Direct answer · GDPR
Processor and data processing agreement
A supplier that processes personal data only on behalf of and on the instructions of the customer is a processor (Article 4(8)). The processing must then be governed by a contract (Article 28(3)) that provides, among other things: processing only on documented instructions; confidentiality of the persons processing the data; security in accordance with Article 32; conditions for engaging sub-processors (Article 28(2) and (4)); assistance with data subjects' requests and with the obligations of Articles 32 to 36; deletion or return of the data at the end of the service; and information and cooperation for audits. If the supplier determines purposes or means itself, it becomes a controller for that part (Article 28(10)).
For you to establish
- Does the supplier also use the data for its own purposes, such as improving its product?
Articles
- Art. 4(8) GDPR Definition of processor.
- Art. 28(3)(a) to (h) GDPR Mandatory content of the data processing agreement.
- Art. 28(10) GDPR Whoever determines purposes and means itself is a controller.
Guidelines and decisions
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR (EDPB, v2.1, 2021-07-07)Guidelines on the concepts of controller and processor.
- Standard contractual clauses between controllers and processors (European Commission, (EU) 2021/915, 2021-06-04)Standard contractual clauses between controllers and processors.
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) (EDPB, 2024-10-07)Obligations when relying on processors and sub-processors.
