> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What is a processor?
- URL: https://www.thedelatorrereview.com/what-is-a-processor/
- Published: 2018-11-22T18:07:00.000Z
- Updated: 2026-07-08T18:10:05.000Z
- Description: What is a processor under the GDPR? This article explains who qualifies as a processor, how processors differ from controllers, the meaning of processing "on behalf of" a controller, and why actual decision-making—not contracts or labels—determines an organization's role.
- Author: Lydia
- Tags: GDPR, Processor, Data Protection Law, EU

> **Key points:** (1) A processor is an individual or entity that process personal data on behalf of the controller (2) Who is the controller in any given situation regarding any given data set **is a factual determination** (3) A controller must, at the minimum, provide instructions with regard to the purpose of the processing and the essential elements of the means but the processor may be allowed to choose the most suitable technical and organizational means.

A controller can decide to delegate all or part of the processing activities to an external organization. A processor under GDPR is an individual or entity that processes personal data on behalf of the controller.

Therefore, the two basic conditions for qualifying as a processor are on the one hand being a separate legal entity or person with respect to the controller and on the other hand processing personal data on his behalf.

![](https://cdn-images-1.medium.com/max/800/1*vLO_j9roBwkPEEUQwf3KOQ.png)

**“Individuals or entities”:** Just as with the definition of controller, a broad series of persons can play the role of processor, ranging from natural to legal persons and including any other entity or individual. Logically, the processor must be a separate legal entity with respect to the controller.

Processing personal data **“on behalf of”** the controller means serving someone else’s interest. Processors must implement the instructions given by the controller at least with regard to the purpose of the processing and the essential elements of the means.The lawfulness of the processor’s data processing activity is determined by the mandate given by the controller. A processor that goes beyond its mandate and acquires a relevant role in determining the purposes or the essential means of processing is a (joint) controller rather than a processor. However, delegation may still imply a certain degree of discretion about how to best serve the controller’s interests, allowing the processor to choose the most suitable technical and organizational means.

The classification as processor (or controller) has to be assessed with regard to specific sets of data or operations. The processing activity may be limited to a very specific task/context or may be more general. The same entity may act at the same time as a controller for certain processing operations and as a processor for others with regards to the same data.

![](https://cdn-images-1.medium.com/max/800/0*vIgyvoPkDcF8_kyJ)

ICO “Cheat-Sheet” (Link provided in resources below)

Although processors act on the controllers behalf, **it is possible that the technical and organizational means for the processing be determined exclusively by the data processor.** This is because the determination of the “means” can include both technical and organizational questions where the decision can be delegated to processors (as e.g. “which hardware or software shall be used?”) and essential elements which are traditionally and inherently reserved to the determination of the controller, (e.g. “which data shall be processed?”, “for how long shall they be processed?”, “who shall have access to them?”).

Controllers are required to enter into a **written contract containing a number of requirements** with their processors (including clear instructions on what is to be done with the personal data and how). However, the existence (or non existence) of a contract does not constitute a necessary condition to qualify as a processor.

#### Plurality of processors

It is common for processing of personal data to be outsourced by a controller to several data processors. These processors may have a direct relationship with the data controller, or be sub-contractors to which the processors have delegated part of the processing activities entrusted to them. Some data protection laws like GDPR explicitly refer to them.

With a plurality of actors involved in the process **the strategic issue is how to allocate the obligations and responsibilities becomes a priority**. Chains of (sub-)processors that dilute or even prevent effective control and clear responsibility for processing should be avoided unless the responsibilities of the various parties in the chain are clearly established.

