What Is a Data Processor Under GDPR? (And Why Every AI Tool Adds One)

AgentHub.ie logo
Dr. Shadi Ghaith Founder, AgentHub.ie ·

A data processor is any outside organisation that handles personal data on your behalf and only on your instructions — your practice software vendor, your payroll bureau, your cloud email provider. Under GDPR Article 28 you must appoint each one in writing and keep it under review. Every cloud AI tool you switch on adds one more to that list.

Dental practice manager at a desk with patient data flowing out to a ring of outside software providers
Most practices have ten processors before anyone has counted. The counting is the job.

What Is a Data Processor?

A data processor is a person or company, other than your own staff, that processes personal data for you and only on your instructions. It does the handling; you decide why the data is used at all. That is the whole definition. The difficulty is never the definition; it is the list.

Tuesday morning in a three-chair dental practice in Galway. The practice manager has an email from a new online-booking vendor with a data processing agreement attached and a polite request to "confirm your current processors" for the practice's own records. She opens a spreadsheet, which is optimistic, and starts writing. Practice management software. The booking widget. The SMS reminder service. The card terminal. The lab portal for crowns. The payroll bureau. The accountant. The IT firm that does the backups. Microsoft 365. Nine.

Then the hygienist mentions, helpfully, that she has been using ChatGPT to tidy up recall letters. Ten. And nobody is sure which login.

The one-question test

The Irish Data Protection Commission defines a processor as "the individual (other than an employee of the controller) or the legal person that carries out processing activities, on behalf of and in accordance with the controller's instructions", and a controller as the one that "determines the purposes and means of the processing" (DPC). Strip the legal language and it comes down to one question: who decides why this data is being used? If you decide, you are the controller. If you are doing it because a client told you to, you are the processor.

The European Data Protection Board's Guidelines 07/2020 add a useful refinement: a processor can choose the non-essential means (which servers, which database, which encryption) and still be a processor. It is deciding the purpose, or the essential means such as which data and for how long, that makes you a controller.

QuestionData controllerData processor
Who decides why the data is used?YouNobody — it follows your instructions
Who decides what data and for how long?YouYou, written into the contract
Who picks the servers and the software?EitherUsually the processor
Who answers to the patient or client?YouYou, with the processor's help
Who carries the liability if it goes wrong?You, for all of itOnly for its own failures

For a dental practice the answer is almost always "controller", because the practice decides why patient records exist and what happens to them. The Dental Council's Code of Practice on Professional Behaviour (March 2022, section 9.8) puts it plainly: dentists "are data controllers, data processers or both". Both is common. An associate treating the practice's patients under the practice's name is usually a processor for the practice; a specialist who sets their own fees and keeps their own notes is usually a controller in their own right.

What are data processors, in a real practice

Here is what the Galway spreadsheet looked like once we had gone through it together. Most Irish practices, clinics and small firms will recognise it.

ProcessorWhat it holds for youWritten agreement?
Practice management softwareFull clinical records, x-rays, chargesUsually in the vendor's terms
Online booking and SMS remindersNames, mobiles, appointment timesUsually, click-through
Dental lab portalNames, scans, prescriptionsOften nothing in writing
Payroll bureau and accountantStaff PPS numbers, pay, bank detailsSometimes, in the engagement letter
IT support with admin accessEverything, in practiceFrequently missing
Cloud email and file storageWhatever anyone has ever emailedYes, in the platform terms
Card payment providerCardholder names and transactionsYes
AI assistant on a business planWhatever staff paste into itYes, if someone accepted it
AI assistant on a personal loginWhatever staff paste into itNo — and it is not your processor at all

Notice the third column. The problem is rarely a rogue vendor. It is the two or three rows where nobody ever wrote anything down, and the one row at the bottom that does not belong on a processor list because nothing was ever agreed. The DPC's 2025 annual report, published on 30 June 2026, records 6,521 valid breach notifications for the year, and almost half of them were correspondence sent to the wrong recipient. Breaches in Ireland are mostly not hackers. They are data going somewhere it should not have gone, quietly, by someone who was busy.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Why Every AI Tool Adds a Data Processor

Every cloud AI service that receives patient or client data from you is, at best, a new data processor: one more organisation to assess, contract with under Article 28, and keep under review, along with everyone it subcontracts to. At worst, on a consumer plan, it is not your processor at all, and the data has simply been disclosed. Either way the list gets longer, and the list is your legal exposure.

