Processing on Behalf of a Controller
Processing on behalf of a controller is when one organisation (the processor) handles personal data for another organisation (the controller), acting only on that controller's instructions rather than for its own purposes. For example, a company may use an external service provider to process personal data that the company has decided to collect and use. In most cases this relationship must be governed by a written contract between the two parties.
Processing on behalf of a controller describes the activity of a processor, defined as a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller and acts solely under the controller's documented instructions. This relationship is central to the controller-processor distinction: the processor does not determine the purposes and means of the processing but carries them out as directed. Where a controller engages a processor, a written data processing contract is generally required to govern the terms and conditions of the processing; under the UK GDPR and EU GDPR this obligation is commonly associated with Article 28 (readers should verify the precise article against the current official text). An organisation may act as both controller and processor for different processing activities, and where it does, it should ensure its systems and procedures distinguish between the personal data processed in each capacity. Note that the precise allocation of controller versus processor status is a factual and functional assessment that can be subject to regulatory guidance and may vary between the EU and UK regimes and across member state implementations.
Why it matters
The concept of processing on behalf of a controller underpins how accountability is allocated across the many organisations that touch personal data in a typical supply chain. When one organisation decides why and how personal data should be used and another simply carries out that processing under instruction, the law treats them differently: the controller bears primary responsibility for determining the purposes and means, while the processor must generally confine itself to acting on documented instructions. Getting this distinction wrong can leave both parties uncertain about their obligations and can expose an organisation to compliance risk if it assumes it is a mere processor when its conduct in fact makes it a controller.
The requirement for a written contract is a practical anchor for this relationship. According to guidance from EU and UK data protection authorities, controllers who engage processors are generally obliged to enter into a data processing contract governing the terms and conditions of the processing. This contract is the instrument through which the controller documents its instructions and through which the processor accepts its constraints. Without it, the relationship may not be adequately governed, and responsibilities for matters such as security and the scope of permitted processing may be left ambiguous.
Because the allocation of controller versus processor status is a factual and functional assessment rather than a matter of self-labelling, organisations should assess their real role in each processing activity. The same organisation may be a controller for some activities and a processor for others, and regulators have noted that where this is the case the organisation should ensure its systems and procedures distinguish between the personal data processed in each capacity. Note that regulatory guidance on this assessment continues to develop and the position may vary between the EU and UK regimes and across member state implementations; readers should verify the current guidance and article references against the official text.
Who it's relevant to
Inside Processing on Behalf of a Controller
Common questions
Answers to the questions practitioners most commonly ask about Processing on Behalf of a Controller.