services Accesses systems for maintenance, with data exposure Processor where personal-data processing is part of the service; incidental access alone needs a factual role assessment

In each case, the client organisation determines why the data is processed and what data is involved. The service provider determines how to carry out the task technically, but not the underlying purpose.

Controller vs Processor: The Practical Distinction

The controller determines the “why” and “what” of processing. The processor determines the “how” within the boundaries set by the controller. This distinction has direct consequences for liability, obligations, and regulatory exposure.

Controller Processor
Determines purpose Yes No
Determines essential means Yes No
Needs a legal basis (Art. 6) Yes No (relies on controller’s basis)
Must conduct DPIAs Yes Assists only
Maintains Art. 30 records Art. 30(1) — full records Art. 30(2) — processor-specific records
Liability for damage Art. 82 conditions apply Art. 82(2): breach of processor-specific duties or action outside/contrary to lawful instructions
Can be fined by DPAs Yes Yes (Art. 83)

A company that collects customer data through its website and stores it in a cloud service is the data controller. The cloud provider is the processor. If the cloud provider independently analyses that data for its own purposes, it becomes a controller for that additional processing — with all the obligations that status entails.

Joint controllership arises when two or more entities jointly determine purposes and means, governed by Art. 26. Under Art. 28(2), a processor needs prior specific or general written authorisation for sub-processors. General authorisation requires advance information about intended additions or replacements, giving the controller an opportunity to object.

Art. 28 Data Processing Agreement Requirements

Processors carry direct statutory obligations under the GDPR. These obligations exist independently of any contract, though contracts are also mandatory.

Art. 28(3) requires a binding contract or other legal act between the controller and processor. This Data Processing Agreement (DPA) must specify:

  • The subject matter and duration of processing
  • The nature and purpose of processing
  • The type of personal data and categories of data subjects
  • The controller’s obligations and rights

For a detailed breakdown, see our Art. 28 GDPR guide.

Mandatory DPA Clauses Under Art. 28(3)

The DPA must include these specific provisions:

  1. Documented instructions — the processor must process data only on documented instructions from the controller.
  2. Confidentiality — personnel with access to personal data must be bound by confidentiality obligations.
  3. Security measures — appropriate technical and organisational measures under Art. 32.
  4. Sub-processor management — prior specific or general written authorisation required before engaging sub-processors.
  5. Data subject rights assistance — the processor must assist the controller in responding to data subject requests.
  6. Breach notification support — assistance with security, breach notification (Art. 33-34), DPIAs, and prior consultation.
  7. Data deletion/return — at the controller’s choice, delete or return the personal data after the service ends and delete copies, unless Union or Member State law requires storage.
  8. Audit rights — the processor must make available all information necessary to demonstrate Art. 28 compliance.

The absence of a written DPA is itself an infringement. Both the controller and the processor can be held liable, with fines up to EUR 10 million or 2% of worldwide annual turnover under Art. 83(4).

Direct Liability and Enforcement Against Processors

Art. 82(2) makes processors directly liable for damage caused by processing if they acted outside or contrary to the controller’s lawful instructions, or if they failed to comply with obligations specifically directed at processors. Art. 83 allows supervisory authorities to fine processors directly.

A processor has its own Art. 32 duty to implement appropriate security. An infringement may lead to regulatory enforcement; compensation under Art. 82 additionally requires damage and a causal link, subject to its liability rules. A processor that engages a sub-processor without the controller’s authorisation violates Art. 28(2) and bears direct responsibility.

Processors must also maintain their own records of processing activities under Art. 30(2), covering all categories of processing carried out on behalf of each controller.

A Verified Processor Security Case

The ICO fined Advanced Computer Software Group £3.07 million in March 2025 following an August 2022 ransomware incident. Advanced supplied IT and software services, including to NHS organisations. Attackers accessed systems through a customer account without multi-factor authentication. This is a UK GDPR case, illustrating why a service provider’s own security controls matter; it is not evidence of an EU-wide trend or a new power created in 2024.

