Data controllers and data processors are key roles under the General Data Protection Regulation (GDPR). The GDPR assigns responsibilities to people involved in handling personal data and data controllers and data processors determine how personal information is handled, protected, and shared.
Understanding these roles is not just a matter of compliance; it is essential for building trust and maintaining accountability in data-driven operations.

What is a Data Controller?
A data controller is the person or party that determines the purposes and means of processing personal data. In essence, controllers are decision-makers. They establish why and how data will be processed, making them central to GDPR’s accountability framework.
A data controller:
-
identifies the activity for which personal data is needed
-
determines what personal data is needed
-
instructs the data processor
-
is accountable for a data processor’s compliance with their instructions
What is a Data Processor?
In contrast, a data processor acts on behalf of the data controller. Processors handle data strictly following the instructions given by the controller, without determining the purpose or legal basis for processing.
Common examples include companies that are engaged for direct marketing, third party courier companies or IT service firms that handle data but do not independently decide its use. While processors play a more limited role, they also have a responsibility to protect data and comply with GDPR standards.
Data processors are accountable to data controllers.
Key Differences Between Data Controllers and Data Processors
The difference between controllers and processors is mainly in decision-making authority and accountability. The table below may help determine if you are a data controller or a data processor in any data processing scenario:
|
Activity |
Data Controller |
Data Processor |
|
Deciding what data to use |
X |
|
|
Data Privacy Impact Assessments |
X |
|
|
Sending the data |
X |
|
|
Processing the data |
|
X |
|
Deleting the data when no longer needed |
|
X |
|
Accountability |
To ICO for both controller and processor activity |
To controller for own activity |
Controllers make overarching decisions about data usage, while processors carry out specific tasks under the controller’s direction. Controllers bear primary accountability for ensuring GDPR compliance, but processors are also bound by obligations to implement robust data protection measures.
Shared Responsibilities: Collaboration for Compliance
While controllers and processors have distinct roles, their collaboration is crucial for GDPR compliance. Effective communication and clear expectations help ensure that data handling aligns with legal requirements. For example, when a business (controller) contracts an IT company (processor) to manage its customer database, both parties must coordinate to implement proper safeguards and respond swiftly to data breaches.
Joint Controllers under the GDPR
There is another concept introduced by the GDPR of “controllers in common” or “joint controllers”. This refers to two or more organisations that jointly determine the purposes and means of processing personal data.1 This means they share responsibility for compliance with the GDPR.
Key characteristics of joint controllers
-
Shared Responsibility: Both controllers are accountable for complying with the GDPR.
-
Joint Decision-Making: They jointly determine the purposes and means of processing personal data
-
People’s GDPR Rights: They are jointly responsible for responding to data subject requests.
-
Breach Notifications: They must coordinate their efforts to notify data protection authorities and affected individuals.4
-
Data Protection Impact Assessments (DPIAs): They may need to conduct joint DPIAs to assess the risks associated with their joint processing activities.
Common Joint Controller Scenarios
-
Shared Services Agreements: When two or more organisations share a common service provider and jointly determine the purpose and means of processing personal data.
-
Joint Ventures: When two or more organisations collaborate on a specific project and jointly process personal data.
-
Recruitment: if a company uses a recruitment firm to fill vacancies the recruitment firm needs certain leeway to collect and process data, and make decisions on behalf of the company with vacancies to fill.
To effectively manage their joint responsibilities, joint controllers should enter into a written agreement that outlines their respective roles, responsibilities, and decision-making processes.8 This agreement should also address how they will cooperate in case of data breaches or other compliance issues.
Sign Up Here:
Controllers hold the main responsibility for compliance under GDPR. They must ensure transparency by providing clear privacy notices to data subjects and enabling the exercise of rights such as access, rectification, and erasure. Additionally, controllers are required to conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities and maintain detailed records of processing activities to demonstrate compliance. Data controllers are also ultimately accountable for data processors’ activities and must maintain appropriate oversight of them. Processors must follow the instructions of controllers. While they are accountable to data controllers, data processors have their own responsibilities under GDPR. They must implement adequate technical and organisational measures to secure data, notify controllers of data breaches promptly, and ensure that sub-processors adhere to the same standards. Even though processors act under the direction of controllers, failure to meet their obligations can lead to direct penalties. The relationship between controllers and processors must be formalised through a contract that clearly sets out: who is the data controller who is the data processor what data are to be collected and processed the purpose of the processing This legally binding contract ensures that processors act in accordance with GDPR requirements and follow the controller’s instructions. Key provisions in this contract will include include the duration of the processing, security measures, breach notification procedures, and the obligation to delete or return data at the end of the contract. Both controllers and processors face severe consequences for failing to comply with GDPR. Controllers can be held liable for inadequate data protection practices, while processors may face penalties for breaches, even if they acted under the controller’s instructions. Fines under GDPR can reach up to €20 million or 4% of annual global turnover, underscoring the importance of strict adherence to roles and obligations. Organisations can take proactive steps to ensure compliance with GDPR’s requirements. Regular audits, staff training, and clear documentation of data handling practices are essential. Alongside clear contracts and the associated due diligence there must be reporting and assurance mechanisms that help data controllers hold data processors to account and that allow processors to alert controllers if anything goes wrong. Controller Obligations Under GDPR
Processor Obligations Under GDPR
The Role of Contracts
Consequences of Non-Compliance
Practical Steps for Ensuring Compliance
Learn More About the GDPR
This GDPR training course includes the following modules:
- what are personal data?;
- the privacy principles;
- privacy by design
- accountability under the GDPR;
- people’s rights under the GDPR;
- consent and other lawful routes for data sharing;
- data flow mapping and records of processing activity;
- Data Protection Impact Assessments;
- restricted and special category data
- Data security and Data Breaches
Plus six months’ free post course support to help you apply your learning

Rated 4.8 out of 5 on Trustpilot
Conclusion: Navigating GDPR for Data Controllers and Data Processors
The GDPR’s emphasis on the roles of data controllers and processors reflects its commitment to protecting personal data. By understanding and fulfilling their respective obligations, controllers and processors can work together to ensure compliance, mitigate risks, and build trust with data subjects. Collaboration, vigilance, and a strong commitment to data protection are the keys to navigating this relationship and meeting the requirements of GDPR.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: