01
Who is the controller and who is the processor
The GDPR defines the controller as the natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The processor, on the other hand, is whoever processes personal data on behalf of the controller, following its instructions.
02
Why the distinction matters operationally
When an organisation entrusts processing to an external provider, the relationship must be governed by a contract or other legal act establishing the subject-matter, duration, nature and purpose of the processing, the type of data and categories of data subjects, as well as the rights and obligations of the controller.
03
Steps to formalise the relationship correctly
Steps
- Identify who determines the purposes and means of the processing: that party is the controller.
- Check whether the provider processes data only on the controller's documented instructions.
- Prepare a contract including the elements set out in Article 28: duration, nature, purposes, data and rights.
- If the processor uses a sub-processor, obtain the controller's prior written authorisation.
- Impose on the sub-processor the same data protection obligations set out in the original contract.
04
A hypothetical case
Hypothetical example: a European company (controller) decides to collect customer data for billing and entrusts the processing to a management software provider (processor). The provider processes the data only according to the controller's documented instructions and, if it subcontracts part of the service to another provider, must first obtain the written authorisation of the commissioning company.
05
Elements the contract should contain
- Documented instructions from the controller as the sole basis for processing.
- Confidentiality commitment from persons authorised to process data.
- Adequate security measures under Article 32.
- Conditions for engaging another processor.
- Assistance to the controller regarding data subject rights and deletion or return of data at the end of the service.
06
Organising roles with a software partner
A company can ask its software partner to map who is the controller and who is the processor for each data flow, tracking the documented instructions received and the authorised purposes.
It is possible to set up periodic review processes for the processing agreement, recording the authorisations granted to any sub-processors and the information provided to the controller in case of planned changes.
07
Frequently asked clarifications
- The distinction is based on who decides the purposes and means of the processing, not on the type of activity carried out.
- A processor may use a sub-processor only with the controller's written authorisation, specific or general.
- If the sub-processor fails to meet its obligations, the initial processor remains fully liable to the controller.
08
Next practical step
Before entrusting processing to a provider, verify that the contract contains all the elements required by Article 28 and ask the provider to document how it manages any sub-processors.
FAQ
Frequently asked questions
Who decides whether an organisation is a controller or a processor?
Status depends on who determines the purposes and means of the processing: whoever decides is the controller, whoever acts on behalf of another is the processor.
Can a processor subcontract to another provider?
Only with the controller's prior written authorisation, specific or general, and by imposing on the sub-processor the same contractual data protection obligations.
What should the contract between controller and processor contain?
It must specify the duration, nature and purpose of the processing, the type of data, categories of data subjects, confidentiality obligations, security measures and how assistance is provided to the controller.
✓