Glossary

The Test That Settles Data Controller vs Data Processor

Taras Shynkarenko
Taras Shynkarenko
•Updated: •7 min read
The Test That Settles Data Controller vs Data ProcessorThe Test That Settles Data Controller vs Data Processor

TL;DR, Quick Answer

7 min read

The controller determines the purposes and means of processing; the processor handles personal data on the controller's behalf and under its instructions. Size, ownership, and who holds the servers change nothing. A site owner who installs an analytics tool is the controller of that data, and the vendor running the tool on its instructions is the processor.

What is the difference between a data controller and a data processor?

The GDPR settles data controller vs data processor with one test: the controller determines the purposes and means of the processing, and the processor handles personal data on that controller's behalf. Who holds the servers and who is bigger decide nothing. A four-person company that decides why visitor data gets collected is its controller, and the vendor storing that data on its instructions is the processor.

What does the GDPR say the two roles are?

Both definitions sit in Article 4. Article 4(7) of Regulation (EU) 2016/679 defines a controller as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing". Article 4(8) defines a processor as "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller".

The European Data Protection Board reduces the test to two words in Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, adopted 7 July 2021: a controller determines "the why and how of the processing". The guidelines split the "how" in two. Essential means belong to the controller: which data, how long, who receives them, whose data they are. Non-essential means, "the choice for a particular type of hard- or software or the detailed security measures", can be left to the processor. Read your contracts against that line: a document labelling you a processor does not make you one if you decide the why.

Who decides, who signs what, who is liable, and who reports a breach?

Data controllerData processor
DecidesThe purpose, and the essential means: which data, how long, who receives themNon-essential means: software, infrastructure, internal access design
SignsAn Article 28(3) contract with each processor, an Article 26 arrangement with any joint controllerThat contract, plus a back-to-back one per sub-processor
Owes duties toData subjects and the supervisory authorityThe controller, under the contract and Article 28
Liability under Article 82Liable "for the damage caused by processing which infringes this Regulation"Liable only for breaching a processor-specific duty or acting "outside or contrary to lawful instructions"
On a breachNotifies the supervisory authority under Article 33(1), inside 72 hoursNotifies the controller under Article 33(2), "without undue delay"
Data subject requestAnswers directlyAssists under Article 28(3)(e)

Article 82(4) changes that liability row. Where a controller and a processor are involved in the same infringing processing, "each controller or processor shall be held liable for the entire damage", and they apportion it between themselves afterwards.

Two colleagues shake hands in an office, representing two companies agreeing to share responsibility as joint controllers.

When are two companies joint controllers instead?

Two companies are joint controllers when they determine the purposes and means together, which Article 26(1) governs. The EDPB sets the threshold in Guidelines 07/2020: joint participation can be "a common decision" or "converging decisions", and the criterion is that "the processing by each party is inseparable, i.e. inextricably linked".

Article 26(1) then requires them to set out their respective responsibilities in a transparent arrangement covering data subject rights. What that arrangement cannot do is contain the exposure, because the EDPB states that "irrespective of the terms of the arrangement, data subjects may exercise their rights in respect of and against each of the joint controllers", and that supervisory authorities are not bound by how the parties labelled themselves. So if a vendor decides for its own purposes what happens to the data you send, no data processing agreement turns it back into a processor.

How far does responsibility travel down the sub-processor chain?

Responsibility travels the whole chain and stops at the controller. Article 28(2) states that "the processor shall not engage another processor without prior specific or general written authorisation of the controller", and Article 28(4) closes the chain: where that other processor fails its obligations, "the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations".

The EDPB reads the mechanics strictly. Under a general authorisation the processor has to actively flag each new sub-processor, and a footnote in Guidelines 07/2020 says it is "not sufficient for the processor to merely provide the controller with a generalized access to a list of the sub-processors which might be updated from time to time". Under a specific authorisation, an unanswered request counts as refused. Ask any vendor for its sub-processor list with each entry's location, since that list is where data residency and data sovereignty part company.

Who notifies whom when there is a breach?

The processor notifies the controller, and the controller notifies the supervisory authority. Article 33(2) gives the processor one duty, to "notify the controller without undue delay after becoming aware of a personal data breach", with no risk assessment attached. Article 33(1) gives the controller the harder one: notify the authority "not later than 72 hours after having become aware of it".

Where that clock starts is the contract term to watch. EDPB Guidelines 9/2022 on personal data breach notification under GDPR, version 2.0, adopted 28 March 2023, state that "the controller should be considered as 'aware' once the processor has informed it of the breach". So:

controller deadline = the moment the processor informs the controller + 72 hours

A processor detects a breach at 08:00 Monday and its contract gives it 24 hours to report, so it informs the controller at 08:00 Tuesday and the controller's 72 hours run to 08:00 Friday: 96 hours from detection to the regulator hearing about it. The GDPR fixes no limit on the processor's leg, so the number you negotiate decides how much of that total burns first.

