Every GDPR obligation attaches to a role. The controller determines the purposes and means of processing; the processor processes personal data on the controller’s behalf and on its instructions. Establishing which role a party occupies is the first step in any data protection assessment, because it decides who must have a lawful basis, who answers data subject requests, who reports a breach and who is liable.
The test is factual, not contractual
Calling a party a processor in the contract does not make it one. What counts is who actually decides why the data are processed and, in essence, how. A supplier that uses the data for its own purposes – to improve its product, to build a profile, to market to the individuals concerned – is a controller for that processing, whatever the agreement says.
Typical processors: a hosting provider, a payroll bureau acting strictly on instructions, an email delivery service. Typical controllers even though they are engaged by another party: an accountant performing a statutory audit, a lawyer conducting a case, an occupational health service in the exercise of its own professional duties.
Joint controllers
Where two parties jointly determine purposes and means, they are joint controllers and must set out their respective responsibilities in an arrangement between them, particularly as regards data subject rights and information duties. The essence of that arrangement must be made available to the individuals concerned.
Joint control arises more often than organisations expect: shared platforms, joint campaigns and social media pages have all been treated as joint controllership. A data subject may exercise their rights against either joint controller regardless of the internal allocation.
The processing agreement
Where a processor is engaged, a written agreement is compulsory, and its content is prescribed: subject matter and duration, nature and purpose, types of data and categories of data subject, the controller’s instructions, confidentiality, security measures, the conditions for engaging sub-processors, assistance with data subject requests and breach notification, what happens to the data at the end, and audit rights.
Two clauses cause most trouble in practice. Sub-processing: general written authorisation is permitted, but the processor must inform the controller of intended changes and give it the opportunity to object. And return or deletion at the end: agree which, and in what format, before the relationship ends rather than during a dispute.
Liability
A controller is liable for damage caused by processing that infringes the Regulation. A processor is liable only where it has not complied with obligations specifically directed at processors, or has acted outside or contrary to lawful instructions. Where both are involved in the same processing, each can be held liable for the entire damage towards the individual, with recourse between them afterwards – which is why the indemnity provisions in a processing agreement are worth negotiating properly.
Advice
We assess roles in a data chain, draft and review processing agreements and joint controller arrangements, and advise on liability after an incident. Please contact Law & More.


