01
The distinction in two definitions
GDPR defines the data controller as the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The data processor, on the other hand, is the one who processes personal data on behalf of the controller, without independently deciding purposes and means.
02
Why the distinction matters operationally
Whoever decides why and how data is processed is the controller; whoever carries out processing activities on someone else's instructions is the processor. This difference determines who signs the processing agreement, who is accountable for the instructions, and who must demonstrate the safeguards adopted when relying on external providers or additional processors.
03
How to map roles and formalize them
Steps
- Identify who decides the purposes and means of processing: that entity is the controller.
- Check whether a provider processes data only on behalf of the controller: in that case it is the processor.
- Draft a contract stipulating the subject matter, duration, nature, purpose, type of data and categories of data subjects.
- Include in the contract the obligations set out in Art. 28.3: documented instructions, confidentiality, security measures, assistance with data subject rights.
- If the processor engages another processor, obtain the controller's prior written authorization first.
04
A hypothetical case
Hypothetical example: a company that decides to collect customer data for commercial purposes is the controller. If it entrusts the processing of that data to an external provider that acts only on documented instructions, that provider is the processor and must ensure confidentiality and security measures as required by the contract.
05
What to check in the contract
- The contract requires the processor to process data only on documented instructions from the controller.
- Persons authorized to process data are bound by confidentiality or an equivalent legal obligation.
- The technical and organizational measures required under Art. 32 are provided for.
- The processor assists the controller in responding to data subject requests.
- At the end of the service, data is deleted or returned according to the controller's choice.
06
How to organize this process with management software
A company can ask its software partner to configure distinct roles for controller and processor, with traceability of documented instructions, a log of changes to sub-processors, and a periodic contract review point. These are suggested operational choices, not guaranteed features: their implementation depends on the configuration agreed with the provider.
07
Common clarifications
- If a processor engages another processor that fails to fulfil its data protection obligations, the initial processor remains fully liable to the controller for the performance of that other processor's obligations.
- A processor must inform the controller when, in its view, an instruction infringes the regulation or other data protection provisions.
- Adherence to an approved code of conduct or an approved certification mechanism can be used as an element to demonstrate sufficient safeguards.
08
Practical next step
Steps
- List all providers that process personal data on behalf of the company.
- Check for each one whether it acts as a processor or as an independent controller.
- Revise or draft missing contracts following the mandatory content of Art. 28.3.
- Schedule a periodic review of sub-processors and written authorizations.
Expected result: An up-to-date list of controllers and processors involved in company processing activities, with contracts compliant with Art. 28.3 ready for periodic review.
FAQ
Frequently asked questions
What is the essential difference between controller and processor?
The controller determines the purposes and means of processing; the processor processes personal data on behalf of the controller, without independently deciding these elements.
What must the contract between controller and processor contain?
It must stipulate the subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, and obligations such as documented instructions, confidentiality, security measures and assistance with data subject rights.
Can a processor engage another processor without oversight?
No: prior written authorization, specific or general, from the controller is required, and in the case of a general authorization the controller must be able to object to planned changes.
✓