Data processor

A GDPR lawyer from us assesses the processor role, contractual requirements and supplier due diligence

What is a data processor?

A data processor is an external party engaged to carry out specific tasks. Typical examples include services for marketing, data analytics and administrative systems. Where one organisation sells a service to another and processes personal data on the buyer’s instructions, the seller acts as the data processor for the buyer.

Processing personal data on the buyer’s instructions means the seller must follow the guidelines set by the controller. The data processor has a defined mandate to perform certain processing on behalf of the controller, who determines the purposes and means of the processing.

Where a processor relationship exists, GDPR requires a data processing agreement to be in place. This agreement sets the scope and purpose of the processing and the categories of personal data involved, and clarifies the processor’s rights and obligations.

In some cases, multiple parties may share responsibility as joint controllers. They must coordinate to ensure all legal requirements are met.

 

Approach for a data processing agreement

Top-down view of a tidy workspace with a laptop, notebook, and two suited hands framing a blank sheet of paper to signal scope and clear objectives for legal counsel.

We review how the collaboration is set up and identify who actually determines the purposes and means of the processing, so the correct role is set from the outset. This provides a stable foundation for contractual requirements and allocation of responsibilities.

Close-up of a whiteboard with simple arrows and neutral markers representing data flows, as legal counsel places a marker.

We make clear which instructions are needed for the processing and where the practical boundaries lie. This makes it easier to assess what is permitted in the ongoing delivery.

Calm meeting table with three neutral document stacks and a pen indicating prioritization; two gender-neutral legal counsel in the background with simplified, faceless features.

We draft or review a data processing agreement that reflects your processes and supplier chains without becoming unnecessarily theoretical. The focus is on feasibility and traceability.

Legal counsel reviewing a tabbed binder beside an open laptop and a checked box on a blank form, signaling implementation and documentation.

We align on how technical and organisational measures, and cooperation on incidents and data subject rights requests, should work in day-to-day operations. The result is clear contact routes and expectations that reduce friction when something happens.

Legal counsel places a neutral token on a stack of folders with a blank calendar in the background, symbolising governance and recurring follow-up.

We set up a simple routine for changes in the service—for example new sub-processors or new types of data—and how this should be documented. This ensures the agreement remains relevant as the business develops.

Business professionals reviewing a contract and laptop at a meeting, discussing their role and obligations as a Data processor under GDPR.

How can Morling Consulting help?

Morling Consulting drafts, reviews and negotiates data processing agreements and provides ongoing advisory support on compliance. Our support reduces the risk of acting contrary to the contract or GDPR by giving you clarity on interpretation and application. Our services include:

  • Assessing whether your organisation acts as controller, data processor or joint controller.
  • Developing data processing agreements to regulate the relationship correctly.
  • Helping to identify and define the purposes and means of processing.
  • Advising on the legal obligations attached to each role.
  • Advising on joint controllership and allocation of responsibilities.

We also assess the roles of parties in collaborations involving personal data processing. Correctly identifying whether you are a controller, a data processor or operating under joint controllership is essential to meeting GDPR requirements across Europe.

Get in touch

If you have questions about data processing agreements or need support managing personal data, contact us. We will discuss your needs and provide guidance aligned to your operations.

 

Whether you are drafting new agreements, reviewing existing ones or seeking advice on a specific matter, we act as a sounding board and provide practical, business-focused guidance.

Business professionals standing by a flowchart, explaining the role of a Data processor in handling personal data and GDPR compliance.

Common questions about data processors

A controller determines why and how personal data are processed, while a data processor only processes the data according to the controller’s instructions.

Example: A company engages an external agency to send customer emails. The agency receives customer lists and uses them in line with the company’s instructions. The agency is the data processor; the company that set the purpose is the controller.

A data processing agreement is required when an external party processes personal data on behalf of a controller. This is a legal requirement under GDPR and applies, for example, when:

  • A company uses a cloud service provider that processes personal data.
  • Marketing, customer service or HR functions involving personal data are outsourced to a third party.
  • A third-party supplier accesses personal data as part of its assignment.

The agreement ensures the processing is secure and lawful.

Without a well-structured contract, there is a greater risk of non-compliant processing and personal data incidents. Ambiguity over responsibilities can undermine control, and the Data Protection Agency may intervene with sanctions and significant fines. Trust can also be damaged among customers, partners and the public.

It depends on who decides the purposes and means of the processing:

  • If you decide why and how personal data are processed → you are the controller.
  • If you process data under another party’s instructions → you are the data processor.

Morling Consulting can clarify roles for your operations and each collaboration involving personal data. For those asking “what is a data processor”, we map your activities to the correct role.

We provide advice and practical support to help you comply with GDPR. This includes:

  • Legal assessment of your role in collaborations involving personal data.
  • Preparation and review of data processing agreements.
  • Support on compliance queries and communications with controllers or processors.
  • Advice on security measures and documentation.

No, but strict conditions apply when the processor is outside the EU/EEA. International transfers must meet GDPR requirements, for example by using standard contractual clauses (SCC). Morling Consulting helps you manage international transfers.

Under GDPR, a compliant agreement should, for example, cover:

  • Types of personal data and categories of data subjects.
  • The processor’s obligations and the controller’s instructions.
  • Required security measures.
  • Rules on sub-processors, incident reporting and data return or deletion.

Morling Consulting drafts and reviews agreements so that nothing material is overlooked. For organisations asking “what is a data processor” or seeking a concise data processor definition, we ensure the contract terms reflect your operating reality.

Yes — but not for the same processing. An organisation may be a controller in one context and a processor in another. Each processing activity must be analysed and roles clearly defined. Morling Consulting helps draw these boundaries so you act correctly in every part of your business.

Examples include:

  • Determining each party’s role in collaborations involving personal data.
  • Reviewing a supplier’s data processing agreement before signature.
  • Guidance on procedures for cooperation between joint controllers.

Our advisory is built around your structure, needs and challenges across Europe.

Speak to a GDPR lawyer

Do you need to assess the processor’s role or a supplier structure? Contact us to discuss

"*" indicates required fields