That’s because the EU General Data Protection Regulation (“GDPR”) effective May 25, 2018, distinguishes a “controller,” (the party primarily responsible for protecting “personal data”) from a “processor” (which is essentially a subcontractor that has secondary, but important responsibilities to protect “personal data”).