The difference between a controller and a processor

Controller and a Processor Roles Under GDPR

Controller and a Processor Roles Under GDPR

The General Data Protection Regulation (GDPR) has already been in force for several months. However, there is still uncertainty about the meaning of certain terms in the GDPR. For example, it is not clear to everyone what the difference is between a controller and a processor, while these are core concepts of the GDPR. According to the GDPR, the controller is the (legal) entity or organization that determines the purpose and means of the processing of personal data. The controller therefore determines why personal data is being processed. In addition, the controller in principle determines with which means the data processing takes place. In practice, the party that actually controls the processing of data is the controller.

General Data Protection Regulation (GDPR)

According to the GDPR, the processor is a separate (legal) person or organization that processes personal data on behalf of and under the responsibility of the controller. For a processor, it is important to determine whether the processing of personal data is performed for the benefit of itself or for the benefit of a controller. It can sometimes be a puzzle to determine who is the controller and who is the processor. In the end, it is best to answer the next question: who has ultimate control over the purpose and means of data processing?

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

You scroll through Instagram and freeze: your face smiles from a clothing ad you never

Businesses across the Netherlands are increasingly using AI tools to improve their operations. Many face

Introduction Application to set aside (verzet aantekenen tegen) a default judgment (verstekvonnis) is a crucial

Dealing with conflict when your team is spread out requires a different playbook. It's not

Workplace conflict is unavoidable, but costly when it’s misunderstood. A missed deadline can be a

A Dutch SaaS company receives a cease-and-desist letter claiming that a core feature of their

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.