SECURE Data Act Processor Requirements — Vendor Contracts & Compliance
What Is a Processor?
A processor is any person or company that processes personal data on behalf of a controller — following the controller’s instructions rather than making its own decisions about the data.
Common examples of processors:
- Cloud hosting providers (AWS, Google Cloud, Azure)
- SaaS platforms that handle customer data on behalf of their clients
- Payroll processors
- Email service providers
- Analytics vendors
- Customer support software companies
The Critical Distinction: Processor vs. Controller
The line between processor and controller matters enormously — controllers face significantly more obligations.
The rule: If a processor starts making its own decisions about the purpose or means of processing data — beyond what the controller instructed — it becomes a controller for that processing activity and takes on full controller obligations.
Example: A cloud provider that stores your customer data as instructed = processor. A cloud provider that decides to analyze that data for its own product improvement = controller for that analysis.
Processor Obligations
1. Follow Controller Instructions
Processors must adhere to controller instructions and assist controllers in meeting their obligations under the Act — including responding to consumer rights requests and maintaining data security.
2. Written Contract Required
Every controller-processor relationship must be governed by a written contract. The contract must clearly cover:
- Instructions for processing personal data
- The nature and purpose of processing
- The types of personal data being processed
- The duration of processing
- The rights and obligations of both parties
3. Minimum Contract Requirements
The contract must require the processor to:
- Confidentiality — ensure everyone handling the data is bound by a duty of confidentiality
- Data return or deletion — at the controller’s direction, delete or return all personal data at the end of the service relationship (unless law requires retention)
- Compliance documentation — make available all information necessary to demonstrate compliance upon the controller’s reasonable request
- Audits — either allow the controller (or their designated assessor) to conduct compliance assessments, OR arrange for an independent qualified assessor to do so and provide the report to the controller
- Subcontractor obligations — pass all processor obligations down to any subcontractors in writing
What Processors Are NOT Responsible For
A processor that faithfully follows a controller’s instructions is not automatically liable for what the controller does with the data. However, this does not eliminate a processor’s own independent obligations under the Act.
Key Takeaways
- Processors follow instructions; controllers make decisions — crossing that line changes your obligations
- Written contracts between controllers and processors are mandatory
- Contracts must cover: confidentiality, data deletion, audit rights, and subcontractor obligations
- Subcontractors inherit processor obligations through the contract chain
Frequently Asked Questions
We are a SaaS company. Are we a controller or a processor? Usually both, depending on the context. For data you process on behalf of your customers (their end-users’ data), you are likely a processor. For your own user data (your customers’ account data), you are a controller. Many companies are simultaneously controllers and processors for different data flows.
Do we need separate contracts with every subprocessor? Yes. The bill requires that any subcontractor you engage must be bound by the same processor obligations through a written subcontract.
What if our existing vendor agreements don’t meet these requirements? They will need to be updated before the law takes effect. Given the 1-2 year lead time, now is the time to begin reviewing and renegotiating vendor contracts.