Data Controllers and Data Processors under the GDPR

Data controllers and data processors are key roles under the General Data Protection Regulation (GDPR). The GDPR assigns responsibilities to people involved in handling personal data and data controllers and data processors determine how personal information is handled, protected, and shared.

Understanding these roles is not just a matter of compliance; it is essential for building trust and maintaining accountability in data-driven operations.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Periodic table of the GDPR

What is a Data Controller?

A data controller is the person or party that determines the purposes and means of processing personal data. In essence, controllers are decision-makers. They establish why and how data will be processed, making them central to GDPR’s accountability framework.

A data controller:

  • identifies the activity for which personal data is needed

  • determines what personal data is needed

  • instructs the data processor

  • is accountable for a data processor’s compliance with their instructions

 

What is a Data Processor?

In contrast, a data processor acts on behalf of the data controller. Processors handle data strictly following the instructions given by the controller, without determining the purpose or legal basis for processing.

Common examples include companies that are engaged for direct marketing, third party courier companies or IT service firms that handle data but do not independently decide its use. While processors play a more limited role, they also have a responsibility to protect data and comply with GDPR standards.

Data processors are accountable to data controllers.

 

Key Differences Between Data Controllers and Data Processors

The difference between controllers and processors is mainly in decision-making authority and accountability. The table below may help determine if you are a data controller or a data processor in any data processing scenario:

Activity

Data Controller

Data Processor

Deciding what data to use

X

Data Privacy Impact Assessments

X

Sending the data

X

Processing the data

X

Deleting the data when no longer needed

X

Accountability

To ICO for both controller and

processor activity

To controller for own activity

Controllers make overarching decisions about data usage, while processors carry out specific tasks under the controller’s direction. Controllers bear primary accountability for ensuring GDPR compliance, but processors are also bound by obligations to implement robust data protection measures.

 

Shared Responsibilities: Collaboration for Compliance

While controllers and processors have distinct roles, their collaboration is crucial for GDPR compliance. Effective communication and clear expectations help ensure that data handling aligns with legal requirements. For example, when a business (controller) contracts an IT company (processor) to manage its customer database, both parties must coordinate to implement proper safeguards and respond swiftly to data breaches.

 

Joint Controllers under the GDPR

There is another concept introduced by the GDPR of “controllers in common” or “joint controllers”. This refers to two or more organisations that jointly determine the purposes and means of processing personal data.1 This means they share responsibility for compliance with the GDPR.

 

Key characteristics of joint controllers

  • Shared Responsibility: Both controllers are accountable for complying with the GDPR.

  • Joint Decision-Making: They jointly determine the purposes and means of processing personal data

  • People’s GDPR Rights: They are jointly responsible for responding to data subject requests.

  • Breach Notifications: They must coordinate their efforts to notify data protection authorities and affected individuals.4

  • Data Protection Impact Assessments (DPIAs): They may need to conduct joint DPIAs to assess the risks associated with their joint processing activities.

Common Joint Controller Scenarios

  • Shared Services Agreements: When two or more organisations share a common service provider and jointly determine the purpose and means of processing personal data.

  • Joint Ventures: When two or more organisations collaborate on a specific project and jointly process personal data.

  • Recruitment: if a company uses a recruitment firm to fill vacancies the recruitment firm needs certain leeway to collect and process data, and make decisions on behalf of the company with vacancies to fill.

To effectively manage their joint responsibilities, joint controllers should enter into a written agreement that outlines their respective roles, responsibilities, and decision-making processes.8 This agreement should also address how they will cooperate in case of data breaches or other compliance issues.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Controller Obligations Under GDPR

Controllers hold the main responsibility for compliance under GDPR. They must ensure transparency by providing clear privacy notices to data subjects and enabling the exercise of rights such as access, rectification, and erasure. Additionally, controllers are required to conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities and maintain detailed records of processing activities to demonstrate compliance.

Data controllers are also ultimately accountable for data processors’ activities and must maintain appropriate oversight of them.

 

Processor Obligations Under GDPR

Processors must follow the instructions of controllers. While they are accountable to data controllers, data processors have their own responsibilities under GDPR. They must implement adequate technical and organisational measures to secure data, notify controllers of data breaches promptly, and ensure that sub-processors adhere to the same standards.

Even though processors act under the direction of controllers, failure to meet their obligations can lead to direct penalties.

 

The Role of Contracts

The relationship between controllers and processors must be formalised through a contract that clearly sets out:

  • who is the data controller

  • who is the data processor

  • what data are to be collected and processed

  • the purpose of the processing

This legally binding contract ensures that processors act in accordance with GDPR requirements and follow the controller’s instructions. Key provisions in this contract will include include the duration of the processing, security measures, breach notification procedures, and the obligation to delete or return data at the end of the contract.

 

Consequences of Non-Compliance

Both controllers and processors face severe consequences for failing to comply with GDPR. Controllers can be held liable for inadequate data protection practices, while processors may face penalties for breaches, even if they acted under the controller’s instructions. Fines under GDPR can reach up to €20 million or 4% of annual global turnover, underscoring the importance of strict adherence to roles and obligations.

 

Practical Steps for Ensuring Compliance

Organisations can take proactive steps to ensure compliance with GDPR’s requirements. Regular audits, staff training, and clear documentation of data handling practices are essential.

Alongside clear contracts and the associated due diligence there must be reporting and assurance mechanisms that help data controllers hold data processors to account and that allow processors to alert controllers if anything goes wrong.

 

Learn More About the GDPR

 

 

This GDPR training course includes the following modules:

  • what are personal data?;
  • the privacy principles;
  • privacy by design
  • accountability under the GDPR;
  • people’s rights under the GDPR;
  • consent and other lawful routes for data sharing;
  • data flow mapping and records of processing activity;
  • Data Protection Impact Assessments;
  • restricted and special category data
  • Data security and Data Breaches

Plus six months’ free post course support to help you apply your learning

 

Conclusion: Navigating GDPR for Data Controllers and Data Processors

The GDPR’s emphasis on the roles of data controllers and processors reflects its commitment to protecting personal data. By understanding and fulfilling their respective obligations, controllers and processors can work together to ensure compliance, mitigate risks, and build trust with data subjects. Collaboration, vigilance, and a strong commitment to data protection are the keys to navigating this relationship and meeting the requirements of GDPR.