What Article 28 makes you put in writing

Article 28 GDPR says you may use "only processors providing sufficient guarantees", and that the relationship "shall be governed by a contract". Article 28(3) then lists what that contract must contain. The DPC's practical guide to controller-processor contracts is the Irish reading of it. In plain English:

Article 28(3)The processor must…What it means for an AI tool
(a)Act only on your documented instructionsNo training on your inputs unless you said so
(b)Bind its staff to confidentialityWho at the vendor can read your prompts, and why
(c)Secure the data (Article 32)Encryption, access controls, tested
(d)Use sub-processors only with your authorisationThe cloud and support firms behind the AI vendor
(e)Help you answer access and erasure requestsCan a patient's prompt history actually be found and deleted?
(f)Help with security, breach notification and DPIAsWill they tell you within hours if their systems leak?
(g)Delete or return the data at the endWhat happens to retained conversations when you cancel
(h)Let you audit and prove complianceLogs you can see, not a promise you have to take
Diagram of a business as controller with one AI vendor as processor and a chain of sub-processors branching behind it
You appoint one processor. Behind it sits a chain you have authorised in general terms and will hear about by blog post.

The chain behind the vendor

Item (d) is the one people underestimate. An AI vendor does not run alone. OpenAI's published sub-processor list runs to 24 entries as of 15 September 2026, according to Registora, which monitors it daily — Microsoft, Oracle, Google Cloud, CoreWeave and Amazon among the infrastructure providers, plus support and moderation contractors, across roughly two dozen countries. Under a standard data processing addendum you give general authorisation to the whole list and get a 30-day window to object to additions. A practice with no data protection officer will never object, because it will never read the notice. That is what "general authorisation" means in practice.

When the AI vendor is not your processor at all

This is the part that separates a business plan from a personal login, and it matters more than any setting. Under OpenAI's own data-use policy, content from ChatGPT Free, Plus and Pro accounts may be used to train models by default, and no data processing addendum is offered on those tiers. OpenAI is a controller in its own right for that processing. On Team, Enterprise and the API, training is off by default and a DPA is signed, which makes OpenAI your processor.

How the AI is usedOpenAI's GDPR roleIs it on your processor list?What actually happened to the data
Staff member's personal Free or Plus loginControllerNoDisclosed to a third party you never appointed
Practice's Team or Enterprise workspace, DPA acceptedProcessorYesProcessed on your instructions, retained per contract
Software you bought that calls the API behind the scenesSub-processorIndirectly, via that software's DPAProcessed two contracts away from you
Model running on a machine in your buildingNoneNo AI processor to listNever left your systems

The reason the first row matters is that it is the common one. LayerX's Enterprise AI and SaaS Data Security Report (October 2025), built on browser telemetry rather than a survey, found that 77% of employees paste data into generative AI tools and that 82% of those pastes come from unmanaged personal accounts. Buy the business tier for everyone and most of the traffic still goes out the side door. I wrote about what each ChatGPT tier does with your files in Is ChatGPT safe for confidential information?; this post is about what it does to your paperwork.

The DPC's guidance on AI and large language models (18 July 2024) tells organisations to "first understand what personal data it uses, how it uses it, where the personal data goes in situations where a third-party is involved in the processing, whether it is retained by the provider of the AI product or re-used in any way". That sentence is a processor assessment. You cannot write it for a tool nobody told you was in use.

Who carries it when it goes wrong

Article 82 settles the liability question in a way that should focus the mind. A controller "shall be liable for the damage caused by processing which infringes this Regulation". A processor is liable "only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller". The vendor answers for its own mistakes; you answer for the whole arrangement, including the choice of vendor. And under Article 28(10), a processor that starts deciding purposes for itself becomes a controller for that processing, which is exactly the shift that happens when a consumer AI tool trains on what you typed.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

How Local AI Takes the AI Step Off Your Processor List

Local AI is a dedicated machine installed at your premises, running open-weight models, with private chat, document search and custom assistants on it. Because the model runs in your building, there is no AI vendor receiving your data: no processor to appoint for the AI step, no sub-processor chain to keep an eye on, and no international transfer to justify. The list gets shorter instead of longer.

We launched it this month, so I will not invent a year of client results. We have been running the same models on our own documents while building the service, and that is the experience the rest of this section comes from.

What it looks like in a dental practice

Take the Galway list. The clinical system, the lab portal, payroll, email — those stay. A practice cannot run without them, and each has a written agreement to tidy up. What changes is row ten. The recall letters, the treatment-plan summaries a patient can actually read, the referral letter drafted from the clinical notes, the insurer's query answered from the file: all of that runs on a box in the back office, on the practice's own Microsoft or Google sign-in, and none of it leaves.

