Governance & Operations

What is Data Processor?

A data processor is an organization that processes personal data on behalf of and under the instructions of a data controller — such as a cloud host, email platform, or analytics service — bound by a data processing agreement under GDPR Article 28.

Processors are the infrastructure of modern data handling: hosting providers, SaaS platforms, payment processors, email senders, support desks, logistics systems. What defines them legally is subordination — they process personal data only on the controller's documented instructions, for the controller's purposes, never their own. The moment a vendor uses the data for its own product development, advertising, or resale, it stops being a processor for that use and becomes a controller, with all attendant obligations and possibly no legal basis.

GDPR Article 28 makes the relationship contractual: a controller may engage only processors providing 'sufficient guarantees' of compliance, and the mandatory data processing agreement (DPA) must bind the processor to process only on instructions, ensure staff confidentiality, secure the data, engage sub-processors only with authorization and equivalent terms, assist the controller with data subject rights and breach obligations, and delete or return the data when services end.

Processors also carry direct statutory duties under GDPR — maintaining their own records of processing, implementing security under Article 32, notifying the controller of breaches without undue delay — and can be fined directly. The same architecture appears in US state laws: 'processor' in Virginia and Colorado, 'service provider' under the CCPA, where certified service-provider status is what keeps a disclosure from being a 'sale.'

Sub-processing chains are the audit challenge: your processor's processors (its cloud host, its support tooling) all touch the data, which is why DPAs require sub-processor lists and notification of changes.

Why it matters for eCommerce

Every tool in your stack that touches customer data should be papered as a processor or CCPA service provider — the DPA is usually a checkbox in the vendor's terms, but someone has to verify it exists and covers what the tool actually does. Ad platforms are the exception to plan around: they generally act as independent controllers or 'third parties,' which is exactly why sending them data is a regulated 'sale' or 'share' rather than ordinary outsourcing.

Frequently asked questions

What must be in a data processing agreement (DPA)?
GDPR Article 28 prescribes the list: processing only on documented instructions, confidentiality, security measures, sub-processor controls, assistance with data subject rights and breach notification, deletion or return at contract end, and audit rights. Most established SaaS vendors publish a standing DPA.
Is Google Analytics a processor or a controller?
It depends on configuration and service: tools can act as processors for measurement performed on your behalf while acting as controllers where data feeds their own or advertising purposes. Read the data-use terms — the 'own purposes' clause is what changes the legal character and your obligations.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms