Privacy
Glossary

Processor

A natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller and under the controller’s instructions.

In brief

Under Article 4(8) GDPR, a processor processes personal data on behalf of a controller. Examples may include a cloud provider, payroll service, IT support provider or external records and archiving service. The contractual label is not decisive. The role depends on how the purposes, processes and powers are actually arranged.

The controller determines the purpose of the processing and its essential means. A processor may choose technical and organisational details within that framework, but it may not use the data for its own incompatible purposes. Employees who work under the direct authority of their own organisation are not processors merely because they handle personal data. The role assessment therefore focuses on actual decision-making power and conduct.

Article 28 GDPR requires the processing to be governed by a contract or other legal act. It must address, among other matters, the subject matter and duration of the processing, the types of data and categories of data subjects, documented instructions, confidentiality, security, assistance with data-subject rights and personal-data breaches, and the return or deletion of data. Sub-processors generally require the controller’s prior specific or general written authorisation. A processor must inform the controller if, in its view, an instruction infringes data protection law.

For a business, the assessment starts with the actual processing activity: which data are processed for which purpose, who determines the essential means, where is the processing carried out and which sub-processors are involved? The processors and service providers section provides the organisational context. The role check offers initial orientation, while the processor assessment checklist supports provider selection and ongoing checks.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich