Skip to content
Topic Contested in court

Processors

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Entities that process data on behalf of controllers

620 linked items 35 Laws82 Case Law270 Guidance173 Enforcement28 News

Overview

24 sources · Jul 23, 2026

Legal Framework

Processors—entities that process personal data on behalf of controllers—are brought within the GDPR's scope primarily through Article 3, which establishes territorial jurisdiction over both controllers and processors established in the Union. Article 3(2) extends that reach to processors outside the EU that offer goods or services to, or monitor the behaviour of, data subjects in the Union. For such non-EU processors, Article 27 imposes a mandatory designation of an in-Union representative, though this mechanism does not insulate the processor from direct legal action:

"The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."
GDPR Art. 27(5)

Article 23 permits Union or Member State law to restrict the scope of certain processor obligations—covering Articles 12 to 22 and Article 34—where restrictions respect the essence of fundamental rights and are necessary and proportionate in a democratic society. The definitions in Article 4 establish the breadth of "processing" that triggers processor status, encompassing operations from collection through erasure. The core obligations for processors are set out in Article 28, which requires written data processing agreements, imposes direct security duties, and governs sub-processor engagement—particularly relevant in cloud computing environments where providers routinely subcontract hosting and server capacity.

Key Developments

The Court of Justice in Schrems II confirmed that both controllers and processors bear obligations under Chapter V for international transfers, emphasising that the GDPR's protection level must not be undermined:

"Alle bepalingen van dit hoofdstuk worden toegepast opdat het door deze verordening voor natuurlijke personen gewaarborgde beschermingsniveau niet wordt ondermijnd."
Schrems II ¶12

The EDPB's Guidelines 01/2021 further clarified that processors share practical breach-management responsibilities alongside controllers:

"Every controller and processor should have plans, procedures in place for handling eventual data breaches."
EDPB Guidelines 01/2021 §11

Enforcement reinforces this: the AEPD's €200,000 fine against Alkora following a ransomware attack illustrates that DPAs scrutinise processor security measures and incident response capabilities in practice.

Status of the Debate

The processor regime is actively contested in court. Courts diverge on the boundaries of processor obligations—particularly around sub-processor chains, cloud computing arrangements, and the allocation of liability between controllers and processors. The EDPB's Opinion 22/2024 on processor and sub-processor obligations signals ongoing regulatory effort to clarify these boundaries, but no definitive CJEU ruling has yet resolved how far processor accountability extends into complex sub-processing chains. Resolution will likely require CJEU guidance on the scope of Article 28, particularly whether processors bear independent duties of care or remain purely derivative of controller instructions.

