A party that processes personal data on behalf of a controller, bound by the controller's instructions and a contract.
A data processor handles personal data only on documented instructions from the controller, typically a vendor or service provider such as a cloud host. It does not decide the purposes of processing.
The relationship must be governed by a Data Processing Agreement that sets out the scope, security obligations, and use of any sub-processors. Processors carry their own direct obligations under the GDPR.
Related frameworks