A person types on a laptop at a desk, representing a business running an analytics tool on its own website.

The 96-hour breach clock
1
Monday, 08:00. The processor detects the breach.
2
Tuesday, 08:00. The processor notifies the controller, using the 24 hours its contract allows.
3
Friday, 08:00. The controller's 72-hour deadline to the supervisory authority expires, 96 hours after detection.
The GDPR sets no limit on the processor's leg, so the number negotiated into the contract decides how much of the 96 hours burns before the regulator hears about it.

Which role do you take when you run an analytics tool?

You are the controller and the analytics vendor is the processor. You decided to measure your traffic, chose what the script collects, set the retention period, and decide who reads the reports. Those are the purposes and the essential means. The vendor stays a processor for as long as it handles that data on your documented instructions, even though it stores every byte.

Flowsery
Flowsery

Start FREE Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Two duties follow. You need an Article 28(3) contract with the vendor before the script goes live, and you need a lawful basis, which for measurement turns on whether anything is stored on or read from the visitor's device. That second question is the ePrivacy one, and cookieless analytics is where the two separate: dropping the storage drops the trigger behind the consent banner, while the GDPR still governs what you hold. Anything you keep that can single out a visitor is personal data with a controller attached, and that controller is you.

Flowsery keeps that surface small. It is cookie-free, EU-hosted and GDPR by design, ships as one script under 10 KB, and applies no data sampling. Its GDPR page sets out how it handles data.

What turns a processor into a controller?

Deciding for itself does. Article 28(10) provides that a processor which determines the purposes and means of processing is considered a controller for that processing, and Guidelines 07/2020 add that it "may be subject to sanctions for going beyond the controller's instructions". Read every vendor contract for the sentence granting a secondary use, since that is where model training and resold profiles hide.

Frequently asked questions

Does the bigger company automatically become the controller?

No. Article 4(7) attaches the role to whoever determines the purposes and means, and says nothing about size or bargaining power. A small business using a large cloud vendor controls the data it collects, and the vendor is its processor.

Do I need a data processing agreement with every vendor?

You need one with every processor. Article 28(3) requires that processing by a processor be governed by a binding written contract or other legal act. Vendors acting as controllers in their own right, such as a bank executing a payment, sit outside Article 28.

Can a processor be fined directly by a supervisory authority?

Yes. Processors carry obligations of their own under Articles 28, 30, 32 and 33, and breaching those exposes them to enforcement. Article 82(2) narrows civil liability differently: a processor owes damages only where it failed a processor-specific duty or acted outside the controller's lawful instructions.

Who answers a data subject's access request?

The controller does. A processor's duty under Article 28(3)(e) is to assist the controller in responding, not to answer the requester itself. Where joint controllers are involved, the EDPB is explicit that data subjects may exercise their rights against each of them, whatever their arrangement says.

How fast must a processor tell me about a breach?

Article 33(2) says "without undue delay" and fixes no number of hours. EDPB Guidelines 9/2022 recommend prompt notification with details following in phases, and treat the controller as aware once the processor informs it. Put a timeframe, a contact point, and a minimum content requirement in the contract.

What is the difference between a sub-processor and a third party?

A sub-processor processes personal data on the original processor's behalf, inside the chain your instructions govern, and needs your prior written authorisation under Article 28(2). A third party processes for its own purposes and is a controller for it, so sending data there is a disclosure, not a delegation.

Who pays if a controller and a processor are both at fault?

Article 82(4) holds each one liable for the entire damage when a controller and a processor are involved in the same infringing processing. They only apportion the cost between themselves afterward, so the data subject does not have to sort out who owes what share first.

Does a contract calling a vendor a processor settle its role?

The EDPB guidelines state that a vendor deciding for its own purposes what happens to data stays a controller no matter what the contract calls it, and supervisory authorities are not bound by how the parties labelled themselves. The test stays functional. Whoever decides the why holds the role, regardless of the paperwork.

What must a processor do before adding a sub-processor?

Article 28(2) requires prior specific or general written authorisation from the controller before engaging another processor. Under a general authorisation the processor still has to actively flag each new sub-processor, since the EDPB says a generalized, occasionally updated list does not satisfy that duty. Under a specific authorisation, a request the controller never answers counts as refused.

Can a processor use the data it handles for its own purposes?

Not under the role it signed up for. Article 28(10) treats a processor that determines its own purposes and means as a controller for that processing, and the EDPB notes it can face sanctions for going beyond the controller's instructions. That is the clause to look for in a vendor contract, since it is where model training or resold profiles hide.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Glossary Terms

Related Articles