Vendor as Processor
In data protection law, a vendor acts as a processor when it handles personal data on behalf of another organization (the controller) and follows that organization's instructions rather than deciding for itself how and why the data is used. Not every vendor is a processor; a vendor that provides goods or services does not automatically process personal data on your behalf, and the classification generally depends on what the vendor actually does with the data and on having an appropriate contract in place. Getting this classification right matters because it determines which contractual and compliance obligations apply.
A vendor is classified as a processor when it processes personal data on behalf of a controller and acts within that controller's documented instructions, as distinguished from a controller, which determines the purposes and means of processing. Under the GDPR framework, this classification is fact-driven: it turns on the vendor's actual role in relation to the data rather than on its label, and it generally requires a contract meeting the applicable regulatory requirements (for example, a data processing agreement under the GDPR, or a service provider contract meeting statutory terms under certain US state privacy laws such as the CCPA/CPRA). Where a vendor engages further parties to handle data on its behalf, those parties are typically treated as sub-processors, a separate but related role. This entry addresses role classification only and does not resolve the specific factual analysis of any given vendor arrangement, which depends on the processing activities, contractual terms, and applicable jurisdiction; classifications and terminology (for example 'processor' versus 'service provider') differ between the EU/UK and individual US state regimes.
Why it matters
Classifying a vendor correctly as a processor rather than a controller (or, under US state regimes, as a service provider rather than a third party) determines which contractual and compliance obligations apply to a data relationship. A vendor that merely provides goods or services does not automatically process personal data on your behalf; the classification generally turns on what the vendor actually does with the data and on whether an appropriate contract is in place. Getting this wrong can leave an organization without the documented instructions, data processing agreements, or statutory contract terms that regulators expect, and it can mislead the allocation of responsibility between the parties.
The classification is fact-driven rather than label-driven. A vendor described in a contract as a 'processor' may in practice determine the purposes and means of processing, which would make it a controller instead, changing the obligations that apply to both parties. Because a vendor can generally only be treated as a processor or service provider if it has a contract meeting the applicable regulatory requirements, an arrangement lacking such terms may not qualify at all, regardless of how the parties intended to characterize it.
Terminology and requirements differ across jurisdictions, which compounds the stakes. The EU and UK GDPR framework uses 'controller' and 'processor,' while certain US state privacy laws such as the CCPA/CPRA use terms like 'service provider' with their own statutory contract requirements. An organization operating across regimes may need to satisfy several sets of criteria for the same vendor, and the analysis of any given arrangement depends on the specific processing activities, contractual terms, and applicable law.
Who it's relevant to
Inside Vendor as Processor
Common questions
Answers to the questions practitioners most commonly ask about Vendor as Processor.

