Skip to main content
Category: Controller & Processor Roles

Non-Essential Means

Also known as: non-essential means of processing
Simply put

In data protection, 'means' refers to how personal data is processed. Non-essential means are the more practical, technical implementation choices about how processing is carried out, as distinct from the fundamental decisions that define the processing itself. Because they are practical rather than defining, non-essential means may in some cases be left to a processor to decide, subject to the controller's overall responsibility.

Formal definition

The concept of 'means' of processing is generally divided into 'essential means' and 'non-essential means'. This distinction is not set out in the text of the GDPR itself but is drawn from European Data Protection Board guidance on the concepts of controller and processor, which separates decisions reserved to the controller from those that may be delegated. Essential means are typically understood as decisions closely linked to the purpose and core scope of processing (for example, which categories of personal data are processed, the categories of recipients, or the retention period), and are reserved to the controller. Non-essential means concern more practical aspects of implementation (for example, the choice of particular hardware, software, or detailed security measures) and, in principle, may be left to a processor to determine, provided the processing remains governed by the controller's instructions and an appropriate arrangement under the relevant controller-processor provisions. The precise boundary between essential and non-essential means depends on the facts of a given processing operation and is assessed case by case; because the distinction derives from EDPB guidance rather than the Regulation's operative text, readers should verify the current guidance and note that regulator interpretation may evolve. The plain-language sense of 'non-essential' (meaning not absolutely necessary) is consistent with, but should not be substituted for, this data protection-specific usage.

Why it matters

The distinction between essential and non-essential means is central to allocating responsibility between controllers and processors. Under European Data Protection Board guidance, the decisions that define the processing, such as which categories of personal data are involved, who the recipients are, and how long data is retained, are treated as essential means and are reserved to the controller. Non-essential means, being the more practical implementation choices, may in principle be delegated to a processor. Getting this allocation right matters because it shapes who bears which obligations and who is answerable to individuals and regulators for a given decision.

In practice, the boundary is often where disputes and compliance risk concentrate. Where a service provider is given latitude over hardware, software, or detailed security configuration, it may be acting within the scope of delegated non-essential means; but if the same provider begins to influence the purpose or core scope of processing, it may cross into essential-means territory and potentially into controller (or joint controller) status. Misjudging that line can leave organisations with contractual arrangements that do not match the actual reality of the processing, which is itself a source of exposure.

Because this distinction derives from EDPB guidance rather than the operative text of the GDPR, its precise application depends on the facts of each processing operation and is assessed case by case. Regulator interpretation may evolve, so organisations should verify the current guidance rather than treat any single characterisation of the boundary as settled.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams use the essential/non-essential distinction to map which decisions their organisation must retain as a controller and which can properly be delegated to a service provider. This informs role classification, the drafting of processing arrangements, and the assessment of whether a vendor's discretion remains within delegated non-essential means. Because the boundary is fact-specific, these assessments should be documented and revisited as processing arrangements change.
Legal and Contracting Teams
Lawyers negotiating controller-processor arrangements rely on the distinction to define the scope of a processor's permitted discretion. Where non-essential means are being delegated, the arrangement should reflect that the processing remains under the controller's instructions. Legal teams should also watch for situations where a provider's practical latitude edges toward influencing purpose or core scope, which may raise questions about controller or joint controller status.
Engineers and Technical Architects
Technical staff choosing hardware, software, or detailed security measures are often the parties exercising delegated non-essential means in practice. Understanding this concept helps them recognise the point at which an implementation choice starts to shape the defining features of processing, such as which data categories are handled or how long data is kept, where the decision may instead belong to the controller as an essential means.
Vendors and Service Providers
Organisations acting as processors need to understand where their operational discretion is properly confined to non-essential means and where crossing into essential means could alter their legal role. This affects how they position their services, structure their contracts, and manage the risk of inadvertently taking on controller obligations. Given that the distinction rests on EDPB guidance and is assessed case by case, providers should track evolving regulator interpretation.

Inside Non-Essential Means

Essential Means
Under EDPB Guidelines 07/2020 on the concepts of controller and processor, essential means are decisions closely linked to the purpose and scope of processing, such as which categories of data are processed, which data subjects are affected, the duration of retention, and who has access. These are reserved to the controller and are generally not delegable to a processor.
Non-Essential Means
As distinguished in EDPB Guidelines 07/2020, non-essential means concern the more practical aspects of implementing the processing, for example, the choice of particular hardware or software, or specific security measures at a technical detail level. These implementation choices may be left to the processor, provided the processor acts on the controller's documented instructions and within the terms of an Article 28 arrangement.
Relevance to Role Determination
Whether an entity determines the essential means (alongside the purposes) is a key indicator of controller status; leaving only non-essential means to a party is typically consistent with a processor role. The distinction supports the functional, fact-based assessment of controller versus processor rather than relying solely on contractual labels.
Guidance-Derived, Not Regulation Text
The specific 'essential/non-essential means' terminology comes from EDPB guidance interpreting Articles 4(7) and 28 rather than appearing verbatim as a defined term in the GDPR articles. It should be read as interpretive guidance that may evolve and that regulators or courts could apply with some variation.

