Skip to content
← All terms

Glossary · Privacy & regulation

Data processor

A data processor is the natural or legal person that processes personal data on behalf of, and under the instructions of, a data controller — without independently deciding why or how that data is used.

The processor’s defining trait under GDPR Article 4(8) is following instructions: it acts on the controller’s documented directions rather than setting its own purposes for the data. A cloud hosting provider, an email-delivery service, or an analytics vendor operating on a customer’s behalf are typical processors — they handle the mechanics of storage, transmission, or computation without deciding what the data is collected for in the first place.

GDPR Article 28 imposes direct obligations on processors, not just controllers: implementing appropriate security measures, assisting the controller with data-subject rights and breach notifications, not engaging a sub-processor without authorization, and deleting or returning data when the engagement ends. A processor that starts determining its own purposes for the data — repurposing it beyond the controller’s instructions — risks being reclassified as a controller (or joint controller) for that processing, with the fuller compliance burden that implies.

Where Ciphera runs infrastructure that a customer uses to manage its own end users’ data — Ciphera ID for authentication, Pulse for analytics — Ciphera typically sits in the processor role, bound by the DPA the customer relationship establishes.

See also

Related terms