Certix

Data processor: what it is and when you need one

Certix
Certix®
· 30 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

Every time your company hires an accounting firm for payroll, uploads its customer base to a cloud CRM or lets an agency manage its marketing database, you are placing personal data in the hands of a third party. That third party has a specific name in the GDPR: the data processor. And the relationship you maintain with it is not held together by a simple commercial agreement, but by a specific contract that the rules themselves require.

The concept of the data processor is, together with that of the controller, one of the pillars of the Regulation. It is also one of the most frequent sources of confusion: many companies do not know whether they are the controller or the processor, or what role each supplier with whom they share data plays. This guide clarifies exactly what the data processor is, how it differs from the controller, what obligations it takes on and when you need to sign a processing agreement.

In short

  • The data processor (art. 4(8) GDPR) processes personal data on behalf of the controller, following its instructions and without deciding what it is used for.
  • The controller (art. 4(7) GDPR) determines the purposes and means; the processor only executes. That is the key difference.
  • Art. 28 GDPR requires the relationship to be governed by a written processing agreement with specific minimum content (art. 28(3) GDPR).
  • Common processors are: your accounting firm, your cloud software, your marketing agency, your IT company, your email marketing platform or your hosting.

Definition of the data processor under the GDPR

Art. 4(8) GDPR defines the data processor as the natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller. The central idea lies in those words: on behalf of the controller.

The processor does not own the decision about the data. It receives instructions from the controller and carries them out. When an accounting firm processes your workforce's payroll, it does not decide what is done with that data: it processes the information that you, as the company, have decided to outsource for a purpose you have set. The accounting firm provides the means (its software, its staff, its know-how), but the purpose — paying your employees' salaries — is determined by you.

At the other end of the relationship is the controller, defined in art. 4(7) GDPR as the one who determines the purposes and means of the processing. The controller is the centre of gravity: it makes the decisions, answers to data subjects and chooses the processors it works with. The processor orbits around those decisions.

Difference between controller and processor

Distinguishing the two figures is the number one source of confusion in data protection, and the rule to resolve it fits in one sentence: the controller decides, the processor executes. Whoever determines what for and how data is processed is the controller; whoever processes it following those instructions, on someone else's behalf, is the processor.

A single company can be the controller in one relationship and the processor in another. Your accounting firm is the processor in respect of the payroll it processes on your behalf, but it is the controller in respect of the data of its own employees or its own invoicing. What defines the role is not the size of the company, but who decides in each specific processing activity.

Aspect Controller (art. 4(7) GDPR) Processor (art. 4(8) GDPR)
Who it is Determines the purposes and means of the processing. Processes the data on behalf of the controller.
Decision Decides what for and how the data is used. Executes the instructions received; does not set its own purposes.
Relationship with the data subject Is the main point of contact for the data subject. Assists the controller in addressing the data subject's rights.
Instrument that binds them Chooses the processor and gives it instructions. Processing agreement under art. 28 GDPR.
Example The company that outsources its payroll. The accounting firm that processes that payroll.

Obligations of the data processor

Art. 28 GDPR regulates the relationship between controller and processor in detail, and from it derive the main obligations taken on by whoever processes data on someone else's behalf. They are not formal burdens: they are conditions that protect the data subject and give security to the company that outsources. The most relevant ones are:

  • Processing the data only according to the controller's instructions. The processor does not use the information for its own purposes other than the contracted service.
  • Confidentiality of staff. The people who access the data must be bound by a duty of confidentiality.
  • Security measures appropriate to the risk of the processing, in line with art. 32 GDPR.
  • Not subcontracting without authorisation. Engaging another processor (sub-processor) requires the controller's prior authorisation (art. 28(2) and art. 28(4) GDPR).
  • Assisting the controller in addressing the data subject's rights and in its security and breach notification obligations.
  • Returning or deleting the data at the end of the service (art. 28(3)(g) GDPR), a point that deserves its own detail below.

When do you need a data processing agreement?

Whenever a third party accesses or processes personal data on behalf of your company. Art. 28(3) GDPR requires that relationship to be governed by a contract or another binding legal act in writing. It is not optional, nor does it depend on the size of the supplier: as soon as someone external handles your data, the processing agreement is needed.

The frequent mistake is to think that an ordinary commercial agreement — the quote, the invoice or the service terms — already covers that relationship. It does not. The processing agreement is a specific document with minimum content that the rules expressly set out, and its absence leaves the relationship with the supplier outside the umbrella of the GDPR, even if the service runs normally.

