Glossary/Compliance/Data Processor
Compliance

Data Processor

Data Processor is a natural or legal person that processes personal data on behalf of a controller, only on documented instructions, under a binding GDPR Article 28 agreement.

What Data Processor is

The Data Processor is defined in GDPR Article 4(8) as any party that processes personal data on behalf of the controller. The processor's defining feature is constraint: it acts only on documented instructions from the controller under Article 29.

Processing for the processor's own purposes converts the processor into a controller for that activity, with all the controller obligations attaching.

Article 28 sets out the mandatory content of the contract between controller and processor: subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, controller obligations and rights, and binding processor commitments on confidentiality, security, sub-processor authorisation, assistance with data-subject rights, breach notification, and audit rights.

Processors have direct GDPR obligations of their own (security under Article 32, records of processing under Article 30(2), breach notification to the controller under Article 33(2), DPO appointment under Article 37 where applicable, international transfer safeguards under Chapter V). Processors can be fined directly by supervisory authorities for breaches of these direct obligations.

When you will meet Data Processor

You will act as a processor when offering services to your customers: a SaaS that hosts customer data, a payroll bureau, a hosting provider, an email-sending tool. Your contracts with customers will include an Article 28 Data Processing Addendum (DPA), a sub-processor list, and Standard Contractual Clauses for any international transfers triggered by the service.

Where this comes up in our guides

Data Processor FAQ

Yes, but only with prior specific or general written authorisation from the controller under Article 28(2). The processor must impose the same data protection obligations on the sub-processor by contract, and remains fully liable to the controller for the sub-processor's performance.
At a glance
Category
Compliance
Confirm current figures with the official registry or a qualified adviser before relying on them.
Related terms
← All 120 glossary terms
Sources
  1. 1GDPR Articles 28-29, 30(2), 32, 33(2), Regulation (EU) 2016/679
  2. 2EDPB Guidelines 07/2020 on the concepts of controller and processor
  3. 3EU Standard Contractual Clauses, Commission Decision 2021/914
Definition reviewed March 2026.
Put it to use

Eight jurisdictions, costed out in full.

See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.

Tax calculatorEffective rates on your revenue and margin.Country comparisonEleven criteria, side by side.Cost estimatorWhat the first year actually costs.Document checklistWhat each registry will ask for.

New terms as the rules change

Thresholds move, regimes close, new ones open. One email, no pitches.