Definition. Under GDPR Article 4: a controller is the entity that determines the purposes and means of processing personal data; a processor is the entity that processes data on behalf of the controller following its instructions. The controller decides “why” and “how” — the processor executes. The controller bears primary accountability under Article 5(2). The processor has direct obligations under Article 28 and is co-liable for breaches of its specific duties.
The controller-processor distinction is the most consequential classification under the GDPR. Controllers sign privacy notices, conduct DPIAs, manage data subject requests, and bear primary fines. Processors sign DPAs, follow controller instructions, and face fines for breaching processor-specific duties. Misclassifying a relationship — labeling a controller as a processor or vice versa — invalidates the legal architecture of the processing.
This guide explains the legal definitions, the decision criteria from the EDPB and CJEU, and the practical implications for contracts and liability. For processor contract obligations, see our controller and processor contract. For data processor specifics, what is a data processor. For the controller side, what is a data controller under GDPR.
Key takeaways
- Controller: determines purposes and means of processing — bears primary accountability.
- Processor: processes on behalf of controller, on documented instructions — bears direct obligations under Article 28.
- The qualification is determined by factual reality, not contract labels (CJEU Wirtschaftsakademie, Fashion ID).
- Core questions: who determines the purpose and essential means, and does the recipient act on behalf of another party? A separate commercial benefit is contextual evidence, not a standalone legal test.
- A joint controller scenario (Article 26) exists when two parties jointly determine purposes and means . Article 26 governs that arrangement.
1. Legal definitions (Article 4)
Controller (Article 4(7)): “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data”.
Processor (Article 4(8)): “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”.
The two definitions are mutually exclusive for a given processing activity: a party is either acting as controller (determining purposes and means) or as processor (acting on instructions). The same legal entity can be controller for some processing and processor for other processing — but never both for the same operation.
2. The decision criteria
EDPB Guidelines 07/2020 set out the criteria. Three questions:
2.1 Who determines the purpose?
The “purpose” is the why of the processing. If party B uses the data for its own purpose (analytics, marketing, profiling), B is a controller — not a processor. If B only uses the data to perform the contract for A, with no autonomous use, B is a processor.
Hypothetical examples:
- A provider storing files solely on customer instructions may be processor for that operation.
- A supplier using personal data for its independently determined benchmarking purpose requires a controller assessment; joint status needs evidence of joint determination.
- An email delivery service may be processor for instructed sending while having distinct controller purposes for its own administration.
2.2 Who determines the essential means?
The “essential means” are the substantial decisions about how processing happens: categories of data and people, duration and recipients. Non-essential means (implementation details such as suitable software and practical security measures, depending on context) can be left to the processor without changing its qualification.
2.3 Is there an independent or jointly determined purpose?
A supplier can have its own purpose for a particular operation. That requires a controller analysis, but does not automatically establish joint controllership. Joint determination of purposes and means must be assessed. Payment for the service does not itself turn a processor into a controller.
3. Hypothetical scenarios to test the distinction
| Operation | Question to resolve | Possible conclusion on the stated facts |
|---|---|---|
| Storage of customer files on instructions | Does the provider use the contents for its own purpose? | Processor for instructed storage |
| Supplier’s own invoice records | Who determines billing and legal retention? | Supplier is controller for its own administration |
| A jointly designed campaign | Do both parties determine the shared collection and use? | Joint controllers for the jointly determined stage |
| Lawyer advising a client | Does the lawyer exercise an independent professional mandate? | Controller assessment for that professional activity |
| Customer data used to train a supplier’s model | Who determines the training purpose and essential means? | Separate controller analysis; not automatically joint |
| A processor choosing encryption technology | Has the controller retained decisions on purpose and essential means? | Practical security discretion can remain compatible with processor status |
These examples concern particular operations, not permanent labels for named vendors. Inspect the service terms and actual conduct before deciding. Genuine anonymised outputs also require care: producing them from personal data remains processing that needs a role analysis.
Controller obligations
These flow from the general responsibility clause of GDPR Article 24:
- Maintain ROPA (Article 30(1))
- Conduct DPIA where required (Article 35) — see Article 35 RGPD
- Implement appropriate technical and organizational measures (Article 32)
- Notify the authority without undue delay and, where feasible, within 72 hours of awareness unless unlikely to result in risk (Article 33)
- Communicate breaches to data subjects when high risk (Article 34)
- Honor data subject rights (Articles 12-23)
- Determine lawful basis (Article 6) — see legitimate interest
- Sign DPAs with all processors (Article 28)
Processor obligations
- Process only on documented instructions (Article 28(3)(a))
- Confidentiality of staff (Article 28(3)(b))
- Implement security measures (Article 28(3)©)
- Engage sub-processors only with controller authorization (Article 28(3)(d))
- Assist controller with data subject requests (Article 28(3)(e))
- Assist controller with breach notification, DPIA, prior consultation (Article 28(3)(f))
- Return or delete data at end of contract (Article 28(3)(g))
- Provide audit information (Article 28(3)(h))
- Maintain ROPA (Article 30(2))
- Notify controller of breaches (Article 33(2))
Joint controller obligations (Article 26)
- Sign joint controllership agreement determining respective responsibilities
- Make essence of the agreement available to data subjects
- Data subjects can exercise rights against either controller
5. Liability follows the applicable duties and facts
Article 82 distinguishes controller responsibility from processor responsibility for processor-specific duties or action outside or contrary to lawful instructions. Multiple parties involved in damage can face liability under its conditions. Contractual allocation does not remove a person’s statutory rights or an authority’s powers.
