The European Union (“EU”) data protection law (the General Data Protection Regulation, or GDPR) makes a distinction between organizations that process personal data for their own purposes (known as “controllers”) and organizations that process personal data on behalf of other organizations (known as “processors”).