01

The difference in short

The controller is whoever determines the purposes and means of personal data processing; the processor is whoever processes data on behalf of the controller, according to the controller's instructions.

This distinction, defined by Article 4 of the GDPR, determines who bears which obligations toward data subjects and toward supervisory authorities.

02

Why the distinction matters

The assigned role is not a matter of labelling: it depends on who actually decides why and how data is processed. An organisation that receives data and processes it following someone else's instructions is a processor, not a controller, regardless of how it is described in the contract.

03

How to determine the role, step by step

Steps

  1. Ask who decides the purposes of the processing: that party is, alone or jointly with others, the controller.
  2. Check who decides the technical and organisational means of the processing: this too points to the controller.
  3. If an organisation processes data only on behalf of another and on its instructions, that organisation is the processor.
  4. Formalise the relationship with a contract or other legal act specifying subject matter, duration, nature, purpose, type of data and categories of data subjects.
  5. Verify that the contract contains the specific obligations required for the processor, not just a general reference to the GDPR.

04

Hypothetical example

A management software company processes the customer data of a manufacturing company according to the latter's documented instructions: in this hypothetical scenario, the manufacturing company is the controller and the software provider is the processor. If the provider engaged another provider for hosting, it would need the controller's written authorisation and would have to impose on the hosting provider the same data protection obligations set out in the original contract.

05

Elements the contract with the processor must contain

  • A documented instruction from the controller as the sole basis for processing by the processor.
  • A confidentiality commitment from persons authorised to process the data.
  • Technical and organisational measures adequate under Article 32.
  • Conditions for engaging a sub-processor, including the same data protection guarantees.
  • Assistance to the controller in responding to data subject requests and in meeting the obligations under Articles 32-36.
  • Deletion or return of data at the end of the service, unless retention is required by law.
  • Making available the information necessary to demonstrate compliance and allowing audits.

06

How to organise roles and evidence with a software partner

An organisation can choose to set up, together with its software partner, a clear register of who is controller and who is processor for each processing activity, with linked contracts and revise dates. This is a recommended operational choice, not an obligation arising from any specific software feature.

It may also be worth defining who in the company approves the use of sub-processors and who periodically checks that contracts contain the required obligations, keeping track of the documented instructions given to processors.

07

In practice, in three moves

Steps

  1. Map who decides the purposes and means for each personal data processing activity in the company.
  2. Draft or review the contract with each processor, including all required obligations.
  3. Periodically review sub-processor chains and the authorisations granted.

08

Next step

Review your existing processing agreements and compare each clause against the obligations listed in this checklist before your next contract review.

FAQ

Frequently asked questions

Can a company be both controller and processor?

Yes, depending on the specific processing activity: for one processing activity it may determine the purposes and means (controller), for another it may process data on the instructions of a third party (processor). The role must be assessed activity by activity.

Can a processor use another provider without notifying the controller?

No: the processor may engage another processor only with the controller's prior written authorisation, specific or general, and in the case of general authorisation it must inform the controller of intended changes.

What must the processor do if an instruction from the controller is unlawful?

The processor must immediately inform the controller if, in its opinion, an instruction infringes the GDPR or other national or Union data protection provisions.

Sources and verification