Disclaimer

Bar Council of India Rules

The Bar Council of India does not permit advertisement or solicitation by advocates in any form or manner. By accessing this website, biztechai.in, you acknowledge and confirm that you are seeking information relating to Advocate Pushpesh Paliwal of your own accord and that there has been no form of solicitation, advertisement or inducement by Advocate Pushpesh Paliwal.

The content of this website is for informational purposes only and should not be interpreted as soliciting or advertisement. No material or information provided on this website should be construed as legal advice. Advocate Pushpesh Paliwal shall not be liable for consequences of any action taken by relying on the material or information provided on this website.

The contents of this website are the intellectual property of Advocate Pushpesh Paliwal.

Cookies on This Website

This website uses a small number of cookies to function and to understand how visitors use the site:

Data Protection

GDPR Processor Obligations: A 2026 Briefing

A comprehensive briefing on GDPR processor obligations in 2026, covering Article 28 requirements, sub-processor management, and cross-border data transfer rules.
GDPR Processor Obligations: A 2026 Briefing

The General Data Protection Regulation (GDPR) imposes specific obligations on data processors — entities that process personal data on behalf of a controller. Understanding these obligations is critical for any organisation operating as a processor or engaging processors for data handling.

Who Is a Processor?

Under Article 4(8) of the GDPR, a processor is any entity that processes personal data on behalf of the controller. The distinguishing factor is that the processor does not determine the purposes or means of processing — that decision rests with the controller.

Common examples include:

  • Cloud service providers (AWS, Azure, GCP) hosting personal data
  • Payroll processing companies handling employee data
  • Marketing agencies conducting email campaigns on behalf of clients
  • IT service providers with access to client databases

Article 28: The Processor’s Charter

Article 28 is the cornerstone provision governing the controller-processor relationship. Key requirements include:

Documented Instructions

The processor must process personal data only on documented instructions from the controller. Any processing outside these instructions — unless required by EU or Member State law — constitutes a breach.

Sub-Processor Management

Processors cannot engage sub-processors without the controller’s prior specific or general written authorisation. If general authorisation is given, the processor must:

  1. Inform the controller of any intended changes
  2. Give the controller an opportunity to object
  3. Impose the same data protection obligations on the sub-processor

Security Obligations

Processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption and pseudonymisation where appropriate
  • Ensuring ongoing confidentiality, integrity, and availability
  • Regular testing of security measures
  • Ability to restore data after an incident

Cross-Border Implications for Indian Companies

For Indian IT services companies acting as processors for EU controllers, these obligations have particular significance. The processor must ensure that any transfer of personal data to India complies with Chapter V of the GDPR, typically through:

  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)
  • The controller’s explicit consent arrangements

Practical tip: Indian companies should ensure their Data Processing Agreements (DPAs) explicitly address sub-processor chains, as many Indian IT firms further sub-contract to smaller vendors, creating complex processing chains that require full GDPR compliance at each link.

Penalties for Non-Compliance

Processors face direct liability under GDPR. Administrative fines for processor violations can reach €10 million or 2% of global annual turnover, whichever is higher. In cases involving basic processing principle violations, fines can escalate to €20 million or 4% of turnover.

Key Takeaways

Obligation GDPR Article Key Requirement
Processing scope Art. 28(3)(a) Only on controller’s documented instructions
Sub-processors Art. 28(2) Prior written authorisation required
Security Art. 28(3)(c) + Art. 32 Appropriate technical and organisational measures
Breach notification Art. 33(2) Notify controller without undue delay
DPO Art. 37 Appoint where required by processing activities
Records Art. 30(2) Maintain records of processing activities

Understanding and implementing these obligations is essential for any organisation operating in the EU data protection ecosystem, whether as a processor or a controller engaging processors.

Pushpesh Paliwal biztechai.in