GDPR

Controller or Processor? Your Role Depends on What You Do

  • Data Protection
  • Data Governance
  • Privacy

A contract calls your organisation a data processor. But your organisation decides why the personal data will be used, which information will be collected and how long it will be retained.

Are you really a processor?

Under the GDPR, the answer does not depend on the label written in the contract. It depends on the particular processing activity and the decisions each organisation actually makes.

The practical rule is simple:

Examine the processing activity first. Determine the role. Then make the contract reflect that reality.

This matters because the difference between a data controller and data processor affects legal responsibility, transparency, contracts, individual rights, security, breach response, retention and deletion.

Data controller vs data processor: the short answer

A data controller determines why personal data will be processed and the essential elements of how the processing will take place.

A data processor processes personal data on behalf of the controller and within the controller’s instructions.

The central question is therefore not:

What does the contract call us?

It is:

Who is making the important decisions about this processing activity?

Under Article 4 of the GDPR, the controller determines the “purposes and means” of processing. The processor handles personal data on behalf of the controller.

Article 4 also provides that a controller may determine the purposes and means alone or jointly with others. Where two or more parties jointly determine them, Article 26 treats them as joint controllers and requires them to allocate their respective responsibilities in a transparent arrangement.

What does a data controller decide?

The controller decides the purpose of the processing - why it should happen.

It also decides its essential means. Depending on the activity, those decisions may include:

  • Whose personal data will be processed
  • Which categories of personal data will be collected
  • What the information will be used for
  • Who may receive or access it
  • How long it should be retained
  • Whether it will be disclosed or reused

For example, an employer decides to collect employee identification, salary and bank account information so that salaries can be calculated and paid. The employer determines the purpose and essential scope of that processing. It is therefore the controller.

A controller does not need to perform every operation itself. It can appoint another organisation to provide a service while remaining responsible for the decisions that made it the controller.

What does a data processor do?

A processor handles personal data on behalf of a controller.

If the employer appoints a payroll company to calculate salaries according to its instructions, the payroll company will generally be a processor for that activity. It performs a defined service using the employer’s personal data, but it does not decide to use the information for an independent purpose.

The phrase for that activity is important. The payroll company will still be a controller for other activities, such as managing its own employees or maintaining its own business records.

Controller and processor compared

Question Data controller Data processor
Who decides why the data is processed? The controller Follows the controller’s defined purpose
Who decides the essential scope? The controller Acts within the controller’s instructions
On whose behalf is the activity performed? For its own or jointly determined purpose On behalf of the controller
Can it use the data for an independent purpose? Potentially, subject to applicable law Not in its capacity as processor
Who determines the lawful basis? The controller Supports the controller where required
Who is responsible for individual rights? The controller Assists the controller
Is a processing contract required? Must appoint the processor under an appropriate contract Must follow the contract and documented instructions

Processors also have direct legal obligations. Being a processor does not mean having no responsibility.

Can a processor make technical decisions?

A processor does not need the controller to dictate every technical detail.

It may select:

  • The infrastructure used to provide the service
  • The method used to store the data
  • Particular technical security measures
  • The process used to retrieve, transfer or delete information
  • The staff and internal procedures used to deliver the service

These practical choices do not automatically turn the processor into a controller.

The distinction is between deciding how to implement an instructed service and deciding why the data is processed or the essential scope of that processing.

Why the contractual label is not enough

A controller-processor relationship must be governed by a contract, or another legal act under Union or Member State law, that meets Article 28 of the GDPR. Among other matters, the contract must address instructions, confidentiality, security, sub-processors, assistance, deletion or return of data and audits.

But the requirement for a contract follows from the relationship. The wording cannot override what the parties actually do.

The European Data Protection Board’s Guidelines 07/2020 (version 2.1, adopted 7 July 2021, with corrections of 20 September 2022) explain that controller and processor status should be determined from actual activities in the particular situation, rather than merely from formal designation in a contract.

If a service provider independently determines a new purpose for using personal data, it may become a controller for that processing. Article 28(10) of the GDPR provides that a processor which determines the purposes and means of processing is considered a controller in respect of that processing.

The correct sequence is:

  1. Identify the processing activity.
  2. Determine who makes the relevant decisions.
  3. Assign the appropriate role.
  4. Ensure the contract accurately governs that relationship.

Determine the role activity by activity

An organisation is not permanently a controller or permanently a processor.

A technology company may be:

  • A controller for its employees’ personal data
  • A processor when hosting a customer’s database
  • A controller for customer contact and billing information
  • A controller for information it independently uses to improve or market its own services

It may even process the same personal data in different capacities when the purposes are genuinely separate.

This is why role assessments should describe a specific processing activity. Assigning one label to an entire organisation can hide important differences in responsibility.

