Skip to content

Controller or Processor? A Practical EU Activity Test

Use a per-activity test to decide controller, processor or joint control, then choose the right GDPR agreement and record the reasons clearly.

An isometric planning hub routes data blocks from a decision desk to a separate service unit.
By AI Priority Map Editorial

Quick Answer: Decide controller or processor for one processing activity, not for the company as a whole. The party choosing the purpose and essential means is a controller; a separate party acting on documented instructions is a processor. If both make indispensable converging decisions, assess joint control and record the contract route.

Last updated: 26 August 2026.

A supplier's contract may call it a processor, but that label does not settle the role. Under the GDPR, controller, processor and joint-controller status follow what each party actually decides and does. The reliable starting point is one narrowly described processing activity, followed by a record of who chose its purpose and essential means.

Classify the activity, not the company

A GDPR role belongs to a processing activity. It is not a permanent badge attached to a business, supplier or sector.

Begin with a sentence that has a clear verb, data and outcome: “The service company stores the client business's customer support messages so authorised staff can answer them.” That is narrow enough to test. “The supplier handles our data” is not, because hosting, analysing, reusing and disclosing the same records may have different purposes and different role outcomes.

The same organisation can therefore hold several roles at once. It may be controller for its own account administration, processor while storing support messages on a client's instructions, and controller again if it separately uses those messages to build an independent industry benchmark. The roles do not cancel each other; the activities need separate rows in the assessment.

This functional approach follows the GDPR definitions. A controller determines the purposes and means of processing, alone or jointly. A processor is a separate natural or legal person, public authority, agency or other body that processes personal data on the controller's behalf 1. The EDPB describes these concepts as autonomous and functional: contractual wording can help explain the relationship, but cannot override the facts 2.

The three outcomes at a glance

There are three branches, not two. First ask whether one party controls the purpose and essential means. Then ask whether another separate party acts on that party's documented instructions, or whether both parties made decisions that are jointly decisive.

One processing activity is defined before the parties' decisions about purpose and essential means are tested 1,2. When one party sets those features and another separate party acts on documented instructions, the route is controller and processor; when each pursues its own purpose, they are separate controllers. Indispensable common or converging decisions point to joint control, while a party that does not process the data has no role for that activity. The factual outcome is recorded and routed to the matching Article 28, Article 26 or controller-to-controller terms.

Outcome for this activityFactual boundaryImmediate document route
Separate controllersEach party determines its own purpose and essential means for its own processingController-to-controller terms appropriate to the disclosure and each party's duties
Joint controllersCommon or converging decisions by both parties are indispensable to the processing as designedA transparent Article 26 arrangement allocating responsibilities
Controller and processorOne party determines purpose and essential means; a separate party processes on its behalf and within documented instructionsAn Article 28 controller-processor agreement

“Both benefit” does not establish joint control. Nor does “the supplier is technical” establish processing on behalf. The deciding evidence is the influence each party has over the purpose and the essential features of the activity.

The outcome may also be “neither” for a party that does not process the personal data in question. Recording that conclusion prevents the assessment from assigning roles merely because an organisation appears in the surrounding commercial arrangement.

Purpose and essential means identify the controller

The controller decides why the activity happens and the essential shape it takes. These decisions define the processing rather than merely implementing it.

Purpose is the intended objective. “Keep the service available” is an operational description; “store customer messages so the client can respond to support requests” identifies why the data is processed. If a supplier adds “analyse every client's messages to develop our own market product”, it has introduced a separate purpose. For that new use, it cannot remain merely the client's processor by repeating the original contract label.

Essential means concern choices closely tied to the purpose and scope. The EDPB points to matters such as the personal data processed, the people concerned, how long processing lasts and who may receive or access the data. These decisions are commonly reserved to the controller because changing them changes what the activity is 2.

DecisionUsually essential or non-essential?What to record
Why the data is processedPurpose; controller-levelThe concrete objective and which party approved it
Which people and data are includedEssential meansCategories, exclusions and who set them
Permitted recipients or access groupsEssential meansThe authorised audience and decision owner
Duration or deletion endpointEssential meansThe business or legal reason and who chose it
Hardware or hosting configuration within requirementsUsually non-essential implementationSupplier choice, constraints and evidence
Detailed technical security implementationOften non-essential implementationRequired outcome, supplier design and assurance evidence

The table is a starting test, not an automatic classification engine. Context matters. A technical choice can become essential when it determines, for example, whether data is disclosed to a new recipient or used beyond the agreed purpose. Record the consequence of the choice, not the vocabulary used to describe it.

Implementation choices can remain with a processor

A processor does not need to be a mindless conduit. It may use expertise and discretion over non-essential means while still acting on behalf of the controller.

The controller can set the purpose, data scope, authorised users, retention outcome and required security level, while the processor chooses suitable infrastructure, backup scheduling and detailed protective controls. Those implementation choices allow the service to function. They do not necessarily give the processor authority to redefine the activity.

The boundary is the documented instruction. An instruction may establish outcomes and limits without dictating every technical step. Article 28 requires the processor to act only on documented instructions, subject to the limited case where Union or Member-State law requires processing. It also gives the processor direct duties concerning matters such as confidentiality, security, subprocessors, assistance, deletion or return, and audit information 1.

Three questions expose a supposed implementation choice that has gone further:

  • Does the choice introduce a new reason for using the data?
  • Does it materially change whose data, which data, recipients or duration are involved?
  • Could the client prohibit the choice while retaining the service it asked for?

If the first two answers point to independent decision-making, split out that use and assess it as a separate activity. If the client cannot meaningfully define or stop a use that serves the supplier's own objective, the word “processor” is unlikely to describe that use.

Joint control is a distinct third branch

Joint control arises when two or more parties jointly determine the purposes and means. It does not require identical influence, equal access to data or a single written decision.

The clearest case is a common decision: both parties design and approve the activity together. Joint control can also follow from converging decisions. The EDPB's test asks whether the decisions complement each other and are necessary for the processing to occur in the way it does. If each party's participation is indispensable to that design, their influence may be jointly decisive 2.

Commercial cooperation alone is too weak. Two companies can benefit from the same transaction while independently deciding what they do with personal data. A supplier can also deliver an important service without sharing control if the client sets the purpose and essential means and the supplier remains inside instructions.

Test converging decisions in two passes. First identify each party's decision, rather than its service, assets or commercial interest. Then ask whether those decisions complement one another and whether each is necessary for the processing to occur in the designed form. The relevant dependency is between decisions about purpose or essential means, not simply between businesses.

That distinction prevents a common false positive. A client's decision to run a support channel and a supplier's decision to sell a standard storage service may be commercially necessary to the transaction, yet the supplier may still only implement the client's purpose within instructions. By contrast, if each party decides a different essential part of a shared programme and neither design can operate without the other, the decisions may converge into joint control. Economic dependence, data access and mutual advantage cannot substitute for that analysis.

Where joint control exists, Article 26 requires a transparent arrangement allocating the parties' respective responsibilities, particularly for data-subject rights and privacy information. The arrangement must reflect the real relationship, its essence must be available to data subjects, and a data subject may exercise rights against each joint controller 1.

One service relationship can contain all three routes

Consider an abstract service company that receives a client business's customer messages. The commercial relationship is one contract, but the data uses inside it are not necessarily one activity.

Activity A: instructed message storage. The client chooses the support purpose, message categories, authorised staff and deletion period. The service company configures infrastructure and backups within those requirements. On those facts, the client is controller and the service company is processor. Their route is an Article 28 agreement.

Activity B: an independent benchmark. The service company decides to analyse message content across clients to create a benchmark that serves its own objective. The client did not instruct that purpose or choose its essential means. The service company is a controller for the benchmark activity, even if it remains processor for Activity A. The parties must decide whether the disclosure to that independent controller is lawful and use controller-to-controller terms rather than trying to stretch the Article 28 label over the new use.

