Every obligation in the regime attaches to a role, so getting the role wrong makes everything downstream wrong — the contract, the notices, who answers a rights request, and who a regulator pursues.
The test is decision-making, not size or direction of payment
A controller determines the purposesDetermines the purposesThe test that separates a controller from a processor: who decides WHY the processing happens. Not who holds the data, who is larger, or what the contract calls them. and means of processing: why it happens, and in broad terms how. A processor processes on the controllerControllerDecides why and how personal data is processed. Carries most of the duties — and the fines.’s behalf and on its instructions.
The intuitions that mislead:
- “They are the big company, so they must be the controller.” Irrelevant. A large cloud provider is usually a processorProcessorProcesses on the controller’s instructions — cloud hosts, payroll bureaus — with its own security and breach duties. for its customers’ data.
- “We pay them, so we are the controller.” Not necessarily. Your accountant, your lawyer and your insurer are typically controllers in their own right — they exercise professional judgement, they do not act on your instructions.
- “The contract says processor.” The label does not decide it. If the recipient uses the data for its own purposes, it is a controller regardless of what was signed, and it has been acting without meeting its own obligations.
The practical question is short: who decides why? If your supplier decides anything of substance about purpose, they are not a pure processor.
Joint controllers
Where two organisations jointly determine purposes and means, they are joint controllers and must agree, in a transparent arrangement, who does what — particularly who answers rights requests and who provides the information notice. The essence of that arrangement must be available to individuals.
Joint control does not mean equal control, and it does not require symmetric processing. Two organisations running a shared service or a joint campaign frequently qualify without realising, because each contributes to deciding the purpose even though only one holds the database.
The consequence people miss: a person can exercise their rights against either joint controller, whatever the arrangement says between them.
What a processor contract must contain
A processing contract is not a formality; the required terms are specified. It must bind the processor to:
- process only on documented instructions, including on transfers
- ensure staff are under a duty of confidence
- apply appropriate security measures
- engage sub-processors only with authorisation, and pass the same obligations down
- assist with rights requests, and with breach, impact assessment and consultation duties
- delete or return the data at the end, at the controller’s choice
- make available the information needed to demonstrate compliance, and allow audits
Sub-processing is where this leaks. A general authorisation still requires notice of changes and a genuine opportunity to object. A processor that swaps a sub-processor silently has breached, and the controller usually discovers it during an incident.
Liability
A processor that goes beyond its instructions and determines purposes itself becomes a controller for that processing, with all the obligations attached — and is exposed accordingly. Processors also carry direct statutory duties, notably security and record-keeping, which they owe regardless of the contract.
An individual can claim compensation from either, and the parties sort out apportionment between themselves afterwards.
Getting it right in practice
- For each supplier, write down who decides why, in one sentence.
- Classify from that sentence, not from the contract template.
- Where the answer is “both of us”, check joint control before assuming a processor arrangement.
- Where a supplier exercises independent professional judgement, expect controller.
- Record the classification and the reasoning in the record of processing. It is the field most often left as “processor” by default, and it is the one that decides who has to answer when something goes wrong.