A practical controller-or-processor test

Begin by describing the activity in one sentence. Then ask:

  1. Who decided why the personal data would be processed?
  2. Who decided which individuals and categories of data would be included?
  3. Who determined the important rules concerning access, disclosure and retention?
  4. Is one party acting only on another party’s instructions?
  5. Can the service provider use the information for its own purposes?
  6. Who provides information to the individuals concerned?
  7. Who decides how rights requests will be handled?
  8. Do the contract and operational reality tell the same story?

No single question will resolve every case. The answers must be considered together.

Practical example 1: payroll services

An employer determines which employee information is needed, why it must be processed and how long it should be retained. A payroll provider calculates salaries and produces payslips according to the employer’s instructions.

For the payroll activity:

  • The employer is the controller.
  • The payroll provider is the processor.

The provider can make technical decisions about its payroll platform without becoming the controller. The position changes if it independently uses the employee data for a separate purpose that it has determined.

Practical example 2: a marketing provider

A retailer gives a marketing provider an approved customer list, message and delivery instructions. The provider uses the information only to send the communication.

For that instructed activity, the retailer is likely to be the controller and the marketing provider the processor.

Suppose the provider adds those individuals to its own marketing database and uses their information to promote its services. That is a different purpose, determined by the provider. The provider may therefore be a controller for that additional processing.

The same organisation - and even the same personal data - can be involved in two activities with different roles.

Practical example 3: a cloud or AI service

An organisation submits personal data to a cloud or AI service for a purpose it has defined. The provider processes the information only to deliver the requested service under the organisation’s instructions.

The customer may be the controller and the provider its processor.

However, if the provider independently decides to reuse submitted information to develop its own products or train models for its own purposes, that separate use requires a fresh role assessment. A processor label in the service agreement does not settle the question.

This is why organisations should examine both contractual terms and the provider’s actual data practices.

What does Vietnam’s PDPL say?

Vietnam’s Law on Personal Data Protection, Law No. 91/2025/QH15 - often called the Vietnam PDPL - uses a similar starting point but its categories are not identical to the GDPR.

Article 2 defines a personal data controller as the party that decides the purposes and means of processing. It defines a processor as a party that processes personal data at the request of a controller, or a controller and processor, through a contract. The law also expressly recognises a personal data controller and processor: a party that decides the purposes and means and directly performs the processing.

The processing contract therefore has an explicit legal role under the Vietnamese framework. Even so, the contractual description must correspond with which party makes the decisions and which party processes the data at another party’s request.

For a detailed explanation, see Controller and Processor Roles Under Vietnam’s PDPL.

Common mistakes

“We are paying them, so they must be our processor”

Not every supplier that receives personal data is a processor. Some professional and regulated service providers determine their own purposes and means and may be independent controllers.

“The agreement calls us a processor”

Under the GDPR, the label is evidence of what the parties intended, but it is not decisive. Actual decision-making carries more weight.

“The provider chooses the technology, so it must be a controller”

A processor may make technical and operational choices while delivering the service. The question is whether it has started determining the purpose or essential scope of the processing.

“Our organisation has only one role”

Roles attach to processing activities, not permanently to an organisation.

Why getting the role right matters

The distinction helps determine:

  • Who establishes and documents the lawful basis
  • Who provides privacy information
  • Who responds to individuals exercising their rights
  • Who decides retention and deletion requirements
  • Who reports and manages personal data breaches
  • Which contractual terms are required
  • Who authorises and oversees sub-processors
  • Who demonstrates accountability
  • Which activities belong in each party’s processing records

Incorrect classification can leave important obligations unassigned. It can also produce a contract that does not reflect the service being delivered.

This is a data governance question

Determining whether an organisation is a controller or processor is often presented as a narrow legal exercise. In practice, it is also a data governance activity.

The assessment establishes:

  • Who has decision-making authority
  • Who is accountable for each processing purpose
  • Who may authorise access, sharing and reuse
  • Which controls must appear in contracts
  • Who must act when something changes or goes wrong

A useful data inventory should therefore record roles at the level of the processing activity - not merely list an organisation as “controller” or “processor” without context.

Good governance connects the legal category, the contract and operational reality.

Final takeaway

The contract matters. It documents instructions, responsibilities and required protections.

But under the GDPR, it should be the result of the role assessment - not a substitute for it.

When deciding whether an organisation is a data controller or data processor, examine the purpose, the essential decisions and the actual use of the personal data.

Your role depends on what you do. The contract should reflect that reality.

This article provides general information about controller and processor roles, primarily under the EU GDPR, with a short note on Vietnam’s Law on Personal Data Protection. Legal requirements depend on the applicable law and the facts of each processing activity. This is not legal advice.