Data Processor
A person or organisation that processes personal data on behalf of, and under the instructions of, a data controller. A processor has more limited compliance obligations than a controller, but can itself become liable as a controller if it processes data outside the controller's instructions.
Independent editorial summary — not the official statute text. Read the official version on legislation.gov.uk.
The ICO sets out the UK GDPR's definition without embellishment: a '‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.' Unlike a controller, a processor does not decide why personal data is processed — only how, and even then usually within limits the controller has set.
Guidance is explicit about where the processor's loyalties lie: 'Processors act on behalf of the relevant controller and under their authority. In doing so, they serve the controller's interests rather than their own.' IT support companies and payroll providers are common real-world examples. If a processor starts making its own decisions about the purposes or means of processing — rather than simply following the controller's instructions — it steps outside the role of processor and takes on a controller's responsibilities and liability for that processing.
Related terms
Official sources
This explanation is drawn from the official sources below; every substantive statement is verified against them. For advice on a specific matter, see our find help page.