What the data processing agreement must include

Art. 28(3) GDPR provides that the processing agreement must be in writing and govern, as a minimum, a set of specific elements. A generic mention is not enough: each of these points must be defined in relation to the actual service the processor provides.

  • The subject matter of the processing. Exactly which processing activity is being entrusted.
  • The duration of the processing, usually linked to the term of the service.
  • The nature and purpose of the processing.
  • The type of personal data involved.
  • The categories of data subjects affected (customers, employees, suppliers, etc.).
  • The obligations and rights of the controller within that relationship.

One of the elements of art. 28(3) is worth pausing on, because it concentrates a common mistake: what happens to the data when the relationship ends. Art. 28(3)(g) GDPR provides that, at the end of the service, the processor must return or delete the data — at the controller's choice — and delete existing copies.

The priority obligation is to return the data or allow the controller to export it, so that the controller can meet its own legal retention periods (tax, employment, commercial). Definitive deletion comes afterwards, once the controller has the information. That is why a well-drafted processing agreement never says only "destroy the data at the end": it first provides for the return or export and reserves deletion for the moment when the controller already has what it needs.

"Almost no one disputes that the processing agreement is needed. The problem is that a generic template gets signed that neither describes the real processing nor properly governs what happens to the data at the end. An art. 28 contract that orders the information to be destroyed with nothing more is a contract that puts at risk the client who signs it."

Mario P. Talamillo · Managing Partner, Certix®

Common examples of processors in a company

The figure of the data processor appears in almost any company, though often without those in charge identifying it as such. These are the most frequent cases:

  • The accounting or advisory firm that processes your payroll and your workforce's employment documentation.
  • The cloud software or SaaS where you store information: the CRM with your customer base, the ERP with your suppliers.
  • The marketing agency that manages the customer database you have entrusted to it.
  • The IT company that maintains your servers and, in doing so, accesses the data they contain.
  • The email marketing platform from which you send communications to your subscriber list.
  • The hosting provider where your website and the data you collect through it are hosted.

In all these cases, your company is the controller and the supplier is the processor. And in all of them an art. 28 GDPR processing agreement is needed to govern the relationship. Identifying all the processors you work with, and checking that each one has its contract properly drafted, is one of the basic tasks of any data protection consultancy.

Frequently asked questions

What is the data processor under the GDPR?

The data processor is the natural or legal person that processes personal data on behalf of the controller (art. 4(8) GDPR). It does not decide what the data is used for: it carries out what the controller instructs. The controller (art. 4(7) GDPR) is the one who determines the purposes and means. Typical examples of a processor: the accounting firm that processes your payroll, the cloud software where you store your customer base or the marketing agency that manages your database.

What is the difference between controller and processor?

The controller decides; the processor executes. The controller (art. 4(7) GDPR) determines the purposes and the means of the processing: it owns the decision on what the data is used for and how. The processor (art. 4(8) GDPR) processes that data on behalf of the controller, following its instructions and without using it for its own purposes. A single company can be controller of some processing activities and processor of others, depending on the role it plays in each relationship.

When is it mandatory to sign a data processing agreement?

Whenever a third party accesses or processes personal data on behalf of your company. Art. 28(3) GDPR requires that relationship to be governed by a contract or another binding legal act in writing. It applies to your accounting firm, your cloud software provider, the IT company that maintains your servers, your email marketing platform or your hosting. Without that contract, the relationship with the supplier is not covered by the GDPR.

What happens to the data when the contract with the processor ends?

At the end of the service, the processor must return or delete the data at the controller's choice and delete existing copies (art. 28(3)(g) GDPR). The priority obligation is for the processor to return the data or allow the controller to export it, so that the controller can meet its own legal retention periods. Definitive deletion comes only after the controller has the information, never as an automatic response to the termination of the service.

Conclusion

The data processor is not a technicality of the GDPR: it is the figure that describes almost all the suppliers with whom your company shares data. Knowing how to tell it apart from the controller — the controller decides, the processor executes — lets you correctly identify your position in each relationship and, above all, detect which processing agreements you need to sign and review.

The critical point lies in the quality of those contracts. A generic processing agreement, one that does not describe the real processing or that orders the data to be "destroyed" without first providing for its return, leaves whoever signs it unprotected. At Certix we draft and review the processing agreements of each supplier so that they reflect the real service and meet the content of art. 28 GDPR. You can consult our complete GDPR guide to place this figure within the framework as a whole.


This content is purely informational and educational; it does not constitute specialised legal advice in any case. Applying the rules to each specific case requires individual analysis.

Are your suppliers' processing agreements in order?

At Certix we identify your data processors and draft each art. 28 GDPR contract. You are attended directly by an expert, with no commercial intermediaries.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →