Skip to main content

SponsoredBuild your website with Vincony

Disclaimer: This is not legal advice. Legislation and case law change. Always consult a qualified solicitor for your specific situation.

UK Law Reference
Full glossary
Legal term
Data Protection & Privacy Law

Data Processor

A person or organisation that processes personal data on behalf of, and under the instructions of, a data controller. A processor has more limited compliance obligations than a controller, but can itself become liable as a controller if it processes data outside the controller's instructions.

Independent editorial summary — not the official statute text. Read the official version on legislation.gov.uk.

The ICO sets out the UK GDPR's definition without embellishment: a '‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.' Unlike a controller, a processor does not decide why personal data is processed — only how, and even then usually within limits the controller has set.

Guidance is explicit about where the processor's loyalties lie: 'Processors act on behalf of the relevant controller and under their authority. In doing so, they serve the controller's interests rather than their own.' IT support companies and payroll providers are common real-world examples. If a processor starts making its own decisions about the purposes or means of processing — rather than simply following the controller's instructions — it steps outside the role of processor and takes on a controller's responsibilities and liability for that processing.

Related terms

Official sources

This explanation is drawn from the official sources below; every substantive statement is verified against them. For advice on a specific matter, see our find help page.