Article 28(10) treats a processor as controller for processing where it determines purposes and means in breach of the Regulation. Not every operational mistake automatically changes the role. Record what decision was taken, by whom and for which processing.
6. Common classification errors
An absent Article 28 contract is a compliance gap; it does not by itself make an instructed service provider an independent controller. Equally, signing a DPA cannot turn autonomous processing into processing solely on behalf of the customer.
Do not infer joint controllership from a shared benefit alone. Establish whether the parties jointly determine the relevant purpose and means, and identify the stages covered. A party may be joint controller for collection and transmission without controlling a recipient’s later independent use.
Sub-processing requires prior specific or general written authorisation. Under general authorisation, the processor must inform the controller of intended changes and allow an opportunity to object. The original processor remains responsible to the controller for the sub-processor’s obligations under Article 28(4).
For secondary use, identify the purpose, role, legal basis and information duties before proceeding. Consent is not a universal way to cure a role error. The factual processing and the contract must be brought into alignment.
7. The joint controller case (Article 26)
When two parties jointly determine purposes and means, neither is a pure processor. Article 26 requires a joint controllership agreement allocating respective responsibilities and making the essence of the agreement available to data subjects.
For a jointly designed marketing operation, identify whether both parties determine the purposes and essential means of collection and use. Record the particular stages covered by the arrangement. Neither a joint commercial benefit nor the use of a named platform establishes the answer on its own.
For the distinct processor contract requirements, see our controller and processor contract guide.
8. Record a decision for each operation
Create a row with the operation, purpose, data categories, decision maker for essential means, recipient instructions, independent uses and supporting contract. Mark uncertainties and ask the supplier specific questions. Request an example of how an instruction is implemented rather than relying on a standard contractual label.
A hypothetical hosting review may conclude that the provider is processor for stored files and controller for its own billing contacts. The resulting file separates those purposes and identifies the applicable notices and agreements. If the provider proposes a new training use of file contents, reopen the assessment instead of extending the earlier hosting conclusion.
Before approval, confirm that the person who signs the decision has reviewed both the contract and the operational evidence. Retain a review trigger for changed data uses, new recipients or material service changes.
Supporting documents
For related context: Article 28 RGPD complete guide, DPA template, vendor audit checklist, data privacy compliance guide.
Official sources: the EDPB Guidelines 07/2020 on the concepts of controller and processor, the ICO guidance on controllers and processors, and Articles 4, 24 and 28 of Regulation (EU) 2016/679 on EUR-Lex.
Conclusion
The controller-processor distinction is not about company size, contract value, or relationship duration — it’s about whether the recipient has its own purpose and determines essential means. Misclassification costs: the wrong contract structure, the wrong liability allocation, and exposure to DPA reclassification with retroactive sanctions. Apply the three-question test rigorously, especially for analytics, marketing platforms, and payment partners.
What’s the simplest test for controller vs processor?
Ask who determines the purpose and essential means of the specific processing, and whether the recipient acts on another party’s behalf. A contractual label, profit motive or generic vendor category is not decisive. Use the EDPB criteria and record the facts supporting the answer.
Can a single entity be both controller and processor?
For different processing activities, yes — common with companies that handle their own employee data (controller) and provide services to customers (processor). For the same processing activity, no — the qualifications are mutually exclusive.
What happens if a processor exceeds the controller’s instructions?
Article 28(10) applies where a processor determines purposes and means in breach of the Regulation. It is then considered controller for that processing. Liability for other failures still requires analysis under the relevant provisions.
Are cloud providers always processors?
A provider may act as processor for instructed storage and have separate controller purposes for other operations. Check the actual service and data use. Offering analytics or model training does not establish joint controllership without examining joint determination.
Do I need a DPA with a joint controller?
You need a joint controllership agreement under Article 26, which allocates respective responsibilities. This is different from a DPA (which is for processors). The two are not interchangeable. Some relationships require both — DPA for processor services, joint controllership agreement for joint operations.