Artifact GuideUKController and Processor Status

UK GDPR Controller and Processor Status

Classify each processing activity from the parties' actual decisions. Contract labels help describe the arrangement but do not decide UK GDPR status.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

Roles are assigned for a particular processing activity, not permanently to an organisation. A determines why and the of processing; determine those matters together; a handles personal data on documented instructions for a controller. The same company can be a controller for one use and a processor for another.

Section 1

What should teams decide about Controller and Processor Status under the UK GDPR?

Define one processing activity at a time, then ask who decides why it happens and the : which personal data and people are in scope, who receives the data, how long it is kept, and the main processing operations. A party that makes those decisions is a . Parties that make them together are . A party that processes only on another controller's documented instructions is a .

The same organisation can hold different roles for different activities. For example, a hosting provider may be a for customer content but a for its own workforce administration or independently determined fraud-prevention processing. Split those activities instead of assigning one label to the entire commercial relationship.

  • : determines purposes and means and remains responsible for lawfulness, transparency, rights, accountability, security, breach decisions, and any required DPIA.
  • : jointly determine purposes and means, transparently allocate responsibilities, make the essence of the arrangement available to people, and cannot prevent a person exercising rights against either .
  • : acts on documented instructions and must comply with Article 28 duties on confidentiality, security, subprocessors, assistance, return or deletion, and audits.
  • Independent controllers: exchange personal data but each determines its own purposes and means; a data-sharing agreement may allocate practical steps but is not an Article 28 contract.
  • A that determines purposes and means contrary to the 's instructions is treated as a controller for that processing.
Section 2

Who should own Controller and Processor Status, and what evidence should prove the decision?

The business owner should describe the service and decisions; privacy or legal should challenge the classification; procurement should align the contract; and engineering or operations should confirm the data flow and instruction controls. Record the conclusion per processing purpose, not only per vendor.

Evidence should include the data-flow map, decision-rights matrix, service description, instructions, Article 28 clause map where applicable, subprocessor list, joint- arrangement where applicable, privacy-notice treatment, and review triggers.

  • List who chooses the purpose, data categories, affected people, recipients, retention, access rules, and material system features.
  • Separate mandatory customer instructions from choices the provider makes for its own purposes.
  • Match each role to the corresponding record of processing activities and public transparency information.
  • Review the classification when purposes, product features, analytics, model training, fraud controls, subprocessors, or onward disclosures change.
Section 3

Which role-classification mistakes should teams check?

A can choose non-essential technical details while remaining a processor, but independent decisions about the purpose or point to status. Commercial influence, access to data, or drafting the contract does not by itself settle the role.

Joint participation does not always mean joint control. The parties must jointly determine purposes and means for the same processing. Sequential or connected processing can still involve separate controllers when each party decides its own purpose and means.

Classify each distinct use. A cloud provider may be a when it stores customer records on instructions and an independent when it uses account contacts for its own billing or fraud controls. The result follows the actual decision rights and processing, not the product label.

  • Do not classify from invoice wording, terms such as "data owner," or a contract recital without testing the actual decisions.
  • Do not treat every service provider as a ; professional advisers and other recipients may act as independent controllers for their own regulated purposes.
  • Do not call parties merely because they share data or benefit from the same project.
  • Do not combine customer-directed processing with the provider's independently determined analytics, advertising, security, or product-development purposes.
Section 4

What changes after the role is decided?

For a -to- activity, Article 28 requires a binding contract or other legal act describing the processing and setting the listed instruction, confidentiality, security, subprocessor, assistance, deletion or return, and audit duties. Controllers must use processors that provide sufficient guarantees.

For joint control, document the transparent allocation of responsibilities and provide the essence to people. For separate controllers, document the disclosure purpose, lawful basis, transparency, security, rights handling, and any transfer restriction without misusing an Article 28 contract.

A general written subprocessor authorisation must require the to tell the about intended additions or replacements so the controller can object. A processor must also tell the controller if, in its opinion, an instruction infringes the UK GDPR or other applicable UK data-protection law.

  • Assign the lawful-basis, notice, rights, DPIA, breach, retention, and Article 30 duties to the activity.
  • Translate duties into contract clauses, operating instructions, access controls, subprocessor approvals, and evidence delivery.
  • Flow the same Article 28 protection into each subprocessor contract; the first remains fully liable to the for its subprocessor's performance.
  • Provide a workable rights and incident path across all parties; contractual allocation does not remove a person's statutory rights.
  • Reopen the decision when actual practice diverges from the documented instructions or arrangement.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for joint-controller arrangements, processor guarantees and clauses, subprocessor authorisation and liability, unlawful-instruction warnings, and processing under authority.
legislation.gov.uk
Referenced sections
  • Binding definitions and duties for controllers, joint controllers, processors, subprocessors, and people acting under a controller's or processor's authority.
ico.org.uk
Referenced sections
  • ICO guidance supports controller and processor status decisions by defining each role and explaining role-specific UK GDPR responsibilities.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.