A controller decides why and how personal data are processed; a processor processes personal data only on the controller’s instructions. Getting this right matters, because your role determines who needs a lawful basis, who must answer data subject requests, who reports a breach, and who is liable if something goes wrong.
How do you tell a controller from a processor?
You ask who decides why the data are processed and, in essence, how. A controller determines the purpose and the essential means of the processing. A processor acts strictly on the controller’s documented instructions and does not use the data for its own purposes.
Does the contract decide your role?
No. Calling yourself a processor in the agreement does not make you one. If a supplier uses the data for its own purposes – to improve its product, to build a profile, to market to the individuals concerned – it is a controller for that processing, whatever the contract says.
Typical processors: a hosting provider, a payroll bureau acting strictly on instructions, an email delivery service. Typical controllers, even though engaged by another party: an accountant performing a statutory audit, a lawyer conducting a case, an occupational health service exercising its own professional duties.
What if you and another party jointly decide the purposes?
You are then joint controllers, and you must set out your respective responsibilities in an arrangement between you, in particular for data subject rights and information duties. The essence of that arrangement must be made available to the individuals concerned.
Joint control arises more often than organisations expect: shared platforms, joint campaigns and social media pages have all been treated as joint controllership. A data subject can exercise their rights against either joint controller, regardless of how you have divided responsibility between you internally.
What must a processing agreement contain?
Where you engage a processor, a written agreement is compulsory and its content is prescribed: the subject matter and duration of the processing, its nature and purpose, the types of data and categories of data subject, your instructions as controller, confidentiality, security measures, the conditions for engaging sub-processors, assistance with data subject requests and breach notification, what happens to the data at the end of the agreement, and your audit rights.
Where do disputes usually start?
Two clauses cause most of the trouble in practice. Sub-processing: general written authorisation is permitted, but the processor must inform you of any intended changes and give you the opportunity to object. And return or deletion at the end of the relationship: agree which of the two applies, and in what format, before the relationship ends rather than during a dispute.
Who is liable if the processing goes wrong?
You are liable, as controller, for damage caused by processing that infringes the GDPR. A processor is liable only if it has not complied with obligations that the GDPR places specifically on processors, or has acted outside or contrary to your lawful instructions. Where both of you are involved in the same processing, each of you can be held liable for the entire damage towards the individual, with a right of recourse between you afterwards – which is why the indemnity provisions in a processing agreement are worth negotiating carefully.
In summary
- Your role follows the facts, not the label in your contract: whoever decides the purpose and essential means is the controller.
- If you jointly decide the purposes with another party, you are joint controllers and must record your division of responsibilities.
- A processing agreement must cover the subject matter, duration, nature, purpose, data types, your instructions, security, sub-processing, assistance, return or deletion, and audit rights.
- A processor may only sub-contract with your authorisation, and must let you object to any change of sub-processor.
- Liability can fall on both parties for the same damage, so negotiate the indemnity clause before you sign.
Frequently asked questions
Can one party be a controller for part of the processing and a processor for another part?
Yes. The assessment is made per processing activity, not per relationship, so the same party can hold both roles for different data flows.
Do you need a processing agreement if you only occasionally share data with a supplier?
Yes, if the supplier processes personal data on your instructions, the agreement is compulsory regardless of how often the processing occurs.
We assess roles in a data chain, draft and review processing agreements and joint controller arrangements, and advise on liability after an incident.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.


