Knowledge · 15 September 2026
Why an IT service provider is a processor
An external technician connects to your server, opens the database and fixes a bug. It takes ten minutes and nobody treats it as processing of personal data. Under the GDPR it is — and out of it comes a contract with eight mandatory elements.
An external IT technician connects to your server, opens the database and fixes an error in an order. It takes ten minutes and nobody treats it as processing of personal data.
Under the GDPR it is — and out of those ten minutes comes a contract that must contain eight mandatory elements.
Where exactly the line runs
The widespread shorthand is "anyone who can get to the data is a processor". That is almost true, and it is the "almost" that causes trouble in practice.
What decides is Article 4(2) GDPR, which defines processing as "any operation or set of operations which is performed on personal data" — and among the operations listed are consultation and storage. It therefore does not matter whether the data are changed. It is enough that someone looks at them in the course of providing the service.
So the test is not "could they get to the data", but: are operations on personal data performed as part of that service?
In IT services they practically always are:
- fixing a bug directly in the database — consultation and alteration,
- remote administration and maintenance — access to a system that holds the data,
- backups — storage,
- data migration — transmission and structuring,
- diagnostics — consultation of logs and records,
- updates carried out on production data.
The difference from an example where no processor arises lies in whether operations are actually performed: a cleaning company that walks past cabinets full of files is not a processor. A technician who logs into the system is one from the first login.
Why not a "third party"
Contracts often refer to a third party, because it sounds less binding. A third party, however, is someone who has no role in the processing and does not get to the data.
Whoever processes on behalf of the controller and on the controller's instructions is a processor — regardless of what the contract calls them. A label in a contract does not change the role; the role is determined by what actually happens.
What follows from it
A processing contract under Article 28 GDPR. Not an annex on confidentiality, not a sentence in a purchase order. It must set out, in particular, the subject matter and duration of the processing, its nature and purpose, the type of personal data and categories of data subjects, the obligations and rights of the controller, security measures, the rules for engaging sub-processors, assistance with data subject rights and with incidents, and what happens to the data once the service ends.
And something overlooked more often than the contract itself: the controller is to assess whether the processor provides sufficient guarantees. Signing a contract is not an assessment. An assessment is a documented answer to the question why you believe that supplier will protect the data — and that is what an inspection asks about, not the contract.
And what if your supplier uses another supplier
That is the question everyone asks once they have understood the first part. Your IT partner runs on someone else's cloud, sends backups elsewhere and uses a third company's tool for support.
EDPB Opinion 22/2024 of 7 October 2024 says three things about this that are worth remembering:
Sufficient guarantees are assessed along the whole chain, not only at the first link. The depth of the assessment follows the risk — more is expected where the processing is more sensitive.
You do not have to read every contract with every sub-processor. Whether obtaining a copy is necessary is judged case by case, and you may rely on information from the first processor.
But the decision is yours. The first processor remains fully liable to you for its sub-processors — and even so, the final say on who joins the chain belongs to the controller. A contract that lets the supplier add another processor without your knowledge takes away a decision that is meant to be yours.
What to do about it in practice
Five measures for external IT specialists that can be introduced without a project:
1. Access limited to what is necessary. A technician who is to fix invoicing does not need to see the HR records. A separate account, not a shared administrator login.
2. Two-factor authentication for every remote access. With no exception for "I will only take a quick look".
3. Access approved in advance. Not after the work and not tacitly. Name, reason, time.
4. A record of access. Who, when, to what. Without it you have no way of finding out what happened — not even when nothing did.
5. A report on the work performed. Short, but written. It is also the only document that shows an inspector that the access had a reason.
The most common mistake
The supplier's model contract, signed without anyone reading it. It tends to be written to protect the supplier — it allows sub-processors to be engaged without notice, sets no deadline for reporting an incident, and deals with what happens to the data after termination in a sentence about "standard procedures".
A contract under Article 28 is not a formality to tick off. It is a document that gets read on the day something happens — and by then it is too late to find out what is not in it.
Where our work ends
- We do not assess the quality of your supplier's IT services — we assess whether the processing is covered and documented.
- We do not represent you in commercial negotiations with the supplier. We prepare the basis and say what is missing from it.
- We do not run IT or provide remote administration, so we have no reason to recommend one supplier over another.
Verified on 15 September 2026 against Regulation (EU) 2016/679, EDPB Guidelines 07/2020 in their final version and EDPB Opinion 22/2024.
Legal position verified as of 15 September 2026. With legal content, an outdated article is worse than none — if you find a discrepancy, write to us at info@iosec.eu.
Sources
Tell us what you are dealing with.
Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.