The General Data Protection Regulation (GDPR) imposes specific obligations on data processors — entities that process personal data on behalf of a controller. Understanding these obligations is critical for any organisation operating as a processor or engaging processors for data handling.
Who Is a Processor?
Under Article 4(8) of the GDPR, a processor is any entity that processes personal data on behalf of the controller. The distinguishing factor is that the processor does not determine the purposes or means of processing — that decision rests with the controller.
Common examples include:
- Cloud service providers (AWS, Azure, GCP) hosting personal data
- Payroll processing companies handling employee data
- Marketing agencies conducting email campaigns on behalf of clients
- IT service providers with access to client databases
Article 28: The Processor’s Charter
Article 28 is the cornerstone provision governing the controller-processor relationship. Key requirements include:
Documented Instructions
The processor must process personal data only on documented instructions from the controller. Any processing outside these instructions — unless required by EU or Member State law — constitutes a breach.
Sub-Processor Management
Processors cannot engage sub-processors without the controller’s prior specific or general written authorisation. If general authorisation is given, the processor must:
- Inform the controller of any intended changes
- Give the controller an opportunity to object
- Impose the same data protection obligations on the sub-processor
Security Obligations
Processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption and pseudonymisation where appropriate
- Ensuring ongoing confidentiality, integrity, and availability
- Regular testing of security measures
- Ability to restore data after an incident
Cross-Border Implications for Indian Companies
For Indian IT services companies acting as processors for EU controllers, these obligations have particular significance. The processor must ensure that any transfer of personal data to India complies with Chapter V of the GDPR, typically through:
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
- The controller’s explicit consent arrangements
Practical tip: Indian companies should ensure their Data Processing Agreements (DPAs) explicitly address sub-processor chains, as many Indian IT firms further sub-contract to smaller vendors, creating complex processing chains that require full GDPR compliance at each link.
Penalties for Non-Compliance
Processors face direct liability under GDPR. Administrative fines for processor violations can reach €10 million or 2% of global annual turnover, whichever is higher. In cases involving basic processing principle violations, fines can escalate to €20 million or 4% of turnover.
Key Takeaways
| Obligation | GDPR Article | Key Requirement |
|---|---|---|
| Processing scope | Art. 28(3)(a) | Only on controller’s documented instructions |
| Sub-processors | Art. 28(2) | Prior written authorisation required |
| Security | Art. 28(3)(c) + Art. 32 | Appropriate technical and organisational measures |
| Breach notification | Art. 33(2) | Notify controller without undue delay |
| DPO | Art. 37 | Appoint where required by processing activities |
| Records | Art. 30(2) | Maintain records of processing activities |
Understanding and implementing these obligations is essential for any organisation operating in the EU data protection ecosystem, whether as a processor or a controller engaging processors.