Practical Guidance

  • Designate an EU representative under Article 27 if your processing falls within Article 3(2); ensure the written mandate covers all processing-related queries from supervisory authorities and data subjects.
  • Maintain documented breach response plans and internal reporting lines, as both controllers and processors face explicit expectations under the GDPR framework.
  • Conduct regular staff training on breach identification and response, as the EDPB considers this essential for processors, not merely controllers.
  • Ensure sub-processor arrangements flow down equivalent contractual obligations, particularly in cloud contexts where hosting and shared server subcontracting is standard practice.
  • Verify that international transfers by processors comply with Chapter V safeguards, as Schrems II confirmed that processors bear transfer obligations alongside controllers.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 35
art 29 Processing under the authority of the controller or processor GDPR Apr 2016 art 28 Processor GDPR Apr 2016 art 79 Right to an effective judicial remedy against a controller or processor GDPR Apr 2016 rec 81 Recital 81 — processor guarantees and contract requirements GDPR Apr 2016 rec 36 Recital 36 — main establishment of controller and processor GDPR Apr 2016 rec 95 Recital 95 — processor assistance with DPIA and prior consultation GDPR Apr 2016 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 art 44 General principle for transfers GDPR Apr 2016 art 48 Transfers or disclosures not authorised by Union law GDPR Apr 2016 art 31 Cooperation with the supervisory authority GDPR Apr 2016 rec 147 Recital 147 — specific jurisdiction rules overriding general rules GDPR Apr 2016 rec 24 Recital 24 — extraterritorial processing behaviour monitoring GDPR Apr 2016 rec 22 Recital 22 — Union establishment territorial scope GDPR Apr 2016 rec 77 Recital 77 — guidance on risk assessment and mitigation GDPR Apr 2016 rec 82 Recital 82 — records of processing activities GDPR Apr 2016 rec 83 Recital 83 — data security risk assessment and mitigation GDPR Apr 2016 rec 146 Recital 146 — liability and compensation for damage GDPR Apr 2016 rec 23 Recital 23 — extraterritorial scope non EU controllers GDPR Apr 2016 rec 164 Recital 164 — supervisory authority access and professional secrecy GDPR Apr 2016 rec 97 Recital 97 — data protection officer requirement criteria GDPR Apr 2016 Show 15 more →
Case Law 82
¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶5 Article 2 of the same directive provides: ‘For the purpose of this Directive: (a) “Personal data” shall mean any information relating to an identified… Patrick Breyer v Bundesrepublik Deutschland ¶20 Chapter IV of the GDPR, entitled ‘Controller and processor’, includes, in Section 1, itself entitled ‘General obligations’, inter alia, Articles 24 to… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – ¶24 Under Article 32 of the GDPR, entitled ‘Security of processing’: ‘1. Taking into account the state of the art, the costs of implementation and the nat… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 132/21 Judgment of the Court (First Chamber) of 12 January 2023.#BE v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Articles 77 to 79 – Remedies – Parallel exercise – Relationship – Procedural autonomy – Effectiveness of the protection rules established by that regulation – Consistent and homo Court of Justice of the European Union Jan 2023 319/20 Judgment of the Court (Third Chamber) of 28 April 2022.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 80 – Representation of the data subjects by a not-for-profit association – Representative action Court of Justice of the European Union Apr 2022 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 Supreme Administrative Court CE - 451423 Supreme Administrative Court Jun 2022 507/23 Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether Court of Justice of the European Union Oct 2024 115/22 Judgment of the Court (Grand Chamber) of 7 May 2024.#SO.#Request for a preliminary ruling from the Unabhängige Schiedskommission Wien.#Reference for a preliminary ruling – Admissibility – Article 267 TFEU – Concept of ‘court or tribunal’ – National arbitration committee competent to combat doping in sport – Criteria – Independence of the body making the reference – Principle of effective judicial protection – Inadmissibility of the request for a preliminary ruling.#Case C-115/22. Court of Justice of the European Union May 2024 Show 62 more →
Guidance 270
guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 for identifying a controller or processors lead supervisory Guidelines for identifying a controller or processor's lead supervisory authority, WP244 rev.01 EDPB May 2018 222024 on certain obligations following from the Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) EDPB Oct 2024 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 182021 on the draft standard contractual clauses Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR) EDPB May 2021 172020 on the draft standard contractual clauses Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR) EDPB May 2020 142019 on the draft standard contractual clauses Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR) EDPB Jul 2019 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 Show 250 more →
Enforcement 173
Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Garante per la protezione dei dati personali (Italy) Jul 2026 NAIH (Hungary) NAIH fines online store HUF 10M for missing and inadequate privacy notice NAIH (Hungary) Apr 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy Garante per la protezione dei dati personali (Italy) Jul 2026 NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 UODO (Poland) UODO (Poland) - DKN.5131.7.2022 UODO (Poland) Apr 2026 AEPD (Spain) AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 APDCAT (Catalonia) APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender APDCAT (Catalonia) Jul 2026 HDPA (Greece) HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers HDPA (Greece) Jun 2026 IP (Slovenia) Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) IP (Slovenia) May 2026 HDPA (Greece) HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College HDPA (Greece) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 Croatian Data Protection Authority (azop) Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Croatian Data Protection Authority (azop) Nov 2025 NL Show 153 more →
News 28
GDPRhub ICO (UK) - ACRO Criminal Records Office GDPRhub Aug 2026 European Data Protection Board The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars European Data Protection Board Jun 2026 GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub CNIL (France) - SAN-2025-014 GDPRhub Jan 2026 GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub VDAI (Litouwen) - Besluit nr. 3R-1700. GDPRhub Jan 2026 NL GDPRhub VDAI (Lithuania) - Decision No. 3R-1700. GDPRhub Jan 2026 European Data Protection Board EDPB contributes to the LED evaluation and adopts recommendations on the application for Processor BCR European Data Protection Board Jan 2026 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 Autoriteit Persoonsgegevens Three recommendations for a strong data processing agreement in the event of a cyberattack Autoriteit Persoonsgegevens Nov 2025 European Digital Rights Artificial intelligence isn't as artificial as you might think. European Digital Rights Nov 2025 Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 GDPRhub De Deense toezichthouder (SA) heeft de regio Syddanmark berispt omdat de procedures voor het controleren van verwerkingsactiviteiten niet voldoende duidelijk waren. GDPRhub Sep 2022 NL AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL News An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR? News Nov 2022 AEPD De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). AEPD Oct 2022 NL Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 News WODC: Rapport Bescherming gegeven Evaluatie UAVG meldplicht datalekken en de boetebevoegdheid News Jun 2022 NL IT en Recht Is the new ICT vendor liable for loss of data from old ICT environment? IT en Recht Mar 2023 Show 8 more →
Literature 30
SSRN Electronic Journal Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World SSRN Electronic Journal Jan 2020 European Data Protection Law Review European Union ∙ EDPB Opinion 14/2019 on Standard Contractual Clauses for Processors under Article 28(8) GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 Show 10 more →
Tools 2
ICO ICO documentation templates (records of processing, Article 30) ICO Jul 2026 European Commission Standard Contractual Clauses (SCCs) for international transfers European Commission Jul 2026