A data processor is a natural or legal person who processes personal data on behalf of a data controller, based on the authority the controller grants, as defined in Article 3 of Turkey's KVKK. Hosting providers, email marketing services and cloud analytics tools are typical examples. The concept matches the 'processor' in Article 4(8) of the GDPR; Article 28 requires a written data processing agreement between the parties.
Article 3 of the KVKK defines the data processor as the natural or legal person who processes personal data on behalf of the data controller, based on the authority the controller grants. The distinction is clear: the controller decides the purposes and means of processing, while the processor carries out the technical operation within the controller's instructions, without making those decisions itself. The processor definition in Article 4(8) of the GDPR follows the same logic. The same company can be a controller in one activity and a processor in another; the role depends on the concrete activity, not the title.
For a website, typical processors are the hosting provider, content delivery network, analytics service, email delivery infrastructure and consent management platform. Article 28 of the GDPR requires controllers to work only with processors offering sufficient guarantees and to sign a written data processing agreement covering, at minimum, the subject and duration of processing, instruction-bound processing, confidentiality, security measures, sub-processor approval and audit rights. The practical route: list every vendor that touches personal data, determine each one's role, complete the agreements with those acting as processors and keep the inventory up to date.
Frequently asked questions
What is the difference between a data processor and a data controller?
The data controller is the party that determines the purposes and means of processing personal data; core duties such as registration and informing individuals rest with it. The processor does not make those decisions and carries out the technical operation on the controller's instructions and behalf. The role follows the facts, not the contract title; a vendor that decides purposes itself becomes a controller regardless of its label.
Is a contract with a data processor mandatory?
Under the GDPR, yes: Article 28 explicitly requires a written data processing agreement with defined content between controller and processor. Under the KVKK, controller and processor are jointly responsible for data security measures, and a written agreement is the established way to define the boundaries of that responsibility. For sites subject to both laws, a single comprehensive agreement is the practical solution.
This content is for information only and is not legal advice.