Skip to content

Processor

Definition

A natural or legal person that processes personal data on behalf of the controller. Processors are directly bound by certain GDPR obligations (including maintaining their own ROPA and implementing security measures) and must act only on documented instructions from the controller.

Regulation
GDPR (EU)
Role
Acts on behalf of the controller
Instruction basis
Documented instructions only
Own obligations
Own ROPA, security measures

Common questions

How does a processor differ from a controller under GDPR?+

The controller determines the purposes and means of processing personal data and bears primary responsibility for compliance, while the processor only processes data on the controller's documented instructions and has no independent authority to decide why or how the data is used, though it still carries direct legal obligations of its own.

Why does GDPR hold processors directly accountable rather than only through the controller?+

Before the GDPR, processors were bound only by contract with the controller. The regulation made them directly liable for specific duties such as security measures and maintaining their own records of processing, so a service provider acting as a processor can face regulatory action even without a direct claim from the data subject.

Related terms

Controller
The natural or legal person, authority, agency, or other body that determines the purposes and means of processing personal data. The controller...
Data Protection Impact Assessment (DPIA)
A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights...
Lawful Basis
One of the six conditions listed in Article 6 that must be satisfied before personal data may be processed. The controller must...
Record of Processing Activities (ROPA)
The inventory of processing operations required under Article 30. It documents the purposes, data categories, recipients, retention periods, and security measures for...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.