  • Private chat for drafting and questions, with documents and images uploaded to the machine and nowhere else.
  • Document spaces — policies, protocols, supplier contracts and templates organised so the team can search and summarise across them, with citations back to the page.
  • Custom assistants built around the jobs that repeat: the recall batch, the standard referral, the month-end report.
  • Your existing accounts — single sign-on with Microsoft 365 or Google Workspace, so access control is the one you already run.
Dedicated AI machine inside a dental practice with patient files circulating in the building and the cloud kept outside
The records stay where the Dental Council expects them. The model comes to the records, not the other way round.

What it does to the paperwork, precisely

No product makes a practice GDPR-compliant, and I would be wary of anyone who says theirs does. What running the model locally removes is specific and checkable:

  • One fewer processor to assess. The eight Article 28(3) items above do not need answering for the AI step, because there is no AI processor.
  • No sub-processor chain. Nothing to authorise in general terms and forget about.
  • No Chapter V transfer. Standard contractual clauses and transfer risk assessments do not arise, because nothing crosses a border.
  • Retention you control. The Dental Council's Code (section 9.1) requires adult records to be kept "for at least eight years after the patient was last seen" and then securely destroyed. When the AI's copies are on your own disk, that schedule is the only one that applies.

To be exact about our own role: you remain the controller. AgentHub acts as a processor only for the support access you choose to grant us, and we sign a data processing agreement scoped to exactly that. It is one line on the list, narrow and in writing, which is how every line should look. Bring your DPO or your adviser to the first call; those are the questions we would rather have early.

And where the cloud is the right answer, we say so. If the job is answering the phone when the desk is busy, our cloud AI Receptionist is faster to set up and costs less, and it comes with a processor agreement because that is what it is. Our privacy policy explains how we handle data on that side. Local AI earns its keep on the document-heavy, patient-identifiable work that should never have gone into a chatbot in the first place.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Data Processors: Frequently Asked Questions

What is a data processor under GDPR?

A data processor is a person or company, other than your own employee, that processes personal data on your behalf and only on your instructions. Your practice software vendor, payroll bureau and cloud email provider are all processors. You, the business deciding why the data is used, are the controller.

What is the difference between a data controller and a data processor?

The controller decides the purposes and means of processing: why the data is collected and, broadly, how. The processor carries out that processing on the controller's documented instructions and cannot use the data for its own purposes. If a processor starts deciding purposes itself, GDPR treats it as a controller for that processing.

Who is a data processor? Can you give examples?

Typical processors for an Irish small business: practice or case management software, online booking and reminder services, payroll bureaus, external accountants doing bookkeeping, IT support firms with access to your systems, cloud email and file storage, card payment providers, and any AI tool you feed client or patient data into on a business plan.

Is ChatGPT a data processor?

Only on the business tiers. On ChatGPT Team, Enterprise and the API, OpenAI signs a data processing addendum and acts as your processor. On the free and Plus tiers there is no such agreement, inputs may be used for training by default, and OpenAI acts as a controller in its own right. Personal-account use is therefore an unappointed disclosure, not processing on your behalf.

Do I need a written contract with every data processor?

Yes. Article 28(3) GDPR requires a contract or other legal act with every processor, covering the subject matter, duration, nature and purpose of the processing, the types of data and categories of people, and eight specific processor obligations. Most established vendors publish a standard data processing agreement you can accept online.

Is a dental practice a data controller or a data processor?

Usually a controller, because the practice decides why patient records are kept and how they are used. The Dental Council's Code of Practice notes dentists can be controllers, processors or both. An associate dentist working for the practice's patients is typically a processor; a specialist who sets their own fees and keeps their own records is often a controller too.

Does running AI on my own premises mean I have no data processors?

No. Your practice software, payroll and email providers stay on the list. What changes is the AI step: when the model runs on a machine in your building, there is no third-party AI processor to appoint, no sub-processor chain to review and no international transfer to justify for that processing. The supplier is a processor only for any support access you grant.

What to do this week

Write the list. Not a policy, not a project — a list, with three columns: who, what they hold, and whether anything is in writing. Ask the team what AI tools they use and on which login, without a disciplinary tone, because the answer is the baseline and not the offence. Then fix the empty rows in order of what they hold, which usually puts the IT firm and the lab portal ahead of anything glamorous.

Back in Galway, the spreadsheet now has nine rows, each with a document behind it. The tenth row is gone, not because the hygienist stopped tidying recall letters but because the machine doing it is in the room behind reception, and nothing it reads goes anywhere else. The letters are, if anything, slightly better. Nobody has had to have a conversation about a login.

If you would like a second pair of eyes on your own list, book a Local AI consultation — I read every enquiry myself — or open the chat on this page and ask it what it does with what you type. It is a cloud agent, and it will tell you.