Controller or processor: who is who under the GDPR?

Controller and a Processor Roles Under GDPR

A controller decides why and how personal data are processed; a processor processes personal data only on the controller’s instructions. Getting this right matters, because your role determines who needs a lawful basis, who must answer data subject requests, who reports a breach, and who is liable if something goes wrong.

How do you tell a controller from a processor?

You ask who decides why the data are processed and, in essence, how. A controller determines the purpose and the essential means of the processing. A processor acts strictly on the controller’s documented instructions and does not use the data for its own purposes.

Does the contract decide your role?

No. Calling yourself a processor in the agreement does not make you one. If a supplier uses the data for its own purposes – to improve its product, to build a profile, to market to the individuals concerned – it is a controller for that processing, whatever the contract says.

Typical processors: a hosting provider, a payroll bureau acting strictly on instructions, an email delivery service. Typical controllers, even though engaged by another party: an accountant performing a statutory audit, a lawyer conducting a case, an occupational health service exercising its own professional duties.

What if you and another party jointly decide the purposes?

You are then joint controllers, and you must set out your respective responsibilities in an arrangement between you, in particular for data subject rights and information duties. The essence of that arrangement must be made available to the individuals concerned.

Joint control arises more often than organisations expect: shared platforms, joint campaigns and social media pages have all been treated as joint controllership. A data subject can exercise their rights against either joint controller, regardless of how you have divided responsibility between you internally.

What must a processing agreement contain?

Where you engage a processor, a written agreement is compulsory and its content is prescribed: the subject matter and duration of the processing, its nature and purpose, the types of data and categories of data subject, your instructions as controller, confidentiality, security measures, the conditions for engaging sub-processors, assistance with data subject requests and breach notification, what happens to the data at the end of the agreement, and your audit rights.

Where do disputes usually start?

Two clauses cause most of the trouble in practice. Sub-processing: general written authorisation is permitted, but the processor must inform you of any intended changes and give you the opportunity to object. And return or deletion at the end of the relationship: agree which of the two applies, and in what format, before the relationship ends rather than during a dispute.

Who is liable if the processing goes wrong?

You are liable, as controller, for damage caused by processing that infringes the GDPR. A processor is liable only if it has not complied with obligations that the GDPR places specifically on processors, or has acted outside or contrary to your lawful instructions. Where both of you are involved in the same processing, each of you can be held liable for the entire damage towards the individual, with a right of recourse between you afterwards – which is why the indemnity provisions in a processing agreement are worth negotiating carefully.

In summary

  • Your role follows the facts, not the label in your contract: whoever decides the purpose and essential means is the controller.
  • If you jointly decide the purposes with another party, you are joint controllers and must record your division of responsibilities.
  • A processing agreement must cover the subject matter, duration, nature, purpose, data types, your instructions, security, sub-processing, assistance, return or deletion, and audit rights.
  • A processor may only sub-contract with your authorisation, and must let you object to any change of sub-processor.
  • Liability can fall on both parties for the same damage, so negotiate the indemnity clause before you sign.

Frequently asked questions

Can one party be a controller for part of the processing and a processor for another part?
Yes. The assessment is made per processing activity, not per relationship, so the same party can hold both roles for different data flows.

Do you need a processing agreement if you only occasionally share data with a supplier?
Yes, if the supplier processes personal data on your instructions, the agreement is compulsory regardless of how often the processing occurs.

We assess roles in a data chain, draft and review processing agreements and joint controller arrangements, and advise on liability after an incident.

Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

How Law & More can help you with this is explained on our IT lawyer page.

Tom Meevis
Tom Meevis is an attorney-at-law at Law & More in Eindhoven and Amsterdam. He handles general practice and is the negotiator and litigator of the firm.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

Cybersecurity incident reporting duties in the Netherlands are governed by the Cybersecurity Act (Cyberbeveiligingswet, Cbw),

EU sanctions against Russia apply directly in the Netherlands and bind every business here, whatever

Using AI in a Dutch business triggers two regimes at once. Any AI system that

Data breaches happen every day in the Netherlands. When they do, someone must take responsibility.

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) regulates AI according to the risk a

Almost every company with a Dutch-facing website publishes a privacy policy — a privacy statement

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.