GDPR

Knowledge Base | GDPR | What is a data processor according to GDPR?

What is a data processor according to GDPR?

A data processor is a separate person or organisation that handles personal data on behalf of a data controller. A payroll company processing employee records for an employer is a typical example.

Under Article 28 of the GDPR, processors must:

  • Follow documented instructions, unless EU or Member State law requires otherwise.

  • Operate under a written, binding contract or another qualifying legal act.

  • Protect the data and ensure confidentiality.

  • Assist with individuals’ rights and relevant security obligations.

  • Notify the controller of personal data breaches without undue delay.

A processor needs the controller’s prior written authorisation to appoint subprocessors. If it determines its own purposes and means, it acts as a controller for that processing.