GDPR applicability to processors
The applicability rules of the GDPR now also include processors. The reason for this inclusion is that the GDPR provides for direct obligations of processors (especially security obligations), which should be triggered independently whether or not the GDPR applies to the controller.
Source: GDPR Conundrums: The GDPR applicability regime — Part 2: Processors