Skip to Primary Navigation

Are data processors really immune from data protection fines under GDPR?

Data privacy, data protection. Using hand to pay with payment chip. Future money/identity theft
Photo: Getty Images

When do regulators choose to go after data processors instead of data controllers? 

What matters

Fines for data processors, rather than data controllers, have been few and far between. But this is likely to change.

What matters next

Consideration of processor location, contract terms and size will be increasingly important to manage controller risk when procuring data processing services.

Previous European data protection

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience