Processors
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Entities that process data on behalf of controllers
Overview
28 sources · Sep 25, 2026Legal Framework
The processor regime is anchored in Article 28 GDPR, which governs the entire controller-processor relationship, supplemented by Article 29 (processing under authority), Article 82 (liability), and Article 4(8) (definition of "processor"). Article 28 imposes a layered set of obligations: the controller must select a processor providing sufficient guarantees (Article 28(1)), the processor must not engage sub-processors without authorisation (Article 28(2)), and the relationship must be governed by a binding contract meeting the stipulations of Article 28(3).
"The processor shall not engage another processor without prior specific or general written authorisation of the controller."
— GDPR Art. 28(2)
Where a general authorisation is granted, the processor must inform the controller of intended additions or replacements, giving the controller the opportunity to object. The contract under Article 28(3) must specify the subject-matter, duration, nature, purpose, data types, and categories of data subjects, and must require the processor to process only on documented instructions. Article 29 extends this instruction-duty to any person acting under the processor's authority who accesses personal data.
Liability is asymmetric. Under Article 82(2), a processor is liable only where it fails to meet processor-specific obligations or acts outside lawful instructions. Joint and several liability applies under Article 82(4) where multiple parties are involved, with a right of recourse under Article 82(5).
Key Developments
The Court of Justice has confirmed that Article 29's instruction requirement binds not only the processor itself but all persons acting under its authority. In GP v juris GmbH, the Court quoted the provision verbatim, underscoring its mandatory character:
"The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law."
— GP v juris GmbH ¶10
The boundary between processor and controller conduct remains critical. In Nacionalinis visuomenės sveikatos centras, the CJEU reaffirmed Article 28(10)'s reclassification mechanism:
"if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing."
— Nacionalinis visuomenės sveikatos centras ¶6
Enforcement authorities have applied these provisions strictly. In the Midlands Regional Hospital Tullamore case, the Irish DPC found that routine hardware and software maintenance involving access to personal data constituted processing on behalf of the controller, triggering Article 28's contractual requirements. The DPC noted that the controller had failed to demonstrate a signed data processing agreement with its infrastructure provider, despite the provider having prepared a template agreement.
Status of the Debate
This topic is actively contested in court. The core obligations under Articles 28 and 29 are well-established, but their application to complex multi-party arrangements—particularly in cloud computing and sub-processing chains—remains unsettled. Courts have diverged on how far a processor's autonomy extends before triggering reclassification as a controller under Article 28(10). The EDPB's Opinion 22/2024 and Guidelines 07/2020 attempt to define the boundaries, but the precise threshold for when a processor's technical decisions constitute "determining the means" of processing is not yet resolved by a definitive CJEU ruling. A future preliminary reference directly addressing sub-processor liability chains or the scope of "documented instructions" in cloud environments would clarify the open questions.
Practical Guidance
Document the processor relationship in a binding contract that meets all Article 28(3) stipulations—subject-matter, duration, data types, instruction mechanisms, and sub-processor terms. A generic template is insufficient; the Irish DPC found a controller non-compliant despite the provider having prepared a template agreement that was never executed.
Control sub-processor chains explicitly: grant either specific or general written authorisation under Article 28(2), and where general authorisation is used, establish a notification-and-objection mechanism for any additions or replacements.
Ensure instructions are documented and specific: Article 28(3)(a) and Article 29 require processing only on documented instructions. Ambiguous or verbal instructions leave the processor exposed to liability under Article 82(2) for acting "outside or contrary to lawful instructions."
Monitor for controller-like conduct: if the processor begins determining purposes or means of processing independently, Article 28(10) reclassifies it as a controller for that processing, with the full liability exposure that entails. Contractual language alone cannot prevent this reclassification.
Restrict third-country transfers in instructions: per EDPB guidance, if controller instructions do not permit transfers, the processor cannot assign processing to sub-processors in third countries or process data in its own non-EU divisions.
why this is here
The processor and any person acting under the authority of the controller or of the processor
This is a primary statement of the processor's duty to follow controller instructions, directly paralleling Article 28's obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
A processor is a natural or legal person, public authority, agency or another body, which processes personal data on behalf of the controller.
The document defines processors, their conditions, and their obligations under Article 28.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The processor shall not engage another processor without prior specific or general written authorisation of the controller
The provision centrally defines processor duties, including sub-processing restrictions and contractual requirements, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority
Extends the cooperation duty to processors as well as controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
as regards a processor with establishments in more than one Member State, the place of its central administration in the Union
The document includes guidance on identifying the main establishment for processors.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment.
The provision mentions processors only to establish the forum for legal actions against them, without addressing their substantive duties.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the conditions laid down in this Chapter are complied with by the controller and processor
Processors are referenced as compliance actors, but the provision does not address processor-specific obligations or roles.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the new ICT supplier cannot be held liable for any damages suffered by the client as a result of data loss from the old ICT environment
The supplier is not characterized as a processor; the case is about contractual obligations for old ICT environments, not about processing on behalf of a controller under GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
aggravating and mitigating circumstances related to past or present behaviour of the controller/processor
Processors are mentioned as subjects of fines but the document is not about processor obligations or agreements.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Google Analytics, Google’s audience measurement tool
Google is implicitly a processor, but the document does not analyze processor obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 35 Laws · all 283 Guidance · all 91 Case Law · all 227 Enforcement · all 33 Literature · all 24 News