Common questions

Answers to the questions practitioners most commonly ask about Non-Essential Means.

Is 'non-essential means' a term without any basis in GDPR guidance?
No. While the term does not appear as a defined term in the operative text of the GDPR itself, the concept is expressly addressed in the EDPB's Guidelines 07/2020 on the concepts of controller and processor. Those guidelines distinguish 'essential means', decisions closely linked to the purpose and scope of processing, which are reserved to the controller, from 'non-essential means,' which concern more practical aspects of implementation that may be left to the processor. Readers should treat the concept as originating in EDPB guidance rather than the Regulation's articles, and should consult the current version of the guidelines directly.
Does the concept of 'non-essential means' have no bearing on who is a controller and who is a processor?
On the contrary, it is directly relevant to that classification. Under the EDPB's approach in Guidelines 07/2020, the ability to determine the 'essential means' of processing is one of the markers of controllership, whereas decisions over 'non-essential means', the practical implementation choices, can generally be delegated to a processor without altering the parties' respective roles. The distinction therefore helps analyse whether an actor is exercising the kind of decision-making that characterises a controller. The assessment remains fact-specific, and the boundary between essential and non-essential decisions can require case-by-case judgement.
What types of decisions typically fall on the 'non-essential means' side of the line?
Under the EDPB's framing, non-essential means generally relate to the more practical aspects of implementing the processing rather than to its purpose or core parameters. These are the choices that may be left to a processor's discretion. Because the guidelines describe this as a matter of degree rather than a fixed list, the classification of any particular decision should be assessed against the specific processing arrangement, and organisations should document their reasoning rather than rely on generic categorisation.
How should a controller record decisions about non-essential means in its contractual arrangements?
Where a processor is engaged, the arrangement should be governed by a written contract or other legal act meeting the requirements set out in Article 28. That instrument typically sets out the subject matter, duration, nature and purpose of the processing, and the controller's instructions. To the extent a processor is left to determine non-essential means, it is generally advisable to make clear in the documentation which practical choices fall within the processor's discretion and which remain subject to the controller's instructions, so that the allocation of responsibilities is transparent and auditable.
What happens if a processor starts making decisions about essential means?
If an actor engaged as a processor begins determining essential means, decisions bound up with the purpose and scope of the processing, it may, on the facts, be acting as a controller (or joint controller) for those aspects rather than merely as a processor. Roles under the GDPR are determined by the actual influence over the processing, not solely by contractual labels. Organisations should therefore monitor how discretion is exercised in practice and reassess the classification where a party's role appears to extend beyond implementation choices. This is a fact-sensitive analysis.
How can an organisation assess whether a given implementation choice is essential or non-essential in practice?
A practical approach is to consider how closely the decision is tied to the purpose of the processing and to core parameters of that processing, drawing on the framework in EDPB Guidelines 07/2020. Decisions that shape why and, in broad terms, how the processing takes place tend toward the essential category, while narrower operational choices tend toward the non-essential. Because the guidelines present this as a spectrum rather than a bright line, organisations should document their assessment, revisit it if the arrangement changes, and consult the current guidance, as regulatory interpretation may develop over time.

Common misconceptions

The GDPR text itself defines 'non-essential means' as a standalone term.
The distinction between essential and non-essential means is articulated in EDPB Guidelines 07/2020 on the concepts of controller and processor, interpreting the GDPR's definitions rather than appearing as a defined term in the Regulation's articles. Practitioners should cite the guidance and verify against the current official text.
Leaving non-essential means to a party makes that party a joint controller.
Determining only non-essential (practical, implementation-level) means is generally consistent with a processor role. Controller or joint controller status typically turns on influence over purposes and essential means, and each arrangement should be assessed on its facts.
A processor deciding technical details always breaches the requirement to follow controller instructions.
The EDPB guidance recognizes that certain non-essential implementation choices may legitimately be left to the processor. This must still operate within the controller's documented instructions and an Article 28 arrangement, and the boundary between essential and non-essential can be uncertain in practice.

Best practices

When mapping data flows, distinguish which decisions are essential means (purpose-linked, reserved to the controller) and which are non-essential means (practical implementation) to support a defensible controller-versus-processor determination.
Document in the Article 28 arrangement which technical and organizational implementation choices the processor is permitted to make, and ensure they remain within the controller's documented instructions.
Assess roles on the actual facts and functions rather than on contractual labels alone, since delegating only non-essential means typically indicates a processor role.
Treat the essential/non-essential distinction as EDPB guidance (Guidelines 07/2020) rather than a defined statutory term, and revisit your analysis if the guidance is updated.
Where the line between essential and non-essential means is unclear for a specific decision, record your reasoning and consider whether the decision affects purpose or scope, flagging any residual uncertainty.
Verify any article references and the current wording of the EDPB guidance against the official published text before relying on them in a compliance program.