What Is a Data Processor?
A data processor is a person or company, other than your own staff, that processes personal data for you and only on your instructions. It does the handling; you decide why the data is used at all. That is the whole definition. The difficulty is never the definition; it is the list.
Tuesday morning in a three-chair dental practice in Galway. The practice manager has an email from a new online-booking vendor with a data processing agreement attached and a polite request to "confirm your current processors" for the practice's own records. She opens a spreadsheet, which is optimistic, and starts writing. Practice management software. The booking widget. The SMS reminder service. The card terminal. The lab portal for crowns. The payroll bureau. The accountant. The IT firm that does the backups. Microsoft 365. Nine.
Then the hygienist mentions, helpfully, that she has been using ChatGPT to tidy up recall letters. Ten. And nobody is sure which login.
The one-question test
The Irish Data Protection Commission defines a processor as "the individual (other than an employee of the controller) or the legal person that carries out processing activities, on behalf of and in accordance with the controller's instructions", and a controller as the one that "determines the purposes and means of the processing" (DPC). Strip the legal language and it comes down to one question: who decides why this data is being used? If you decide, you are the controller. If you are doing it because a client told you to, you are the processor.
The European Data Protection Board's Guidelines 07/2020 add a useful refinement: a processor can choose the non-essential means (which servers, which database, which encryption) and still be a processor. It is deciding the purpose, or the essential means such as which data and for how long, that makes you a controller.
| Question | Data controller | Data processor |
|---|---|---|
| Who decides why the data is used? | You | Nobody — it follows your instructions |
| Who decides what data and for how long? | You | You, written into the contract |
| Who picks the servers and the software? | Either | Usually the processor |
| Who answers to the patient or client? | You | You, with the processor's help |
| Who carries the liability if it goes wrong? | You, for all of it | Only for its own failures |
For a dental practice the answer is almost always "controller", because the practice decides why patient records exist and what happens to them. The Dental Council's Code of Practice on Professional Behaviour (March 2022, section 9.8) puts it plainly: dentists "are data controllers, data processers or both". Both is common. An associate treating the practice's patients under the practice's name is usually a processor for the practice; a specialist who sets their own fees and keeps their own notes is usually a controller in their own right.
What are data processors, in a real practice
Here is what the Galway spreadsheet looked like once we had gone through it together. Most Irish practices, clinics and small firms will recognise it.
| Processor | What it holds for you | Written agreement? |
|---|---|---|
| Practice management software | Full clinical records, x-rays, charges | Usually in the vendor's terms |
| Online booking and SMS reminders | Names, mobiles, appointment times | Usually, click-through |
| Dental lab portal | Names, scans, prescriptions | Often nothing in writing |
| Payroll bureau and accountant | Staff PPS numbers, pay, bank details | Sometimes, in the engagement letter |
| IT support with admin access | Everything, in practice | Frequently missing |
| Cloud email and file storage | Whatever anyone has ever emailed | Yes, in the platform terms |
| Card payment provider | Cardholder names and transactions | Yes |
| AI assistant on a business plan | Whatever staff paste into it | Yes, if someone accepted it |
| AI assistant on a personal login | Whatever staff paste into it | No — and it is not your processor at all |
Notice the third column. The problem is rarely a rogue vendor. It is the two or three rows where nobody ever wrote anything down, and the one row at the bottom that does not belong on a processor list because nothing was ever agreed. The DPC's 2025 annual report, published on 30 June 2026, records 6,521 valid breach notifications for the year, and almost half of them were correspondence sent to the wrong recipient. Breaches in Ireland are mostly not hackers. They are data going somewhere it should not have gone, quietly, by someone who was busy.
