Classify each processing activity from the parties' actual decisions. Contract labels help describe the arrangement but do not decide UK GDPR status.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
Roles are assigned for a particular processing activity, not permanently to an organisation. A determines why and the of processing; determine those matters together; a handles personal data on documented instructions for a controller. The same company can be a controller for one use and a processor for another.
1
Section 1
What should teams decide about Controller and Processor Status under the UK GDPR?
Define one processing activity at a time, then ask who decides why it happens and the : which personal data and people are in scope, who receives the data, how long it is kept, and the main processing operations. A party that makes those decisions is a . Parties that make them together are . A party that processes only on another controller's documented instructions is a .
The same organisation can hold different roles for different activities. For example, a hosting provider may be a for customer content but a for its own workforce administration or independently determined fraud-prevention processing. Split those activities instead of assigning one label to the entire commercial relationship.
: determines purposes and means and remains responsible for lawfulness, transparency, rights, accountability, security, breach decisions, and any required DPIA.
: jointly determine purposes and means, transparently allocate responsibilities, make the essence of the arrangement available to people, and cannot prevent a person exercising rights against either .
: acts on documented instructions and must comply with Article 28 duties on confidentiality, security, subprocessors, assistance, return or deletion, and audits.
Independent controllers: exchange personal data but each determines its own purposes and means; a data-sharing agreement may allocate practical steps but is not an Article 28 contract.
A that determines purposes and means contrary to the 's instructions is treated as a controller for that processing.
Who should own Controller and Processor Status, and what evidence should prove the decision?
The business owner should describe the service and decisions; privacy or legal should challenge the classification; procurement should align the contract; and engineering or operations should confirm the data flow and instruction controls. Record the conclusion per processing purpose, not only per vendor.
Evidence should include the data-flow map, decision-rights matrix, service description, instructions, Article 28 clause map where applicable, subprocessor list, joint- arrangement where applicable, privacy-notice treatment, and review triggers.
List who chooses the purpose, data categories, affected people, recipients, retention, access rules, and material system features.
Separate mandatory customer instructions from choices the provider makes for its own purposes.
Match each role to the corresponding record of processing activities and public transparency information.
Review the classification when purposes, product features, analytics, model training, fraud controls, subprocessors, or onward disclosures change.
Which role-classification mistakes should teams check?
A can choose non-essential technical details while remaining a processor, but independent decisions about the purpose or point to status. Commercial influence, access to data, or drafting the contract does not by itself settle the role.
Joint participation does not always mean joint control. The parties must jointly determine purposes and means for the same processing. Sequential or connected processing can still involve separate controllers when each party decides its own purpose and means.
Classify each distinct use. A cloud provider may be a when it stores customer records on instructions and an independent when it uses account contacts for its own billing or fraud controls. The result follows the actual decision rights and processing, not the product label.
Do not classify from invoice wording, terms such as "data owner," or a contract recital without testing the actual decisions.
Do not treat every service provider as a ; professional advisers and other recipients may act as independent controllers for their own regulated purposes.
Do not call parties merely because they share data or benefit from the same project.
Do not combine customer-directed processing with the provider's independently determined analytics, advertising, security, or product-development purposes.
For a -to- activity, Article 28 requires a binding contract or other legal act describing the processing and setting the listed instruction, confidentiality, security, subprocessor, assistance, deletion or return, and audit duties. Controllers must use processors that provide sufficient guarantees.
For joint control, document the transparent allocation of responsibilities and provide the essence to people. For separate controllers, document the disclosure purpose, lawful basis, transparency, security, rights handling, and any transfer restriction without misusing an Article 28 contract.
A general written subprocessor authorisation must require the to tell the about intended additions or replacements so the controller can object. A processor must also tell the controller if, in its opinion, an instruction infringes the UK GDPR or other applicable UK data-protection law.
Assign the lawful-basis, notice, rights, DPIA, breach, retention, and Article 30 duties to the activity.
Translate duties into contract clauses, operating instructions, access controls, subprocessor approvals, and evidence delivery.
Flow the same Article 28 protection into each subprocessor contract; the first remains fully liable to the for its subprocessor's performance.
Provide a workable rights and incident path across all parties; contractual allocation does not remove a person's statutory rights.
Reopen the decision when actual practice diverges from the documented instructions or arrangement.
Binding source for joint-controller arrangements, processor guarantees and clauses, subprocessor authorisation and liability, unlawful-instruction warnings, and processing under authority.
Binding definitions and duties for controllers, joint controllers, processors, subprocessors, and people acting under a controller's or processor's authority.