How to identify a data processor and not miss the data processing agreement?

18 April 2025

GDPR has been with us for several years now – during this time, many companies have not only prepared documentation but have also undergone initial audits and exchanged several letters with the Polish DPA. However, there are areas that can still be surprising – one of them is the management of data processors, commonly referred to as processors.

When do we talk about a data processor?

This refers to any contractor who:

  • performs a task on behalf of our company,
  • processes personal data in the process,
  • acts according to our instructions (does not independently decide on the purpose of processing).

Example:

Does your department instruct a call center agency to contact clients? Or does it use an application operating “in the cloud”? This may indicate collaboration with a data processor – and this, in turn, requires the signing of a data processing agreement.

Who can be a data processor in your environment?

Below you will find a list of categories of companies that most often act as data processors. Consider which ones your department collaborates with – and whether each of these relationships has been properly regulated:

  • External document archiving
  • Security agency
  • HR company / accounting office
  • Cloud service provider / hosting
  • Call center
  • <div class="adbox-bulletin">
        <div class="adbox-bulletin-content">
            <div class="image">
                <img class="img-responsive mobileoff" src="/template/default/images/bazawiedzy-reklama-blog.png" alt="Knowledge Base GDPR">
            </div>
            <div class="text">
                <h4>Free knowledge about GDPR.<br>Use it freely!</h4>
                <div class="desc">Webinars, articles, guides, training, snapshots, and assistance. Welcome to the ODO 24 knowledge base.</div>
                <a class="button" href="/pl/wiedza">I'M IN</a>
            </div>
        </div>
    </div>
    
  • Shared Services Center
  • Recruitment agency
  • Translation office
  • Software and IT systems provider
  • Building manager (acting on behalf of the owner)
  • Consulting firm
  • Debt collection agency
  • Marketing agency
  • Mail service provider and warehousing company
  • Newsletter sending tool provider
  • Electronic signature platform
  • Document and data carrier destruction company
  • User behavior analysis company on the website
  • IT body leasing / service point
  • Companies from the capital group (in selected cases)

What is worth doing?

  • Conduct a quick review of the companies your department collaborates with.
  • Consider whether any of them process personal data on our behalf.
  • Ensure that a data processing agreement has been concluded with each such company (if not – inform the person responsible for GDPR in your organization).
  • Check whether these companies (so-called data processors) have been properly verified before commencing cooperation – and whether they are subject to regular assessments, for example, once a year, regarding compliance with data protection requirements.

A small oversight can have significant consequences – and the Polish DPA does not ask whether "someone from IT was handling it," but whether the agreement is signed.

If you have any doubts – ask. It is better to be cautious with GDPR than to later explain a breach.

 

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.