What is a data processor?
A data processor is an external party engaged to carry out specific tasks. Typical examples include services for marketing, data analytics and administrative systems. Where one organisation sells a service to another and processes personal data on the buyer’s instructions, the seller acts as the data processor for the buyer.
Processing personal data on the buyer’s instructions means the seller must follow the guidelines set by the controller. The data processor has a defined mandate to perform certain processing on behalf of the controller, who determines the purposes and means of the processing.
Where a processor relationship exists, GDPR requires a data processing agreement to be in place. This agreement sets the scope and purpose of the processing and the categories of personal data involved, and clarifies the processor’s rights and obligations.
In some cases, multiple parties may share responsibility as joint controllers. They must coordinate to ensure all legal requirements are met.