Under the GDPR, how do you decide whether a vendor is a controller, a processor or a joint controller?
answer
- who decides why
- purposes and means
- on behalf of someone else
- Art. 4(7), Art. 4(8), Art. 26
basics
~20 sUnder the GDPR, whoever determines the purposes and means of processing is the controller (Art. 4(7)); a party processing on the controller's behalf is a processor (Art. 4(8)); parties that jointly determine purposes and means are joint controllers (Art. 26).
solid answer
~50 sUnder the GDPR, the roles follow from what a party actually does, not from the label in its contract. The **controller** determines the *purposes and means* of processing, alone or jointly (`Art. 4(7)`). A **processor** processes personal data *on behalf of* the controller (`Art. 4(8)`) and may act only on its documented instructions (`Art. 28(3)(a)`, `Art. 29`). When two or more parties *jointly* determine purposes and means they are **joint controllers** and must agree their respective responsibilities in an arrangement whose essence is made available to data subjects (`Art. 26`). A payroll provider computing salaries exactly as its client instructs is a processor for that work, even though it picks its own software. The same company can hold different roles for different processing, and a processor that starts deciding purposes itself is treated as a controller for that processing (`Art. 28(10)`).
go deeper
Recall the one-line test: the controller decides why and how, the processor acts on its behalf. Know that joint controllers exist and Art. 26 governs them.
Walk a concrete vendor through the test per processing operation, separating essential decisions from technical details, and cite Arts. 4(7), 4(8), 26 and 28(10).
Show that role allocation drives duties and liability: processor duties under Arts. 29, 30(2), 32 and 33(2), and the Art. 82(2) split between controller and processor liability.
Own the vendor-role inventory across the estate, challenging contract labels against actual data use, since a mislabelled vendor leaves duties nobody believes are theirs.
## The three roles in the Regulation's text The GDPR assigns obligations by **role**, and every role is defined in the Regulation: | Role | Definition | Where | |---|---|---| | **Controller** | Determines the purposes and means of processing, alone or jointly with others | `Art. 4(7)` | | **Processor** | Processes personal data on behalf of the controller | `Art. 4(8)` | | **Joint controllers** | Two or more controllers that jointly determine purposes and means | `Art. 26(1)` | | **Third party** | Anyone other than the data subject, controller, processor and persons authorised under their direct authority | `Art. 4(10)` | A **recipient** (`Art. 4(9)`) is any body to which data are disclosed, whether a third party or not, so a processor is a recipient too. ## The test: who decides why, and who decides how Role allocation is a question of fact. Ask, for each distinct processing operation: - **Why is this processing happening, and for whose benefit?** The party that sets the purpose is a controller. - **Who decides the essentials of how?** Which data are collected, how long they are kept, who receives them. Deciding these is part of determining the means. - **Who merely decides technical details?** Choosing the database engine, the hosting region or the batch schedule while serving someone else's purpose does not, on its own, make a vendor a controller. - **Does the vendor have any use of the data of its own?** If not, and it follows instructions, it is a processor. The contract's label is evidence, not the answer. A contract calling a vendor "processor" while the vendor uses the data for its own ends does not make it one, and `Art. 28(10)` says a processor that determines purposes and means in breach of the Regulation *shall be considered to be a controller in respect of that processing*. ## Worked example: a payroll provider A company hires a payroll provider to compute its employees' salaries, withholdings and payslips. 1. **The client decides why**: pay employees and meet its payroll duties. It decides which employees and which data go in. 2. **The provider decides technical details**: its software, its servers, its calculation engine. 3. **The provider has no purpose of its own** for the employee data in this service. So the client is the controller and the provider is the processor for payroll processing, and an `Art. 28` contract must govern the relationship. The same provider is a controller for other processing, for example its own staff records or its own customer accounts. Roles are assigned *per processing operation*, not per company. ## Joint controllers When two parties **jointly determine** purposes and means, for instance two companies that design and run a shared customer programme together, each deciding what is collected and why, they are joint controllers. `Art. 26` then requires: - a **transparent arrangement** determining their respective responsibilities, in particular for data-subject rights and the Art. 13 and 14 information duties (`Art. 26(1)`), unless law already allocates them; - that the arrangement **duly reflects** their roles and that its **essence is made available** to data subjects (`Art. 26(2)`); - acceptance that a data subject **may exercise their rights against each** of the controllers, whatever the arrangement says (`Art. 26(3)`). Joint control does not require equal shares of responsibility; it requires joint determination. ## Why the label matters in practice The role decides which duties you carry: - **Controllers** carry the Regulation's core duties: the principles in `Art. 5`, a lawful basis, transparency, data-subject rights, records under `Art. 30(1)`, security under `Art. 32`, breach notification to the authority, and choosing processors that give sufficient guarantees (`Art. 28(1)`). - **Processors** carry their own direct duties: act only on documented instructions (`Art. 28(3)(a)`, `Art. 29`), keep records of processing carried out for controllers (`Art. 30(2)`), implement `Art. 32` security, and notify the controller *without undue delay* after becoming aware of a breach (`Art. 33(2)`). - **Liability** follows too: under `Art. 82(2)` a controller involved in processing is liable for damage caused by infringing processing, while a processor is liable only where it breached obligations aimed at processors or acted outside or contrary to lawful instructions. ## Common mistakes - Treating the party that **stores** the data as the controller. Storage is a means; it says nothing about purpose. - Assuming a vendor is a processor **because the contract says so**. - Believing a company has **one role overall**. It has a role per processing operation. - Thinking joint controllers can **route all rights requests to one party**. `Art. 26(3)` lets the data subject choose.
- Under the GDPR, can a vendor be a processor for one client service and a controller for other processing?Yes. Roles attach to each processing operation, not to the company. A payroll provider is a processor when computing a client's salaries on instructions, and a controller for its own staff records, its own customer accounts, or any purpose it decides for itself. The analysis is repeated for each operation, asking who determines purposes and means (`Art. 4(7)`, `Art. 4(8)`).
- Under GDPR Art. 26, can joint controllers agree that data subjects must send every request to only one of them?They can designate a contact point (`Art. 26(1)`) and split who handles what, but `Art. 26(3)` lets the data subject exercise their rights in respect of and against each controller, irrespective of the arrangement. The arrangement governs the controllers between themselves; it does not narrow the data subject's choice.
- Under the GDPR, does a processor have obligations of its own, or only contractual ones?It has direct statutory duties: acting only on documented instructions (`Art. 29`), keeping a record of processing carried out for controllers (`Art. 30(2)`), security under `Art. 32`, and notifying the controller without undue delay after becoming aware of a breach (`Art. 33(2)`). `Art. 82(2)` makes it liable for damage where it breaches processor-specific obligations or acts outside lawful instructions.
saying these in an interview costs you the question
- Whoever stores the data or runs the servers is the controller.
- A vendor is a processor because the contract calls it a processor.
- A company is either a controller or a processor, never both.
- Joint controllers can force data subjects to deal with only one of them.
- Processors have no obligations under the GDPR, only under their contract.