![](https://cdn-images-1.medium.com/max/800/1*vReqllxGtPCo7TzH-z0mhg.png)

EU regulators have issued helpful guidelines (including flowcharts) that identify criteria helpful in determining the qualification of the various entities involved in processing (see Resources section below)

Criteria include:

- **Level of prior instructions** given by the data controller, which determines the margin of maneuver left to the data processor
- **Monitoring by the data controller** of the execution of the service. A constant and careful supervision by the controller to ensure thorough compliance of the processor with instructions and terms of contract provides an indication that the controller is still in full and sole control of the processing operations;
- Visibility/image given by the controller to the data subject, and **expectations of the data subjects** on the basis of this visibility.
- **Expertise of the parties**: in certain cases, the traditional role and professional expertise of the service provider play a predominant role, which may entail its qualification as data controller.
- In the same line, the **autonomous decision-making power** left to the various parties involved in the processing is relevant. The case of clinical drug trials illustrates this point as the relationship between sponsor companies and external entities entrusted to carry out the trials depends on the discretion left to the external entities in respect of data processing (this entails that there may be more than one controller, but also more than one processor or person in charge of the processing — see example below).

### Concept of ‘processor’ across multiple jurisdictions

![](https://cdn-images-1.medium.com/max/800/1*Zi6hwhr6hDcuRf2MMasOIQ.png)

Process workers at work at the Golden Circle cannery in Northgate, ca. 1947 — State Library of Queensland

The concept of processor has a remarkable track record of being defined in a consistent manner across most jurisdictions with data protection laws.

Although the definition and the interpretation tends to be consistent, in practice, where the line between acting as controller and acting as processor is blurry, different data protection authorities can come to different conclusions for identical factual patterns.

### Examples

**NOTE: All examples and analysis below is based on A29WP and EDPB guidelines**

> **Example: Internet service providers of hosting services**  
> An ISP providing hosting services is in principle a processor for the personal data published online by its customers, who use this ISP for their website hosting and maintenance. If however, the ISP further processes for its own purposes the data contained on the websites then it is the data controller with regard to that specific processing. This analysis is different from an ISP providing email or internet access services (see example “Telecom operators” in [“What is a controller?](https://medium.com/golden-data/what-is-a-controller-afd99a8ebd0a?ref=thedelatorrereview.com)).

---

> **Example: Outsourcing of mail services**  
> Private bodies provide mail services on behalf of (public) agencies — e.g. the mailing of family and maternity allowances performed on behalf of the National Social Security Agency. In that case a DPA indicated that the private bodies in question should be appointed as processors considering that their task, though carried out with a certain degree of autonomy, was limited to only a part of the processing operations necessary for the purposes determined by the data controller.

---

> **Example: Email platforms**

> John Smith looks for an email platform to be used by himself and the five employees of his company. He discovers that a suitable user-friendly platform — and also the only one offered for free — keeps personal data for an excessive amount of time and transfers them to third countries without adequate safeguards. Furthermore, the contractual terms are “take it or leave it”.  
> In this case, Mr Smith should either look for another provider or — in case of alleged non compliance with data protection rules or lack of availability in the market of other suitable providers — refer the matter to competent authorities, such as DPAs, consumer protection and antitrust authorities, etc.

---

> **Example: Computer grids**  
> Large scale research infrastructures are increasingly using distributed computing facilities, especially grids, to profit in terms of computing and storage capacity. Grids are installed in different research infrastructures established in different countries. A European grid may, for instance, consist of national grids, which in turn are under the responsibility of a national body. This European grid, however, may not have a central body, responsible for its functioning. Researchers using such a grid can not usually identify where their data are exactly being processed, and thus who is the responsible data processor (the case is even more complicated if there are grid infrastructures in third countries). Should a grid infrastructure use the data in an unauthorized manner, this party may be considered data controller, if it does not act on behalf of the researchers.

---

> **Example: Call centers**  
> A data controller outsources some of its operations to a call center and instructs the call center to present itself using the identity of the data controller when calling the data controller’s clients. In this case the expectations of the clients and the way the controller presents himself to them through the outsourcing company lead to the conclusion that the outsourcing company acts as a data processor for (on behalf of) the controller.

