A data processor simply processes any data that the data controller gives them.
Gdpr controller vs processor.
Following the example above the data processor is the third party company that the data controller chose to use and process the data.
Gdpr data controllers and data processors since gdpr was launched in may 2018 controllers have specific obligations.
In addition processors have legal obligations of their own.
The third party data processor does not own the data that they process nor do they control it.
This is a major difference between the original dpd legislation in 1995.
Obligations of a controller vs a processor as the controller is the key decision maker with regards to personal data most of the responsibilities for compliance with the gdpr fall on the controller s shoulders.
Data processor 11 february 2020 both data controllers and data processors have new obligations under the gdpr but their responsibilities vary.
Processor according to article 4 of the eu gdpr different roles are identified as indicated below.
As a data controller one must ensure that the data processor s remain aware of their gdpr obligations.
Generally data controllers have more accountability and liability but processors will have new responsibilities and new added layers of liability written into their roles.