Skip to main content
Category: Controller & Processor Roles

Determination of Purposes and Means of Processing

Also known as: The 'why' and 'how' of processing, Purposes and means test, Determining purposes and means
Simply put

This is the test used to decide who is legally in charge of a set of personal data activities. Whoever decides both the reasons for processing personal data (the 'why') and the essential ways it will be carried out (the 'how') is generally treated as the controller. An organisation that only follows another's instructions typically acts as a processor rather than making these decisions itself.

Formal definition

Under Article 4 GDPR, a 'controller' is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. In guidance from the EDPB (and previously the Article 29 Working Party) and the ICO, 'purposes' refers to the 'why' of the processing and 'means' to the 'how'. The determination is assessed on the factual reality of the activity rather than on labels adopted by the parties. Regulatory guidance generally distinguishes between essential means, which tend to be reserved to the controller, and non-essential (more technical or operational) means, which a processor may decide. A processor that goes beyond the controller's instructions and itself determines the purposes and means of processing may, in respect of that activity, be treated as a controller. This entry describes the concept at a general level; the precise boundary of what counts as determining 'means' is subject to regulatory guidance that continues to develop, and readers should verify against the current text of the GDPR (or UK GDPR) and applicable regulator guidance.

Why it matters

Determining the purposes and means of processing is the pivotal test that fixes who bears the heaviest legal responsibilities under the GDPR. Controller status carries the primary accountability obligations, including identifying a lawful basis under Article 6, responding to data subject rights requests, and demonstrating compliance. Processor status, by contrast, generally confines an organisation to acting on documented instructions. Getting this classification wrong at the outset can cascade through an entire compliance programme, because contracts, notices, records of processing, and breach-response responsibilities are all allocated according to whether a party is treated as a controller, a joint controller, or a processor.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams rely on this test to map each processing activity to the correct role before building records of processing, notices, and contracts. Because status is assessed on factual reality rather than labels, they should document the reasoning behind each classification and revisit it as arrangements change, particularly where a vendor may be exercising more decision-making than its contract suggests.
Privacy and Commercial Lawyers
Lawyers drafting service and vendor agreements need to align the contractual characterisation with the factual allocation of decision-making over purposes and essential means. Where the reality points to controller or joint-controller status, a processor label in the contract will not be decisive, and the wrong framing can leave obligations unallocated or misassigned.
Engineers and Product Teams
Technical and product staff often make operational decisions about how data is handled, which can bear on the 'means' analysis. Understanding the distinction between essential means (generally reserved to the controller) and non-essential technical means helps them recognise when a design choice may shift or clarify legal responsibility, and when to escalate to legal or the DPO.
Service Providers and Vendors
Organisations offering processing services need to understand that acting beyond a client's documented instructions, or determining purposes and means for their own ends, may cause them to be treated as a controller for that activity, with the fuller set of obligations that entails. Careful scoping of instructions and internal controls helps keep activities within an intended processor role.

Inside Determination of Purposes and Means of Processing

Determination of Purposes
The decision about why personal data is processed, meaning the objective or intended outcome of the processing. Determining the purposes is a core element in identifying who acts as a controller under GDPR, generally by reference to Article 4 (definition of controller) and Article 24 (controller responsibility).
Determination of Means
The decision about how personal data is processed. Guidance from the European Data Protection Board and case law generally distinguishes between essential means (such as which data is processed, the categories of data subjects, the retention period, and who has access) and non-essential means (more technical or operational choices, such as the specific software or security measures). Determining the essential means is typically reserved to the controller, while a processor may be permitted to decide certain non-essential means.
Controller Identification
An entity that alone or jointly determines the purposes and means qualifies as a controller. This is a functional assessment based on actual influence over the processing, not merely on contractual labels adopted by the parties.
Joint Controllership
Where two or more entities jointly determine the purposes and means, they may be joint controllers. This arrangement carries specific obligations, including an arrangement setting out respective responsibilities, and is subject to factual assessment of each party's role.
Processor Boundary
A processor processes personal data on behalf of and under the instructions of a controller. A processor that begins to determine purposes and, in most cases, essential means may exceed its role and be treated as a controller for that processing. This distinction is governed by the arrangements typically required under Article 28.
Factual, Fact-Specific Assessment
The determination is assessed against the reality of the relationship and the degree of actual influence each party exercises over the purposes and means, rather than solely by how the parties describe themselves. The outcome can vary depending on the specific processing activity and context.

