A controller decides the purposes and essential means of processing; a processor processes personal data on a controller's behalf; joint controllers jointly determine the purposes and means for the relevant processing.
This answer helps document the role boundary, decide when Article 28 processor terms or an Article 26 joint-controller arrangement is needed, and keep records that explain the decision.
Under the EU GDPR, the role label follows the actual processing facts, not the commercial title in a contract. Decide the role for each processing activity: who determines the purpose, who decides the essential means, whether another party processes only on documented instructions, and whether two or more parties jointly determine the purposes and means.
Side-by-side comparison
GDPR processor vs controller: practical role differences
This matrix helps route a processing activity to accountability, Article 28 terms, or joint-controller Article 26 allocation.
A supplier is not automatically a because it chooses hosting architecture, security tooling, or operational details, but it may become one if it decides its own purpose or essential means.
Keep purpose-and-means analysis, lawful-basis and transparency evidence, Article 30 records, due diligence, and Article 26 arrangements where joint control exists.
Article 28 terms should be in place before the processor starts acting on behalf of the , because the processing must already be governed by a binding contract or legal act.
A has direct GDPR duties, including instruction, confidentiality, security, , recordkeeping, cooperation, and audit-support duties. Under Article 28(10), a processor that determines purposes and means is treated as a for that processing.
A remains accountable for the role decision and for its own controller duties, including how it allocates responsibilities when it acts jointly with others.
The legal consequences depend on the duty and the actual role. A remains responsible for its direct obligations, and status can attach to processing for which it determines purposes and means.
A supplier is not automatically a because it chooses hosting architecture, security tooling, or operational details, but it may become one if it decides its own purpose or essential means.
Keep purpose-and-means analysis, lawful-basis and transparency evidence, Article 30 records, due diligence, and Article 26 arrangements where joint control exists.
Article 28 terms should be in place before the processor starts acting on behalf of the , because the processing must already be governed by a binding contract or legal act.
A has direct GDPR duties, including instruction, confidentiality, security, , recordkeeping, cooperation, and audit-support duties. Under Article 28(10), a processor that determines purposes and means is treated as a for that processing.
A remains accountable for the role decision and for its own controller duties, including how it allocates responsibilities when it acts jointly with others.
The legal consequences depend on the duty and the actual role. A remains responsible for its direct obligations, and status can attach to processing for which it determines purposes and means.
Short answer: how do you tell a processor from a controller?
A is the party that determines why personal data is processed and the essential means of that processing. A is a separate party that processes personal data on behalf of the controller and must not use the data for its own purposes outside the controller's instructions.
The EDPB treats the concepts as functional: the analysis should follow the actual role each party plays in the specific processing operation. Contract wording helps, but it is not enough if the operational facts show that a party decides purposes or essential means. Union or Member State law can also determine the or set the criteria for nominating one.
Start with the specific processing activity, not the whole vendor, group company, or product.
Label a party as when it decides the purpose or essential means of that processing.
Label a party as when it is separate from the and acts on the controller's behalf under instructions.
Treat a that starts using the data for its own purposes as a for that processing.
Do not treat employees or internal teams as separate processors merely because they handle personal data under the organisation's authority.
What is the practical GDPR difference between a and a ?
The determines the purpose and essential means and must be able to demonstrate compliance for that processing. The acts on the controller's behalf and needs Article 28 terms, documented instructions, security measures, controls, assistance duties, deletion or return rules, and audit support.
EDPB Guidelines 07/2020 explain that role labels are functional and must be assessed against the actual processing activity.
Question 2
When do Article 28 processor terms apply?
Article 28 applies when processing is carried out on behalf of a . The controller must use only processors that provide sufficient guarantees for appropriate technical and organisational measures, and the processing must be governed by a binding contract or other legal act.
The Article 28 record should identify the subject matter, duration, nature, purpose, personal-data types, data-subject categories, obligations and rights of the , and the concrete duties that make the instructions operational. A generic data-processing addendum may not supply that detail. If a processor goes beyond the controller's instructions and determines the purposes and means, Article 28(10) treats it as a controller for that processing, without excusing the departure from the contract or instructions.