Activity C: a jointly designed shared response programme. Both parties decide the programme's purpose, target group, data fields and recipients; neither design works without the other's complementary decision. If those decisions are truly indispensable, the parties may be joint controllers and need an Article 26 arrangement. If one party merely supplies technical capacity within the other's design, the branch returns to controller and processor.

This scenario shows why a relationship-level question produces unreliable answers. The useful question is not “What is the service company?” It is “What role does each party have for Activity A, B or C, and why?”

Route the result to the right terms

Classification is incomplete until it changes the paperwork. Each branch needs a document that matches the facts rather than a preferred label.

For controller and processor, Article 28 requires a binding contract or other legal act. It must cover the subject matter and duration, nature and purpose, types of personal data, categories of data subjects, and the controller's rights and obligations. It must also contain the required operational terms, including documented instructions and the processor's duties. The detailed drafting procedure belongs in a separate task; the role assessment should at least identify the correct route and owner.

For joint controllers, the Article 26 arrangement must transparently divide responsibilities and present the real relationship. Avoid allocating every visible duty to one party while the other retains decisive control without corresponding accountability. The arrangement can designate contact points, but it cannot remove a person's ability to exercise rights against either joint controller 1.

For separate controllers, do not use an Article 28 agreement merely because data moves between them. Use controller-to-controller terms that support the actual disclosure: identify each purpose, the basis and expectations for sharing, transparency ownership, security, retention, rights handling, onward disclosure and incident cooperation. The GDPR does not turn those terms into a new role; their job is to make two independent sets of duties workable.

Recorded resultUseDo not substitute
Controller to processorArticle 28 contract or other binding legal actA generic confidentiality clause
Joint controllersArticle 26 arrangement reflecting actual responsibilitiesAn Article 28 agreement that pretends one joint decision-maker only follows instructions
Separate controllersController-to-controller sharing terms appropriate to the activityAn Article 28 label or an Article 26 arrangement without joint determination

Keep a reusable decision record

A short role record is more valuable than an unsupported conclusion. It lets a reviewer trace the facts, tests, result and agreement route without reconstructing the project from email.

Use one row per processing activity. Where a service contains distinct purposes, create more rows rather than compressing them into one answer.

FieldWhat the record should say
ActivityA narrow description of the data action and outcome
PurposeWhy processing occurs and who decided it
Essential meansData, people, recipients, duration and other defining choices; decision owner for each
InstructionsScope, limits, change process and evidence of documented instructions
Decisions retained by each partyController choices and processor implementation discretion
Joint-control testAny common or converging indispensable decisions; why benefit alone is insufficient
EvidenceContract schedules, design decisions, approvals, system settings and meeting records
Role outcomeRole for each party for this activity, including any split use
Document routeController-to-controller terms, Article 26 arrangement or Article 28 agreement
Owner and change triggerPerson responsible for review and facts that require reassessment

The reasoning matters more than the final noun. “Processor because the contract says so” records no test and will fail as soon as the service changes. A useful conclusion reads: “Processor for instructed storage because the client sets the purpose, data scope, users and deletion endpoint; supplier discretion is limited to infrastructure and detailed controls.”

Attach evidence at the level claimed. A contract schedule can show instructions, while technical settings may show actual access and reuse. The controller should have enough information to understand the processor and subprocessor chain and assess whether the required guarantees remain available; responsibility does not disappear merely because processing sits several contracts away 4.

Immediate duties follow the role

The controller remains accountable for the lawfulness and design of the processing. It needs a lawful basis, appropriate transparency, data minimisation, rights handling, security, retention and evidence that its chosen processors provide sufficient guarantees. Appointment does not transfer the controller's responsibility to the supplier 1.

A processor must stay within documented instructions, ensure authorised people are bound to confidentiality, apply appropriate security and respect the agreed subprocessor route. It must assist the controller where Article 28 requires, notify the controller after becoming aware of a personal data breach without undue delay, deal with data at the end of the service as instructed, and provide information needed to demonstrate compliance 1.

