Determination of Purposes and Means of Processing
This is the test used to decide who is legally in charge of a set of personal data activities. Whoever decides both the reasons for processing personal data (the 'why') and the essential ways it will be carried out (the 'how') is generally treated as the controller. An organisation that only follows another's instructions typically acts as a processor rather than making these decisions itself.
Under Article 4 GDPR, a 'controller' is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. In guidance from the EDPB (and previously the Article 29 Working Party) and the ICO, 'purposes' refers to the 'why' of the processing and 'means' to the 'how'. The determination is assessed on the factual reality of the activity rather than on labels adopted by the parties. Regulatory guidance generally distinguishes between essential means, which tend to be reserved to the controller, and non-essential (more technical or operational) means, which a processor may decide. A processor that goes beyond the controller's instructions and itself determines the purposes and means of processing may, in respect of that activity, be treated as a controller. This entry describes the concept at a general level; the precise boundary of what counts as determining 'means' is subject to regulatory guidance that continues to develop, and readers should verify against the current text of the GDPR (or UK GDPR) and applicable regulator guidance.
Why it matters
Determining the purposes and means of processing is the pivotal test that fixes who bears the heaviest legal responsibilities under the GDPR. Controller status carries the primary accountability obligations, including identifying a lawful basis under Article 6, responding to data subject rights requests, and demonstrating compliance. Processor status, by contrast, generally confines an organisation to acting on documented instructions. Getting this classification wrong at the outset can cascade through an entire compliance programme, because contracts, notices, records of processing, and breach-response responsibilities are all allocated according to whether a party is treated as a controller, a joint controller, or a processor.
Who it's relevant to
Inside Determination of Purposes and Means of Processing
Common questions
Answers to the questions practitioners most commonly ask about Determination of Purposes and Means of Processing.