Under the General Data Protection Regulation (GDPR), processors (i.e. organisations processing personal data on behalf of a third party) is subject to new obligations. Indeed, before the GDPR, processors were only contractually liable to the controller on behalf of which they processed personal