---

> **Example: Barristers**  
> A barrister represents his/her client in court, and in relation to this mission, processes personal data related to the client’s case. The legal ground for making use of the necessary information is the client’s mandate. However, this mandate is not focused on processing data but on representation in court, for which activity such professions have traditionally their own legal basis. Such professions are therefore to be regarded as independent ‘controllers’ when processing data in the course of legally representing their clients.

---

> **Example: “Lost and found” website**  
> A ‘lost and found’ website was presented as being merely a processor as it would be those who post lost items who would determine the content and thus, at a micro level, the purpose (e.g. finding a lost brooch, parrot etc). A data protection authority rejected this argument. The website was set up for the business purpose of making money from allowing the posting of lost items and the fact that they did not determine which specific items were posted (as opposed to determining the categories of items) was not crucial as the definition of “data controller” does not expressly include the determination of content. The website determines the terms of posting etc and is responsible for the propriety of content.

---

> **Example: Accountants**  
> The qualification of accountants can vary depending on the context. Where accountants provide services to the general public and small traders on the basis of very general instructions (”Prepare my tax returns”), then — as with solicitors acting in similar circumstances and for similar reasons — the accountant will be a data controller. However, where an accountant is employed by a firm, and subject to detailed instructions from the in-house accountant, perhaps to carry out a detailed audit, then in general, if not a regular employee, he will be a processor, because of the clarity of the instructions and the consequent limited scope for discretion. However, this is subject to one major caveat, namely that where they consider that they have detected malpractice which they are obliged to report, then, because of the professional obligations they owe they are acting independently as a controller.

---

> **Example: Clinical drug trials**  
> The pharmaceutical company XYZ sponsors some drug trials and selects the candidate trial centers by assessing the respective eligibility and interests; it draws up the trial protocol, provides the necessary guidance to the centers with regard to data processing and verifies compliance by the centers with both the protocol and the respective internal procedures.

> Although the sponsor does not collect any data directly, it does acquire the patients’ data as collected by trial centers and processes those data in different ways (evaluating the information contained in the medical documents; receiving the data of adverse reactions; entering these data in the relevant database; performing statistical analyses to achieve the trial results). The trial center carries out the trial autonomously — albeit in compliance with the sponsor’s guidelines; it provides the information notices to patients and obtains their consent as also related to processing of the data concerning them; it allows the sponsor’s collaborators to access the patients’ original medical documents to perform monitoring activities; and it handles and is responsible for the safekeeping of those documents. Therefore, it appears that responsibilities are vested in the individual actors.

> Against this background, in this case both trial centers and sponsors make important determinations with regard to the way personal data relating to clinical trials are processed. Accordingly, they may be regarded as[ joint data controllers](https://medium.com/golden-data/what-are-joint-controllers-a9614d4a633d?ref=thedelatorrereview.com). The relation between the sponsor and the trial centers could be interpreted differently in those cases where the sponsor determines the purposes and the essential elements of the means and the researcher is left with a very narrow margin of maneuver.

---

#### Resources:

[EDPS Guidelines on the concepts of controller, processor and joint controllership under Regulation (EU) 2018/1725.](https://edps.europa.eu/sites/edp/files/publication/19-11-07%5Fedps%5Fguidelines%5Fon%5Fcontroller%5Fprocessor%5Fand%5Fjc%5Freg%5F2018%5F1725%5Fen.pdf?ref=thedelatorrereview.com) November 7, 2019

EDPB [Guidelines on the concept of controller and processor](https://edpb.europa.eu/our-work-tools/public-consultations-art-704/2020/guidelines-072020-concepts-controller-and-processor%5Fen?ref=thedelatorrereview.com) (2020)

Article 29WP Opinion on the concept of Controller and Processor [169/2010](https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2010/wp169%5Fen.pdf?ref=thedelatorrereview.com)

ICO Report:[ Data controllers and data processors: what the difference is and what the governance implications are](https://ico.org.uk/media/about-the-ico/events-and-webinars/2698/ico-annual-conference-2014-iain-bourne.pdf?ref=thedelatorrereview.com)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-32.png)