Who It Covers
GDPR applies equally to both data controllers and to data processors. Any organization that gathers personal data from a data subject is considered a data controller. They have to document the purposes for which they are collecting the data, how and why they will use or process the data and with whom they will share it.
Data processors are organizations that process data for a data controller, like a payroll processor or a cloud service provider. For the first time, such organizations are also directly bound by the requirements of the GDPR if any of the data they process belongs to EU residents.
Image Source: Yeexin Richelle via Shutterstock