GDPR: you are a data processor — personally
When a client hands you personal data — a user database, a production system, an export — you are acting as a data processor (and sometimes a controller) under the GDPR. That status does not require a company: it attaches to “a natural or legal person”. It obliges you to process under a contract, to implement appropriate security measures for the data you hold, and to notify your client without undue delay if it is breached — and it exposes you to compensation claims and administrative fines.
Basis: GDPR Article 4 (definitions), Article 28 (processing under contract), Article 32 (security of processing), Article 33 (breach notification), Articles 82–83 (liability and administrative fines of up to €20 million or 4% of annual worldwide turnover, whichever is higher).