Processing on behalf of a controller takes place when a service provider processes personal data for another company and is bound by its instructions.
Typical cases
Typical cases include hosting, sending newsletters and payroll. A data processing agreement under Art. 28 GDPR is required, setting out the obligations and responsibilities of both parties.
Distinction from acting as a controller
The decisive question is who determines the purposes and means of the processing. The processor acts solely on the controller's instructions. If a service provider also uses the data for its own purposes, it becomes a controller itself to that extent.
Independent professional services, such as those of tax advisers, lawyers or auditors, generally do not constitute processing on behalf of a controller.
Obligations of the processor
The processor must implement appropriate technical and organisational measures, engage sub-processors only with authorisation and assist the controller with data subject requests and data breaches. The controller may only use service providers that provide sufficient guarantees.
Legal provisions
- Art. 4(8) GDPR
- Defines the processor.
- Art. 28 GDPR
- Governs the selection of processors, the contract and the obligations involved.
- Art. 29 GDPR
- Processing only on the instructions of the controller.
- Art. 32 GDPR
- Obligation to implement appropriate security measures, including for processors.