Keep documented instructions, including instructions on international transfers where relevant.
Record confidentiality duties for authorised personnel and the Article 32 security measures required for the service.
Track prior specific or general written authorisation for subprocessors and objections to changes.
Document assistance with data-subject rights, security, breach notification inputs, DPIAs, and prior consultation where applicable.
Keep deletion or return evidence at service end and audit-support evidence showing the made compliance information available.
Article 28 sets processor-selection requirements and mandatory processor-contract terms, including instructions, subprocessors, assistance, deletion or return, and audits.
EDPB Guidelines 07/2020 say processing agreements should include concrete information on how GDPR requirements and security levels will be met.
Question 3
When is it joint controllership instead of a processor relationship?
exists where two or more parties jointly determine the purposes and means of the same processing. The EDPB explains that joint participation may come from a common decision or from converging decisions that complement each other and are necessary for the processing in a way that has a tangible impact on purposes and means.
Article 26 requires joint controllers to transparently determine their respective GDPR responsibilities by arrangement, especially for data-subject rights and Articles 13 and 14 information duties. The essence of that arrangement must be made available to data subjects, and data subjects may exercise their rights against each joint .
Use Article 26 when parties jointly determine purposes and means; do not force the relationship into Article 28 if both parties make -level decisions.
Allocate rights handling, privacy information, security, breach notification, DPIAs, use, transfers, and authority communications where those issues are relevant to the joint processing.
Make the arrangement reflect the real roles and relationships, not only a preferred contracting model.
Keep the internal allocation evidence, because the EDPB treats that analysis as part of accountability documentation.
Remember that an Article 26 arrangement allocates tasks between joint controllers but does not prevent data subjects from contacting either .
Article 26 defines joint-controller arrangements, responsibilities, data-subject access to the arrangement essence, and rights against each joint controller.
EDPB Guidelines 07/2020 explain common and converging decisions, practical allocation of joint-controller duties, and recommended documentation.
Question 4
What evidence should teams keep for the role decision?
Keep evidence at processing-activity level. A useful role file shows the purpose, essential means, party responsibilities, instructions, contract or arrangement, relevant records of processing, and the trigger for reassessing the label.
Article 30 records support this work. Where the recordkeeping duty applies, controllers must record processing activities under their responsibility, while processors must record categories of processing carried out on behalf of each . Article 30(5) provides a limited exception for an enterprise or organisation employing fewer than 250 persons only where the processing is unlikely to result in a risk to people's rights and freedoms, is occasional, and does not include Article 9 special-category or Article 10 criminal-offence data. RoPA entries should preserve the controller, , joint-controller, and distinctions instead of collapsing every party into a vendor list.
Role assessment showing who decides the purpose and essential means for the specific processing activity.
Article 28 contract or legal act, documented instructions, approvals, assistance logs, deletion or return record, and audit evidence for relationships.
Article 26 arrangement, responsibility allocation, contact point if designated, and published essence evidence for joint- relationships.
RoPA entry with purposes, data-subject categories, personal-data categories, recipients, transfers, retention where possible, and Article 32 measure description where possible.
RoPA entry with each on whose behalf the processor acts, processing categories for each controller, transfers where applicable, and security-measure description where possible.
The DPC guidance explains controller and processor RoPA content, standalone record quality, and the need to make records available to the supervisory authority on request.
Recommended next step
Document controller, processor, and joint-controller boundaries
Sorena can help turn this GDPR role analysis into cited role records, Article 28 checks, Article 26 responsibility maps, and RoPA evidence requests.
Articles 24 and 30 require controller accountability measures and processing records; Article 26 requires joint controllers to determine their respective GDPR responsibilities by arrangement.
Articles 28 to 30 set direct processor duties for instructions, confidentiality, security, subprocessors, records, cooperation, audits, and controller status when a processor determines purposes and means.
Articles 5 and 24 establish controller accountability; Article 26 requires joint controllers to determine their respective responsibilities in a transparent manner.