Data processor

A person or organisation that processes personal data on behalf of a controller and on its documented instructions, as defined in GDPR Article 4(8), without deciding the purposes.

Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP

A data processor handles personal data for someone else. GDPR Article 4(8) defines a processor as a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller. Cloud providers, payroll bureaux and outsourced call centres are common examples, and the role is often shortened to processor. It does not decide why the data is processed: that belongs to the data controller.

A processor is bound to the controller by a data processing agreement under Article 28, which limits it to documented instructions and requires appropriate security. It may not engage a sub-processor without the controller’s prior written authorisation, and a processor that begins to set purposes and means for itself is treated as a controller for that processing. Processors also carry direct obligations, including security under Article 32. The role is easily confused with the data custodian: both do hands-on work with the data, but the custodian is an internal governance role, while the processor is a legal role, usually an external party.

Exam relevance: a scenario is likely to describe an outsourced service handling customer or employee records. Candidates are expected to identify the vendor as the processor and the client organisation as the controller, and to recognise that outsourcing moves the work but not the controller’s accountability.