Skip to content
Topic Contested in court

Processors

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Entities that process data on behalf of controllers

695 linked items 35 Laws91 Case Law283 Guidance227 Enforcement24 News

Overview

28 sources · Sep 25, 2026

Legal Framework

The processor regime is anchored in Article 28 GDPR, which governs the entire controller-processor relationship, supplemented by Article 29 (processing under authority), Article 82 (liability), and Article 4(8) (definition of "processor"). Article 28 imposes a layered set of obligations: the controller must select a processor providing sufficient guarantees (Article 28(1)), the processor must not engage sub-processors without authorisation (Article 28(2)), and the relationship must be governed by a binding contract meeting the stipulations of Article 28(3).

"The processor shall not engage another processor without prior specific or general written authorisation of the controller."
— GDPR Art. 28(2)

Where a general authorisation is granted, the processor must inform the controller of intended additions or replacements, giving the controller the opportunity to object. The contract under Article 28(3) must specify the subject-matter, duration, nature, purpose, data types, and categories of data subjects, and must require the processor to process only on documented instructions. Article 29 extends this instruction-duty to any person acting under the processor's authority who accesses personal data.

Liability is asymmetric. Under Article 82(2), a processor is liable only where it fails to meet processor-specific obligations or acts outside lawful instructions. Joint and several liability applies under Article 82(4) where multiple parties are involved, with a right of recourse under Article 82(5).

Key Developments

The Court of Justice has confirmed that Article 29's instruction requirement binds not only the processor itself but all persons acting under its authority. In GP v juris GmbH, the Court quoted the provision verbatim, underscoring its mandatory character:

"The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law."
— GP v juris GmbH ¶10

The boundary between processor and controller conduct remains critical. In Nacionalinis visuomenės sveikatos centras, the CJEU reaffirmed Article 28(10)'s reclassification mechanism:

"if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing."
— Nacionalinis visuomenės sveikatos centras ¶6

Enforcement authorities have applied these provisions strictly. In the Midlands Regional Hospital Tullamore case, the Irish DPC found that routine hardware and software maintenance involving access to personal data constituted processing on behalf of the controller, triggering Article 28's contractual requirements. The DPC noted that the controller had failed to demonstrate a signed data processing agreement with its infrastructure provider, despite the provider having prepared a template agreement.

Status of the Debate

This topic is actively contested in court. The core obligations under Articles 28 and 29 are well-established, but their application to complex multi-party arrangements—particularly in cloud computing and sub-processing chains—remains unsettled. Courts have diverged on how far a processor's autonomy extends before triggering reclassification as a controller under Article 28(10). The EDPB's Opinion 22/2024 and Guidelines 07/2020 attempt to define the boundaries, but the precise threshold for when a processor's technical decisions constitute "determining the means" of processing is not yet resolved by a definitive CJEU ruling. A future preliminary reference directly addressing sub-processor liability chains or the scope of "documented instructions" in cloud environments would clarify the open questions.

Practical Guidance

  • Document the processor relationship in a binding contract that meets all Article 28(3) stipulations—subject-matter, duration, data types, instruction mechanisms, and sub-processor terms. A generic template is insufficient; the Irish DPC found a controller non-compliant despite the provider having prepared a template agreement that was never executed.

  • Control sub-processor chains explicitly: grant either specific or general written authorisation under Article 28(2), and where general authorisation is used, establish a notification-and-objection mechanism for any additions or replacements.

  • Ensure instructions are documented and specific: Article 28(3)(a) and Article 29 require processing only on documented instructions. Ambiguous or verbal instructions leave the processor exposed to liability under Article 82(2) for acting "outside or contrary to lawful instructions."

  • Monitor for controller-like conduct: if the processor begins determining purposes or means of processing independently, Article 28(10) reclassifies it as a controller for that processing, with the full liability exposure that entails. Contractual language alone cannot prevent this reclassification.

  • Restrict third-country transfers in instructions: per EDPB guidance, if controller instructions do not permit transfers, the processor cannot assign processing to sub-processors in third countries or process data in its own non-EU divisions.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 29 Processing under the authority of the controller or processor Laws GDPR Apr 2016 processor's obligation to controller
why this is here
The processor and any person acting under the authority of the controller or of the processor

This is a primary statement of the processor's duty to follow controller instructions, directly paralleling Article 28's obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Definition and obligations of processors
why this is here
A processor is a natural or legal person, public authority, agency or another body, which processes personal data on behalf of the controller.

The document defines processors, their conditions, and their obligations under Article 28.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 28 Processor Laws GDPR Apr 2016 processor obligations and sub-processing
why this is here
The processor shall not engage another processor without prior specific or general written authorisation of the controller

The provision centrally defines processor duties, including sub-processing restrictions and contractual requirements, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 31 Cooperation with the supervisory authority Laws GDPR Apr 2016 Obligation to cooperate
why this is here
The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority

Extends the cooperation duty to processors as well as controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Guidance EDPB Apr 2023 main establishment for processors
why this is here
as regards a processor with establishments in more than one Member State, the place of its central administration in the Union

The document includes guidance on identifying the main establishment for processors.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 79 Right to an effective judicial remedy against a controller or processor Laws GDPR Apr 2016 Court jurisdiction over processors
why this is here
Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment.

The provision mentions processors only to establish the forum for legal actions against them, without addressing their substantive duties.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 44 General principle for transfers Laws GDPR Apr 2016 Mentions processors but no substantive rules
why this is here
the conditions laid down in this Chapter are complied with by the controller and processor

Processors are referenced as compliance actors, but the provision does not address processor-specific obligations or roles.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Is the new ICT vendor liable for loss of data from old ICT environment? District Court of North Holland February 15, 2023, IT 4241; ECLI:NL:RBNHO:2023:2471 (Pit v. OfficeGrip Holding c.s.) This case deals with the question of whether a new ICT… News IT en Recht Mar 2023 supplier as potential processor
why this is here
the new ICT supplier cannot be held liable for any damages suffered by the client as a result of data loss from the old ICT environment

The supplier is not characterized as a processor; the case is about contractual obligations for old ICT environments, not about processing on behalf of a controller under GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

DeFine is a calculator for GDPR fines based on method of the EDPB > DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the… News Kromann Reumert Feb 2022 controller/processor in fine calculation
why this is here
aggravating and mitigating circumstances related to past or present behaviour of the controller/processor

Processors are mentioned as subjects of fines but the document is not about processor obligations or agreements.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the… News Datatilsynet Sep 2022 Google as processor
why this is here
Google Analytics, Google’s audience measurement tool

Google is implicitly a processor, but the document does not analyze processor obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 35 Laws · all 283 Guidance · all 91 Case Law · all 227 Enforcement · all 33 Literature · all 24 News