Privacy
Data processor
Also called processor.
Data processor is the party that processes personal data on a controller's behalf and on its instructions. It does not decide the purposes.
How it is measured
A processor holds data to deliver a service: hosting, email sending, analytics collection. Its duties include security, using subprocessors only with approval, and helping the controller answer requests.
Test the role by asking whether the vendor uses the data for its own aims. If yes for any purpose, it is acting as a controller for that use.
Worked example
A small shop uses a hosted checkout. The vendor stores orders and card tokens so the shop can fulfill them, acting as a processor. The vendor also builds a fraud model from every customer's orders for its own benefit, which makes it a controller for that part.
The shop updates its notice to explain the split.
How it differs
A data processor works on instructions. A data controller sets the purposes. The processor excludes decision power over why; the controller excludes performing the handling itself.
Common errors
Assuming a vendor is a processor because the contract says so. Missing the vendor's own use of data. Having no list of subprocessors. Giving broad instructions. Ignoring return or deletion at exit.
In practice
Ask each vendor if it uses your data for itself. Record the answer. Update the notice if it does.