What is a data processor?
A data processor is an organisation or other party that processes personal data on documented instructions from a controller. The processor provides a service without independently deciding the main purpose of the processing. Common examples include cloud hosting, payroll, customer support, communications, analytics and document-management providers.
The role is determined by actual activity. A service provider may be a processor for customer content while acting as a controller for its own employee records, security operations or independent marketing. Role analysis should therefore be completed for each processing purpose.
What responsibilities does a processor have?
A processor should follow lawful documented instructions, ensure confidentiality, implement appropriate security and support the controller with data-subject requests, incidents, impact assessments and regulator enquiries. It should maintain required records and make relevant compliance information available.
Processors may also have direct legal obligations under some frameworks. They should not use personal data for independent purposes unless a separate legal role and basis have been established transparently.
How are processors selected and managed?
Controllers should assess a processor before sharing data. Due diligence may cover security, privacy, resilience, locations, sub-processors, deletion, audit evidence and incident history. The depth of review should reflect the sensitivity, scale and criticality of the service.
A data processing agreement should define scope and responsibilities. Ongoing monitoring may include certifications, updated assessments, service changes, sub-processor notices and remediation of identified issues.
What happens when a processor uses sub-processors?
The processor should use sub-processors only under the agreed approval or notification process. Equivalent privacy and security duties should flow down through the supply chain. The processor normally remains responsible to the controller for the sub-processor’s performance.
Controllers need visibility over locations and onward transfers because a seemingly simple service can rely on a complex global infrastructure.
Frequently asked questions
Can a processor choose its own technical tools?
Yes, it may decide non-essential technical details, but it should not redefine the purpose or use the data beyond the controller’s instructions.
Can a processor become a controller?
Yes. If it independently determines a new purpose or essential means, it may become a controller for that activity.
Does a processor respond directly to data subjects?
Usually it supports the controller rather than responding independently, unless the legal framework or agreed arrangement provides otherwise.
Must processors report security incidents?
They generally must notify controllers promptly under legal and contractual obligations and provide information needed for assessment.
Can a processor keep data after the contract ends?
Only where instructed or legally required. Otherwise, the data should be returned or deleted according to the agreement.



