Data Processor is a natural or legal person that processes personal data on behalf of a controller, only on documented instructions, under a binding GDPR Article 28 agreement.
The Data Processor is defined in GDPR Article 4(8) as any party that processes personal data on behalf of the controller. The processor's defining feature is constraint: it acts only on documented instructions from the controller under Article 29.
Processing for the processor's own purposes converts the processor into a controller for that activity, with all the controller obligations attaching.
Article 28 sets out the mandatory content of the contract between controller and processor: subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, controller obligations and rights, and binding processor commitments on confidentiality, security, sub-processor authorisation, assistance with data-subject rights, breach notification, and audit rights.
Processors have direct GDPR obligations of their own (security under Article 32, records of processing under Article 30(2), breach notification to the controller under Article 33(2), DPO appointment under Article 37 where applicable, international transfer safeguards under Chapter V). Processors can be fined directly by supervisory authorities for breaches of these direct obligations.
You will act as a processor when offering services to your customers: a SaaS that hosts customer data, a payroll bureau, a hosting provider, an email-sending tool. Your contracts with customers will include an Article 28 Data Processing Addendum (DPA), a sub-processor list, and Standard Contractual Clauses for any international transfers triggered by the service.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.