Home / Guides / What Is a Data Processor?

GDPR Basics

What Is a Data Processor?

Processor role boundaries, contract requirements, and operational duties.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

June 2026

Reading time

2 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

Explain processor obligations and limits so teams can manage vendors and service providers correctly under GDPR. Especially useful for SaaS and agency delivery models.

What it means

A processor handles personal data on behalf of a controller and follows documented instructions.

Processors need appropriate security, confidentiality, and subprocessor governance controls.

Article 28 contracts require defined processing scope, duration, and obligations.

Processors have direct GDPR duties including breach notification support and record-keeping.

Why it matters

Regulators, customers, and automated scanners increasingly treat published policies and live site behavior as one system. Gaps between what you say and what your site does create enforcement and commercial risk.

Fixing issues early is cheaper than retrofitting consent, tag managers, and legal pages after a complaint or failed enterprise security review.

Common mistakes

  • Reusing personal data for your own marketing without controller instruction.
  • Adding subprocessors without contractual authorization workflows.
  • Offering unclear retention/deletion behavior at contract end.
  • Using generic terms that miss mandatory Article 28 clauses.
  • Treating security documentation as optional for processor audits.

Practical checklist

  1. Verify whether your service acts on behalf of customer instructions.
  2. Sign DPAs with required Article 28 content.
  3. Publish subprocessor list and change notification process.
  4. Set security controls and incident response procedures.
  5. Implement deletion/export controls for end-of-contract scenarios.
  6. Define how you assist with DSAR and DPIA requests.
  7. Audit subprocessors and cross-border transfers regularly.

How GDPRChecker helps

GDPRChecker helps teams turn legal theory into testable controls. Its scanner identifies trackers, third-party calls, and policy mismatches so you can prioritize the highest-risk gaps first.

After changes ship, GDPRChecker runtime monitoring can confirm consent and tag behavior remains aligned over time. That makes compliance less of a one-off audit and more of an operational process.

FAQ

Can a processor choose lawful basis?
Usually no; lawful basis is primarily a controller decision.
Do processors need records of processing?
Yes, processors maintain records for processing they perform on behalf of controllers.
Is a DPA always required?
If processing occurs on behalf of a controller, a compliant DPA is generally required.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification