# Processor (Article 4(8) GDPR)

A processor is any body that processes personal data on behalf of the controller. The GDPR establishes the processor's own obligations and independent liability.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter
> Sprache: en



Article 4(8) GDPR defines the processor as a natural or legal person, public authority, agency or other body which processes personal data on behalf of the [controller](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher). The concept replaces the earlier term "commissioned data processing" (Auftragsdatenverarbeitung) under the old German Federal Data Protection Act (BDSG) and has gained considerably more definition in substantive terms compared with it.

<Callout type="info">
  **Key takeaways**

  * A processor processes personal data exclusively on the controller's instructions, not for its own purposes.
  * The GDPR imposes its own obligations on the processor: a record of processing activities under Article 30(2) GDPR and, where applicable, the designation of a representative under Article 27 GDPR.
  * Processing and sub-processing mandatorily require a contract that meets the minimum requirements of Article 28(3) GDPR. Standard contractual clauses are available for this contract (Implementing Decision (EU) 2021/915).
  * If the processor itself determines the purposes and means of the processing, it becomes a controller in its own right under Article 28(10) GDPR.
  * Alongside the controller, the processor is also liable for damages under Article 82 GDPR; in the external relationship, liability is joint and several.
</Callout>

## 1. Overview [#1-overview]

### 1.1 Definition and distinction from the former legal position [#11-definition-and-distinction-from-the-former-legal-position]

A processor is any body that processes personal data not for its own purposes but on the instructions and for the account of a controller. Being bound by instructions is the core characteristic: the processor does not itself decide why and in what manner the data are processed; that remains the controller's task (Article 4(8) GDPR).

Compared with the former law, the role of the processor has changed fundamentally. Under the old BDSG understanding, the contractor was regarded as an extended arm of the principal; obligations and liability lay almost exclusively with the controller. The GDPR breaks with this conception: it addresses the processor with its own, directly applicable obligations and makes it liable for their breach.

### 1.2 Practical significance [#12-practical-significance]

Almost any use of external IT service providers gives rise to processing on behalf of a controller: cloud infrastructure, software-as-a-service, external hosting, payroll accounting, and debt collection activities are typical use cases. As long as the claim has not been assigned to the service provider, a debt collection or billing agency acts on behalf of the controller and is to be classified as a processor. Cloud computing, too, is generally regarded as processing on behalf of a controller.

## 2. Obligations of the processor [#2-obligations-of-the-processor]

### 2.1 Record of processing activities [#21-record-of-processing-activities]

Unlike under the old law, the processor maintains its own [record of processing activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten) under Article 30(2) GDPR. The record must contain the names and contact details of all controllers on whose behalf the processor acts, the categories of processing carried out on their behalf, and a general description of the technical and organizational measures under Article 32(1) GDPR. The record-keeping obligation applies regardless of the size of the undertaking.

### 2.2 Representative in the Union [#22-representative-in-the-union]

If the processor is not established in the European Union, it is obliged under Article 27 GDPR to designate a representative in the Union in writing. The representative acts as a point of contact for data subjects and supervisory authorities. Exempt are only occasional processing operations without particular risk, as well as processing carried out by public authorities.

## 3. Contractual basis of processing on behalf of a controller [#3-contractual-basis-of-processing-on-behalf-of-a-controller]

### 3.1 Obligation to conclude a data processing agreement [#31-obligation-to-conclude-a-data-processing-agreement]

Every instance of processing on behalf of a controller requires a contract or another legal act (Article 28(3) GDPR). This contract must be drawn up in writing or in electronic form and must have a minimum content: it sets out the subject-matter, duration, nature and purpose of the processing, the type of personal data, and the categories of data subjects. In addition, it governs the controller's specific powers to issue instructions and the processor's obligations, in particular regarding confidentiality, the implementation of technical and organizational measures, assistance in giving effect to data subjects' rights, and the erasure or return of the data after the end of the assignment.

### 3.2 Standard contractual clauses [#32-standard-contractual-clauses]

For the drafting of the contract under Article 28(3) GDPR, the European Commission has adopted standard contractual clauses (Implementing Decision (EU) 2021/915 of 4 June 2021). Controllers and processors may adopt these clauses directly in order to meet the requirements of Article 28(3) and (4) GDPR. Their use does not dispense with a substantive assessment of the processing situation; additional agreements are permissible as long as they do not contradict the clauses.

### 3.3 Sub-processing arrangements [#33-sub-processing-arrangements]

The processor may engage further processors (sub-processors) only where the controller has consented to this (Article 28(2) GDPR). Consent may be given generally or specifically; in the case of general authorization, the processor must inform the controller of any intended changes. The sub-processor must be bound by a contract that contains the same data protection obligations as the main contract (Article 28(4) GDPR). If the sub-processor fails to meet these obligations, the original processor remains fully liable to the controller.

<Callout type="warn">
  A contract with a service provider that processes personal data without meeting the requirements of Article 28(3) GDPR does not establish valid processing on behalf of a controller. In that case there is no legal basis for the disclosure of the data, which constitutes a separate data protection infringement and triggers the risk of fines under Article 83(4)(a) GDPR.
</Callout>

## 4. Liability [#4-liability]

### 4.1 The processor's own liability [#41-the-processors-own-liability]

The GDPR has fundamentally changed the liability situation. Whereas under the old law responsibility in the external relationship lay essentially with the principal, the processor is now itself liable under Article 82 GDPR for compensation for material and non-material damage. The basis of liability is a breach of GDPR obligations specifically directed at the processor, or conduct outside or contrary to the lawful instructions of the controller.

### 4.2 Joint and several liability [#42-joint-and-several-liability]

Where, in addition to the processor, the controller is also responsible for the same damage, both are jointly and severally liable to the data subject (Article 82(4) GDPR). The data subject may claim the full compensation from any of the entities involved. In the internal relationship, an apportionment is made according to the respective degree of responsibility. A processor can be exempt from liability only if it proves that it is not in any way responsible for the event giving rise to the damage (Article 82(3) GDPR).

## 5. The processor as a controller [#5-the-processor-as-a-controller]

If the processor exceeds the limits of the assignment and independently determines the purposes and means of the processing, it becomes a controller in its own right, within the meaning of Article 4(7) GDPR, under Article 28(10) GDPR. Classification as a processor therefore does not provide permanent protection against being treated as a controller; what is decisive is who actually determines the purposes of the processing.

## 6. Distinction from related legal concepts [#6-distinction-from-related-legal-concepts]

Distinguishing between processing on behalf of a controller, joint controllership under Article 26 GDPR, and the transfer to an independent controller is of considerable importance in practice, because different obligations and legal bases follow from it.

The GDPR does not recognize the earlier data protection concept of "function transfer" (Funktionsübertragung). A body that assumes tasks of the controller with its own decision-making authority is therefore to be classified either as an independent controller or, where there is a division of labor, as a joint controller.

The following table summarizes the key differences:

| Criterion                           | Processing on behalf of a controller (Article 28 GDPR)                 | Joint controllership (Article 26 GDPR)    | Transfer to a [third party](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.10-dritter) |
| :---------------------------------- | :--------------------------------------------------------------------- | :---------------------------------------- | :------------------------------------------------------------------------------------ |
| Determination of purposes and means | Solely by the controller                                               | Jointly by both parties                   | Independently by the recipient                                                        |
| Bound by instructions               | Yes, fully                                                             | No, both co-determine                     | No                                                                                    |
| Legal basis for the disclosure      | Data processing agreement under Article 28(3) GDPR                     | Arrangement under Article 26(1) GDPR      | Legal basis under Article 6 GDPR required                                             |
| Recipient's own obligations         | Yes (Article 28(3), Article 30(2) GDPR)                                | Yes, as a controller                      | Yes, as an independent controller                                                     |
| Liability                           | Joint and several with the controller (Article 82(4) GDPR)             | Joint and several, apportioned internally | Independent liability                                                                 |
| Typical practical examples          | Cloud hosting, payroll accounting, debt collection (before assignment) | Jointly operated platform, joint venture  | Disclosure to public authorities, independent service providers                       |

<Callout type="info">
  Payroll accounting by an external service provider or tax advisor constitutes processing on behalf of a controller, as long as that party acts exclusively on the employer's instructions. If the accounting is understood as a division-of-labor collaboration in which the tax advisor has its own discretion in shaping it, joint controllership under Article 26 GDPR may apply. The distinction depends on the actual arrangement of the cooperation.
</Callout>

<Cards>
  <Card title="Controller" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher" description="Article 4(7) GDPR: Who determines the purposes and means of the processing." />

  <Card title="Third party" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.10-dritter" description="Article 4(10) GDPR: Distinction from the independent controller." />

  <Card title="Record of processing activities" href="/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten" description="Article 30(2) GDPR: The processor's documentation obligations." />

  <Card title="Article 28 GDPR" href="https://dsgvo-gesetz.de/art-28-dsgvo/" description="Full text: processor, contract content, sub-processing." />

  <Card title="Article 82 GDPR" href="https://dsgvo-gesetz.de/art-82-dsgvo/" description="Liability and claims for damages in the event of GDPR infringements." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.