Answers
What is a GDPR data processor?
In short
A GDPR data processor is an organisation that processes personal data on behalf of a controller, under documented instructions and a written Data Processing Agreement (DPA).
Short answer
A GDPR data processor is an organisation that processes personal data on behalf of a controller, under documented instructions and a written Data Processing Agreement (DPA).
What this actually means in practice
Processors must implement appropriate technical and organisational measures, notify the controller of breaches without undue delay, and only use sub-processors with the controller's authorisation. Most enterprise contracts require a DPA before any data flows.
The most common pitfall
Acting as a controller and a processor without distinguishing the two.
What to do next
Map your data flows and tag every relationship as controller-processor or controller-controller.
Frequently asked questions
Does Forth Systems help with this?
Yes — Forth Systems works with banks, payment institutions, insurers and infrastructure operators on exactly this kind of work. Engagements start with a fixed-scope assessment so you see the shape before committing.
How experienced is the team?
Engagements are staffed by named, UK-based senior engineers — not a rotating offshore pool. References from the second line of comparable clients are available on request.
Where are you based?
Edinburgh-based, delivering UK-wide with onsite presence in London and across Scotland as required.
How fast can we start?
Most engagements start within 2-4 weeks of a signed SoW, faster where an existing supplier framework is in place.
