Governance

Data processor

Entity that processes personal data on behalf of a controller.

Definitions (13)

An entity that processes personal data on behalf of a data controller according to the controller's instructions, and which must adhere to contractual and regulatory obligations, cooperate with the ECA, and implement appropriate technical and organizational measures.

Third-party vendors, cloud providers or other service providers that process data on behalf of the controller under contract; processors must follow contractual requirements and technical measures (e.g., secure transfer, encryption) set out by the controller and the guide.

A natural or legal person who processes personal data on behalf of and under the instructions of a data controller, carrying out operations such as collection, storage, retrieval, use, disclosure, or deletion, and who must implement appropriate technical and organizational measures as required by the controller and law.

A person who processes personal data on behalf of a data controller, acting under the controller's instructions and subject to contractual and statutory duties set out in the PDPA and subordinate rules, including implementing appropriate security measures and assisting the controller in fulfilling obligations.

An entity that collects and processes data during operations inside China and that is responsible for classifying data, performing required self-assessments, submitting applications to authorities where necessary, implementing technical and contractual safeguards, and cooperating with regulator inspections under the Measures.

A role referenced by the Strategy and aligned with the Data Protection Act: an individual or organisation that processes personal data on behalf of a data controller, subject to contractual and regulatory obligations to implement security, privacy‑by‑design, and other governance measures.

A natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller, following the controller's instructions. Processors must apply appropriate security measures and may be subject to contractual obligations and supervisory oversight under the law.

A person or organization who processes personal data on behalf of the data user/controller but does not determine the purposes or means of processing. Processors are bound by contractual and statutory obligations to follow the controller's instructions and implement appropriate technical and organisational measures.

An entity that processes personal data on behalf of a data controller, acting under the controller's instructions and subject to obligations to implement appropriate security and processing safeguards.

An entity that processes personal data on behalf of a data controller, acting under the controller's instructions and subject to contractual and regulatory duties to implement appropriate technical and organisational measures for data protection, documentation, and security in AI deployments.

A person or entity that processes personal data on behalf of a data controller under instruction, required to implement technical and organizational security measures and assist controllers in meeting compliance obligations under the Bill.

An entity that processes personal data on behalf of a data controller (e.g., cloud or ML service provider) and must act only on controller instructions and under contractual safeguards aligned with KVKK requirements.

A natural or legal person, public or private, who by itself or in association with others performs processing of personal data on behalf of the Data Controller, for example an integrator or technology vendor contracted to run the facial recognition system.