Processing on behalf of a controller

Data protection glossary · 1 minute read

Processing on behalf of a controller takes place when a service provider processes personal data for another company and is bound by its instructions.

Typical cases

Typical cases include hosting, sending newsletters and payroll. A data processing agreement under Art. 28 GDPR is required, setting out the obligations and responsibilities of both parties.

Distinction from acting as a controller

The decisive question is who determines the purposes and means of the processing. The processor acts solely on the controller's instructions. If a service provider also uses the data for its own purposes, it becomes a controller itself to that extent.

Independent professional services, such as those of tax advisers, lawyers or auditors, generally do not constitute processing on behalf of a controller.

Obligations of the processor

The processor must implement appropriate technical and organisational measures, engage sub-processors only with authorisation and assist the controller with data subject requests and data breaches. The controller may only use service providers that provide sufficient guarantees.

Art. 4(8) GDPR
Defines the processor.
Art. 28 GDPR
Governs the selection of processors, the contract and the obligations involved.
Art. 29 GDPR
Processing only on the instructions of the controller.
Art. 32 GDPR
Obligation to implement appropriate security measures, including for processors.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.