When do we talk about a data processor?
This refers to any contractor who:
- performs a task on behalf of our company,
- processes personal data in the process,
- acts according to our instructions (does not independently decide on the purpose of processing).
Example:
Does your department instruct a call center agency to contact clients? Or does it use an application operating “in the cloud”? This may indicate collaboration with a data processor – and this, in turn, requires the signing of a data processing agreement.
Who can be a data processor in your environment?
Below you will find a list of categories of companies that most often act as data processors. Consider which ones your department collaborates with – and whether each of these relationships has been properly regulated:
- External document archiving
- Security agency
- HR company / accounting office
- Cloud service provider / hosting
- Call center
<div class="adbox-bulletin">
<div class="adbox-bulletin-content">
<div class="image">
<img class="img-responsive mobileoff" src="/template/default/images/bazawiedzy-reklama-blog.png" alt="Knowledge Base GDPR">
</div>
<div class="text">
<h4>Free knowledge about GDPR.<br>Use it freely!</h4>
<div class="desc">Webinars, articles, guides, training, snapshots, and assistance. Welcome to the ODO 24 knowledge base.</div>
<a class="button" href="/pl/wiedza">I'M IN</a>
</div>
</div>
</div>
What is worth doing?
- Conduct a quick review of the companies your department collaborates with.
- Consider whether any of them process personal data on our behalf.
- Ensure that a data processing agreement has been concluded with each such company (if not – inform the person responsible for GDPR in your organization).
- Check whether these companies (so-called data processors) have been properly verified before commencing cooperation – and whether they are subject to regular assessments, for example, once a year, regarding compliance with data protection requirements.
A small oversight can have significant consequences – and the Polish DPA does not ask whether "someone from IT was handling it," but whether the agreement is signed.
If you have any doubts – ask. It is better to be cautious with GDPR than to later explain a breach.

