A data processor is a person or organization that processes personal data on behalf of a data controller. Their role should be regulated in a so-called Data processing agreement (DPA) signed between the data controller and data processor.

Among other things, the data processor:

  • must have adequate information security measures in place
  • shouldn’t engage sub-processors without the prior consent of the controller
  • must cooperate with the authorities in the event of an enquiry
  • must report data breaches to the controller as soon as they become aware of them, without undue delay
  • may need to appoint a mandatory Data protection officer
  • must give the Data controller the opportunity to carry out audits examining their GDPR compliance
  • must keep records of all processing activities
  • must comply with EU transborder data transfer rules (if necessary)
  • must help the controller to comply with Data subject ’ rights (including the processing of data subject requests)
  • must assist the data controller in managing the consequences of data breaches
  • must delete or return all personal data at the end of the contract as requested by the controller, and
  • must inform the controller if the processing instructions infringe GDPR

More about Data Processor on Piwik PRO blog:


  • 25 years of digital analytics with Brian Clifton: The real challenge for the future is to make sense of data

    Organizations are becoming more and more aware of data-driven strategies, so understanding the complexities surrounding data quality, privacy, and technological advancements becomes crucial for their future success. They also need to rely on new tools, often supported by AI, to adapt to changes in the digital analytics field. Dive into the fourth and final episode…

    Read more

  • Is Google Analytics HIPAA-compliant?

    Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but does not provide legal consultancy. If you’d like to make sure you’re in compliance with HIPAA guidelines, we encourage you to consult an attorney. SUMMARY Healthcare organizations use analytics platforms to collect and analyze data about their patients. The data…

    Read more