Common questions

Answers to the questions practitioners most commonly ask about Determination of Purposes and Means of Processing.

Does the party that physically holds or stores the data automatically determine the purposes and means of processing?
No. Determining the purposes and means is about deciding why and how personal data is processed, not about who technically stores or handles it. An entity can host or process data on another's behalf without determining these matters, in which case it would typically act as a processor rather than a controller. The controller/processor distinction turns on decision-making influence over the processing, not on physical possession of the data, subject to assessment of the actual arrangements.
Must a controller decide every technical detail itself to be treated as determining the means of processing?
Not generally. Guidance from EU regulators has distinguished between essential means and non-essential means. Essential means, such as which data is processed, the categories of individuals concerned, the retention period, and who has access, are typically closely linked to the purpose and are for the controller to determine. Non-essential means, which are more practical or technical implementation choices, may in many cases be left to a processor without altering the controller's role. The precise boundary can involve judgment and should be assessed case by case.
How can an organisation assess in practice whether it is determining the purposes and means of a given processing activity?
A common approach is to map, for each processing activity, who decides why the data is processed and who decides the essential elements of how it is processed. Reviewing factual reality, contractual terms, and actual decision-making influence together tends to be more reliable than relying on labels alone. Where an organisation exercises genuine influence over the purpose or essential means, it will generally be treated as a controller regardless of how the contract describes it. This is a factual assessment rather than a purely contractual one.
What should be documented to evidence who determines the purposes and means?
Organisations typically document the allocation of roles in records of processing activities and in the relevant contracts, such as controller-to-processor terms under Article 28 or joint controller arrangements where applicable. It is generally advisable to record the reasoning behind the role determination, including who decided the purpose and the essential means, so the position can be explained if questioned. The appropriate level of detail depends on the complexity and risk of the processing and should be verified against current regulatory guidance.
How does this determination affect the choice and documentation of a legal basis?
The party that determines the purposes and means, as controller, is generally responsible for identifying and documenting an appropriate legal basis under Article 6 for that processing, and an additional condition under Article 9 where special category data is involved. Because the controller sets the purpose, it is typically best placed to select the basis that fits that purpose. A processor acting on a controller's instructions does not usually select the legal basis for the controller's processing. The specific basis depends on the context and should be assessed individually.
How is this handled where two or more organisations jointly decide the purposes and means?
Where more than one organisation jointly determines the purposes and means, they may be joint controllers, which typically triggers a requirement to arrange transparently between themselves their respective responsibilities for compliance. Joint control does not require identical or equal involvement, and the analysis focuses on whether the parties jointly influence the purpose and essential means. The allocation of responsibilities should be assessed on the facts of each arrangement and reflected in a suitable agreement, verifying the applicable requirements against the current official text.

Common misconceptions

Whoever a contract names as the processor is definitively the processor for GDPR purposes.
Role status is a functional determination based on who actually determines the purposes and means. Contractual labels are relevant evidence but are not decisive; an entity described as a processor that in fact determines purposes or essential means may be treated as a controller. The assessment is fact-specific.
A processor can never make any decisions about how personal data is processed.
Guidance generally recognises that a processor may determine certain non-essential (often technical or operational) means, while decisions on purposes and essential means are typically reserved to the controller. The precise boundary between essential and non-essential means can involve some uncertainty and depends on the circumstances.
Sharing personal data with another organisation automatically makes the parties joint controllers.
Joint controllership arises where entities jointly determine the purposes and means; it does not follow automatically from data sharing. Depending on the facts, the relationship may instead be controller-to-controller, controller-to-processor, or joint controllership, and this should be assessed for the specific processing activity.

Best practices

Map each processing activity and identify, on the facts, who determines its purposes and its essential means, rather than relying on the labels used in commercial documentation.
Assess essential means (such as which data, which data subjects, retention periods, and access) separately from non-essential means when deciding whether an entity is acting as a controller or a processor.
Where roles may be shared, evaluate whether the arrangement amounts to joint controllership and, if so, put in place an arrangement setting out respective responsibilities.
Ensure that a processor's activities remain within documented instructions, and monitor for any drift where a processor begins determining purposes or essential means, which could change its role.
Document the reasoning behind each role determination so it can be justified and revisited if the processing activity or relationship changes.
Verify role classifications against the current official GDPR text and applicable regulatory guidance, and reassess where regulators or case law refine the boundary between controller and processor.