Processors
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Entities that process data on behalf of controllers
Overview
24 sources · Jul 23, 2026Legal Framework
Processors—entities that process personal data on behalf of controllers—are brought within the GDPR's scope primarily through Article 3, which establishes territorial jurisdiction over both controllers and processors established in the Union. Article 3(2) extends that reach to processors outside the EU that offer goods or services to, or monitor the behaviour of, data subjects in the Union. For such non-EU processors, Article 27 imposes a mandatory designation of an in-Union representative, though this mechanism does not insulate the processor from direct legal action:
"The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."
— GDPR Art. 27(5)
Article 23 permits Union or Member State law to restrict the scope of certain processor obligations—covering Articles 12 to 22 and Article 34—where restrictions respect the essence of fundamental rights and are necessary and proportionate in a democratic society. The definitions in Article 4 establish the breadth of "processing" that triggers processor status, encompassing operations from collection through erasure. The core obligations for processors are set out in Article 28, which requires written data processing agreements, imposes direct security duties, and governs sub-processor engagement—particularly relevant in cloud computing environments where providers routinely subcontract hosting and server capacity.
Key Developments
The Court of Justice in Schrems II confirmed that both controllers and processors bear obligations under Chapter V for international transfers, emphasising that the GDPR's protection level must not be undermined:
"Alle bepalingen van dit hoofdstuk worden toegepast opdat het door deze verordening voor natuurlijke personen gewaarborgde beschermingsniveau niet wordt ondermijnd."
— Schrems II ¶12
The EDPB's Guidelines 01/2021 further clarified that processors share practical breach-management responsibilities alongside controllers:
"Every controller and processor should have plans, procedures in place for handling eventual data breaches."
— EDPB Guidelines 01/2021 §11
Enforcement reinforces this: the AEPD's €200,000 fine against Alkora following a ransomware attack illustrates that DPAs scrutinise processor security measures and incident response capabilities in practice.
Status of the Debate
The processor regime is actively contested in court. Courts diverge on the boundaries of processor obligations—particularly around sub-processor chains, cloud computing arrangements, and the allocation of liability between controllers and processors. The EDPB's Opinion 22/2024 on processor and sub-processor obligations signals ongoing regulatory effort to clarify these boundaries, but no definitive CJEU ruling has yet resolved how far processor accountability extends into complex sub-processing chains. Resolution will likely require CJEU guidance on the scope of Article 28, particularly whether processors bear independent duties of care or remain purely derivative of controller instructions.
Practical Guidance
- Designate an EU representative under Article 27 if your processing falls within Article 3(2); ensure the written mandate covers all processing-related queries from supervisory authorities and data subjects.
- Maintain documented breach response plans and internal reporting lines, as both controllers and processors face explicit expectations under the GDPR framework.
- Conduct regular staff training on breach identification and response, as the EDPB considers this essential for processors, not merely controllers.
- Ensure sub-processor arrangements flow down equivalent contractual obligations, particularly in cloud contexts where hosting and shared server subcontracting is standard practice.
- Verify that international transfers by processors comply with Chapter V safeguards, as Schrems II confirmed that processors bear transfer obligations alongside controllers.