Controller-Processor Relationship
This is the working arrangement between two organisations handling the same personal data: the controller decides why and how the data is processed, while the processor simply acts on the controller's instructions. Because both parties handle the data but hold different responsibilities, their relationship must generally be set out in a written contract. This contract sets the rules for how the processor may use the data on the controller's behalf.
The controller-processor relationship describes the legal and operational arrangement in which a processor processes personal data on behalf of, and under the documented instructions of, a controller. The controller determines the purposes and means of the processing, while the processor acts on the controller's instructions and does not determine the purposes of the processing (though a processor may typically determine certain technical means of processing). Under EU and UK data protection guidance, this relationship must generally be governed by a binding written contract or other legal act that sets out the processing operations, the parties' respective obligations, and the processor's responsibilities. Note that role classification is fact-specific and turns on who actually decides the purposes and essential means of processing, rather than on how the parties label themselves; the required content and scope of the governing contract should be verified against the applicable provisions of the GDPR (or UK GDPR) and relevant supervisory authority guidance, and this definition does not address joint controllership, which is a distinct arrangement.
Why it matters
The controller-processor relationship sits at the heart of most modern data processing arrangements, because organisations rarely handle personal data entirely in-house. When a controller engages a processor to carry out processing on its behalf, both parties handle the same data but carry distinct responsibilities, and getting the allocation of those responsibilities right is essential to demonstrating accountability. Misclassifying a party's role, or failing to put the required arrangements in place, can leave gaps in responsibility that expose individuals to risk and expose organisations to regulatory scrutiny.
A recurring practical challenge is that role classification is fact-specific: it turns on who actually decides the purposes and essential means of the processing, not on how the parties describe themselves in a contract. An organisation labelled a processor may in fact be acting as a controller if it determines the purposes of the processing, and vice versa. Because both controllers and processors 'process' personal data in the broad sense (processing covering essentially any action taken in relation to personal data), the label alone does not settle the question, and each party's actual obligations flow from its true role rather than its chosen title.
Under EU and UK data protection guidance, a controller that engages a processor is generally obliged to put in place a binding written contract (commonly a data processing contract or agreement) governing the processing. This contract is the instrument through which the controller sets the rules for how the processor may use the data on its behalf. Failing to have such an arrangement in place, or having one that does not adequately set out the processing operations and the parties' obligations, is a common area of compliance weakness. The precise required content and scope should be verified against the applicable provisions of the GDPR or UK GDPR and relevant supervisory authority guidance.
Who it's relevant to
Inside Controller-Processor Relationship
Common questions
Answers to the questions practitioners most commonly ask about Controller-Processor Relationship.