Joint controllers remain responsible for the areas assigned to them and for making the allocation transparent. Their arrangement should say who supplies privacy information, receives and routes requests, manages security and incidents, and maintains the underlying record. Allocation supports delivery; it does not erase the statutory rights a person can exercise against each party.

Separate controllers each carry their own controller duties. One controller should not assume that the other's privacy notice, lawful basis or retention choice automatically covers its separate processing. The sharing terms should expose the seam between those responsibilities before a request, complaint or incident does.

Reassess whenever the facts move

Role analysis is a maintained record, not a one-time procurement answer. A supplier that began inside instructions can gain a new purpose, new recipients or a broader data population through an apparently small feature change.

Set change triggers around the facts that determine roles: purpose, data categories, affected people, recipients, retention, authorised users, integrations, subprocessors, independent reuse, model or training uses, and the boundary of documented instructions. A material change should pause approval until the owner has re-run the activity test and updated the agreement route.

A periodic review can catch quieter drift, but it should not replace event-based review. Compare the record with current system settings, product descriptions, instructions and data flows. The EDPB's small-business guidance likewise starts with the real decision-making relationship rather than the title used by the parties 3.

Finish each review with an explicit outcome: role for each party, evidence, required document, remediation owner and date of next trigger. If the answer is uncertain because the activity is described too broadly, narrow the activity. If uncertainty remains because each party appears indispensable to the purpose or essential means, examine joint control instead of forcing the facts into a binary choice.

Frequently Asked Questions

Can a contract decide whether a supplier is a processor?
No. A contract records the parties' intended relationship, but the facts decide the GDPR roles. Examine one processing activity and identify who determines its purpose and essential means. If the supposed processor makes those decisions for its own objective, calling it a processor does not prevent it from being a controller for that processing.
Can the same business be both controller and processor?
Yes, across different processing activities. A business may determine why it processes its own workforce or customer data, making it controller there, while processing another organisation's data only on documented instructions in a separate service. Record each activity separately; do not give the organisation one permanent role for every use of personal data.
Does choosing software make a supplier a controller?
Usually not by itself. A processor may choose non-essential implementation details such as suitable hardware, software or practical security measures while staying within the controller's purpose, scope and instructions. The answer changes if the choice determines an essential feature of the processing or enables the supplier to pursue an independent purpose.
When are two parties joint controllers?
Joint control can arise when both parties make a common decision, or when their converging decisions are complementary and indispensable to the processing as designed. Shared commercial benefit or ordinary cooperation is not enough. Map each party's actual influence over the purpose and essential means before deciding whether Article 26 applies.
What if a processor starts using data for its own purpose?
For that additional processing, the supplier crosses into controller territory if it determines the new purpose and essential means. The original instructed service may still be processor activity, so split the analysis rather than relabelling the whole relationship. Stop or regularise the extra use, identify a lawful basis and update transparency and contract records.
Do independent controllers need an Article 28 agreement?
No. Article 28 governs processing by a processor on behalf of a controller. When each party determines its own purpose and essential means, use controller-to-controller terms suited to the sharing instead. Those terms should address lawful disclosure, transparency, security, rights requests, retention and responsibility, without falsely describing one controller as the other's processor.
What must an Article 26 arrangement cover?
Joint controllers must transparently allocate their respective GDPR responsibilities, especially duties concerning data-subject rights and the information required by Articles 13 and 14. The arrangement must reflect the real relationship, and its essence must be made available to data subjects. A person may still exercise rights against each joint controller.
When should a controller-or-processor assessment be repeated?
Repeat it when the activity changes materially: a new purpose, data category, recipient, user group, integration, reuse, model-training use or instruction boundary can change the result. Review the assessment before approving the change, then update the role record, privacy information and agreement route. A calendar review also helps catch gradual factual drift.

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016
  2. 2.Guidelines 07/2020 on the concepts of controller and processor in the GDPREuropean Data Protection Board · 2020
  3. 3.Data controller or data processorEuropean Data Protection Board
  4. 4.Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)European Data Protection Board · 2024

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.