Data Processor
A data processor is an organisation or person that handles personal data on behalf of, and under the instructions of, another party known as the data controller. Unlike the controller, the processor does not decide why or how the data is used; it acts on the controller's directions. In practice, this is often an external service provider engaged by the controller to carry out specific processing tasks.
Under the EU General Data Protection Regulation (GDPR), a data processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of a data controller and acts only under the controller's documented instructions. The defining feature distinguishing a processor from a controller is the absence of decision-making authority over the purposes and essential means of processing; the processor executes processing activities as directed rather than determining them. In practice, the role is typically filled by an external organisation engaged by the controller, and generally excludes employees acting within the controller's own organisation. The precise obligations, contractual requirements, and boundaries of the processor role depend on the applicable legal regime and jurisdiction; this entry is educational and does not constitute legal advice.
Why it matters
The controller-processor distinction determines where accountability sits when personal data is handled. Under the GDPR, the controller decides the purposes and essential means of processing and bears primary responsibility for compliance, while the processor acts only on the controller's documented instructions. Misclassifying a service provider as a processor when it in fact exercises decision-making authority over purposes and means can leave an organisation exposed to obligations it has not addressed, because a party that determines the why and how of processing is generally treated as a controller regardless of the label applied in a contract.
For governance, risk, and compliance functions, the processor relationship is a focal point of third-party risk management. When a controller engages an external organisation to process personal data on its behalf, the controller does not shed its own responsibilities; it must satisfy itself that the processor offers appropriate safeguards and that the arrangement is governed by suitable contractual terms. Poorly governed processor relationships can create gaps in oversight, particularly where processing is subcontracted onward or performed across jurisdictions with differing legal regimes.
The practical significance of the role also varies by legal regime and jurisdiction. The obligations, contractual requirements, and boundaries described here reflect the GDPR framework, and the specific duties that attach to a processor depend on the applicable law and the facts of the arrangement. Organisations should treat classification as a fact-specific analysis rather than a formality, and seek qualified legal advice where the allocation of roles is uncertain.
Who it's relevant to
Inside Data Processor
Common questions
Answers to the questions practitioners most commonly ask about Data Processor.