Legal and compliance
What is Data processor?
A third party that handles personal data on your behalf under your instructions — your host, your email provider, your analytics tool, your payment gateway. You remain the controller and stay responsible, which is why a written processor agreement is required.
Also called: processor agreement · sub-processor
Who is a processor on a typical small site
- The hosting company storing your database and server logs
- The transactional email service delivering form notifications
- The analytics provider, unless it collects nothing personal
- The payment gateway, which is usually a controller in its own right too
- Any backup or CDN service that stores or caches user data
What the agreement has to cover
That the processor acts only on your instructions, keeps the data secure, restricts onward sub-processors, assists with data subject requests, notifies you of breaches, and deletes or returns data at the end. Most reputable suppliers publish a standard one you accept rather than negotiate.
The list nobody has and everybody needs
Write down every service that touches customer data, what it holds, and where. It takes an hour, it is the basis of an accurate privacy policy, and it is the first thing anyone asks for after an incident.
Where this is covered in depth
A definition can only go so far. Who actually owns your website — a checklist you can verify today covers this properly — 3 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.