Make the Role Decision Per Operation

Consider a payroll supplier providing three services to an employer:

  1. Calculating salaries from employer instructions: identify the employer as controller and assess the supplier as processor for that service. Record permitted data, instructions and access.
  2. Managing its own customer billing: the supplier normally determines this separate purpose and acts as controller for the relevant business contact records. Its own transparency and retention duties follow.
  3. Reusing employee records for a commercial benchmarking product: do not assume the payroll DPA authorises this. Examine who determines the new purpose, whether the disclosure and reuse are lawful, and whether the records can actually be treated as anonymous.

Capture those decisions in a service map with separate rows for each operation, the evidence supporting the role and the responsible legal entity. A contract label does not override the facts. Where the supplier is a processor, use the DPA review guide to translate the role decision into instructions, assistance commitments and annexes. Where it determines a separate purpose, the controller guide is the appropriate next step.

Common Processor Compliance Failures

Processor compliance gaps to check include:

  • Operating without a written DPA
  • Engaging sub-processors without authorisation
  • Retaining personal data after the service relationship ends
  • Failing to notify the controller of data breaches without undue delay (Art. 33(2))
  • Missing Art. 30(2) records of processing activities

Each may expose the organisation to enforcement depending on the applicable duty and facts; sanction amounts are not automatic.

How to Ensure Processor Compliance

Organisations acting as data processors should:

  1. Audit Art. 28 compliance — conduct a gap assessment against every requirement in Art. 28(3).
  2. Ensure DPAs are in place with every controller client, covering all mandatory clauses.
  3. Designate a DPO where required under Art. 37.
  4. Maintain Art. 30(2) records — record the categories of processing carried out for each controller and the other Art. 30(2) fields, assessing any Art. 30(5) exemption.
  5. Implement Art. 32 security measures — encryption, access controls, vulnerability management, and incident response.

FAQ

What is a data processor under GDPR?

Art. 4(8) GDPR defines a data processor as any natural or legal person, public authority, agency, or other body that processes personal data on behalf of a controller. The processor acts on the controller’s instructions and does not determine the purposes of processing. Common examples include cloud hosting providers, payroll services, and email marketing platforms.

How do you determine if a vendor is a processor or a controller?

Apply the EDPB’s “essential means” test. If the vendor follows your instructions and has no independent decision-making power over why personal data is processed, it is a processor. If the vendor determines its own purposes for using the data, it is a controller (or joint controller under Art. 26) — and a DPA alone is insufficient.

Can a data processor be fined under GDPR?

Yes. Art. 83 applies to both controllers and processors. Processors can be fined for violations of their specific obligations — Art. 28 contract requirements, Art. 32 security measures, Art. 30(2) record-keeping, and data transfer rules — regardless of the controller’s instructions. The ICO’s 2025 fine against Advanced Computer Software Group confirmed this enforcement power in practice.

What must a Data Processing Agreement contain?

Art. 28(3) mandates that a DPA include: documented instructions from the controller, confidentiality obligations, security measures, sub-processor authorisation requirements, data subject rights assistance, breach notification support, data deletion or return at end of service, and audit rights. Missing any of these clauses creates an infringement risk for both parties.

Conclusion

Determine the supplier’s role for each processing operation before choosing an Article 28 contract. A processor needs both workable client instructions and its own controls for security, records, sub-processors and prompt breach escalation. Retain the evidence behind the role decision and revisit it when the supplier changes how it uses data.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

E-Commerce GDPR Compliance: Step-by-Step

E-commerce businesses collect personal data at every stage of the customer journey — browsing, account creation, checkout, delivery, and post-sale marketing. Every one of these touchpoints triggers…

02GDPR Compliance

GDPR for Indian Companies: Scope and Obligations

Almost every article about the GDPR and India asks the wrong question. It asks whether Art. 3(2) catches an Indian company that targets European consumers. For a small number of Indian D2C brands and…

July 30, 2026
03GDPR Compliance

What Is a Data Controller Under GDPR?

The data controller is the central figure in GDPR compliance. Art. 4(7) GDPR defines the controller as the entity that "determines the purposes and means of the processing of personal data." Every…

April 12, 2026
04Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
05Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
06Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
07Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
08Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026