Controller or Processor? A Practical EU Activity Test
Use a per-activity test to decide controller, processor or joint control, then choose the right GDPR agreement and record the reasons clearly.

Quick Answer: Decide controller or processor for one processing activity, not for the company as a whole. The party choosing the purpose and essential means is a controller; a separate party acting on documented instructions is a processor. If both make indispensable converging decisions, assess joint control and record the contract route.
Last updated: 26 August 2026.
A supplier's contract may call it a processor, but that label does not settle the role. Under the GDPR, controller, processor and joint-controller status follow what each party actually decides and does. The reliable starting point is one narrowly described processing activity, followed by a record of who chose its purpose and essential means.
Classify the activity, not the company
A GDPR role belongs to a processing activity. It is not a permanent badge attached to a business, supplier or sector.
Begin with a sentence that has a clear verb, data and outcome: “The service company stores the client business's customer support messages so authorised staff can answer them.” That is narrow enough to test. “The supplier handles our data” is not, because hosting, analysing, reusing and disclosing the same records may have different purposes and different role outcomes.
The same organisation can therefore hold several roles at once. It may be controller for its own account administration, processor while storing support messages on a client's instructions, and controller again if it separately uses those messages to build an independent industry benchmark. The roles do not cancel each other; the activities need separate rows in the assessment.
This functional approach follows the GDPR definitions. A controller determines the purposes and means of processing, alone or jointly. A processor is a separate natural or legal person, public authority, agency or other body that processes personal data on the controller's behalf 1. The EDPB describes these concepts as autonomous and functional: contractual wording can help explain the relationship, but cannot override the facts 2.
The three outcomes at a glance
There are three branches, not two. First ask whether one party controls the purpose and essential means. Then ask whether another separate party acts on that party's documented instructions, or whether both parties made decisions that are jointly decisive.
One processing activity is defined before the parties' decisions about purpose and essential means are tested 1,2. When one party sets those features and another separate party acts on documented instructions, the route is controller and processor; when each pursues its own purpose, they are separate controllers. Indispensable common or converging decisions point to joint control, while a party that does not process the data has no role for that activity. The factual outcome is recorded and routed to the matching Article 28, Article 26 or controller-to-controller terms.
| Outcome for this activity | Factual boundary | Immediate document route |
|---|---|---|
| Separate controllers | Each party determines its own purpose and essential means for its own processing | Controller-to-controller terms appropriate to the disclosure and each party's duties |
| Joint controllers | Common or converging decisions by both parties are indispensable to the processing as designed | A transparent Article 26 arrangement allocating responsibilities |
| Controller and processor | One party determines purpose and essential means; a separate party processes on its behalf and within documented instructions | An Article 28 controller-processor agreement |
“Both benefit” does not establish joint control. Nor does “the supplier is technical” establish processing on behalf. The deciding evidence is the influence each party has over the purpose and the essential features of the activity.
The outcome may also be “neither” for a party that does not process the personal data in question. Recording that conclusion prevents the assessment from assigning roles merely because an organisation appears in the surrounding commercial arrangement.
Purpose and essential means identify the controller
The controller decides why the activity happens and the essential shape it takes. These decisions define the processing rather than merely implementing it.
Purpose is the intended objective. “Keep the service available” is an operational description; “store customer messages so the client can respond to support requests” identifies why the data is processed. If a supplier adds “analyse every client's messages to develop our own market product”, it has introduced a separate purpose. For that new use, it cannot remain merely the client's processor by repeating the original contract label.
Essential means concern choices closely tied to the purpose and scope. The EDPB points to matters such as the personal data processed, the people concerned, how long processing lasts and who may receive or access the data. These decisions are commonly reserved to the controller because changing them changes what the activity is 2.
| Decision | Usually essential or non-essential? | What to record |
|---|---|---|
| Why the data is processed | Purpose; controller-level | The concrete objective and which party approved it |
| Which people and data are included | Essential means | Categories, exclusions and who set them |
| Permitted recipients or access groups | Essential means | The authorised audience and decision owner |
| Duration or deletion endpoint | Essential means | The business or legal reason and who chose it |
| Hardware or hosting configuration within requirements | Usually non-essential implementation | Supplier choice, constraints and evidence |
| Detailed technical security implementation | Often non-essential implementation | Required outcome, supplier design and assurance evidence |
The table is a starting test, not an automatic classification engine. Context matters. A technical choice can become essential when it determines, for example, whether data is disclosed to a new recipient or used beyond the agreed purpose. Record the consequence of the choice, not the vocabulary used to describe it.
Implementation choices can remain with a processor
A processor does not need to be a mindless conduit. It may use expertise and discretion over non-essential means while still acting on behalf of the controller.
The controller can set the purpose, data scope, authorised users, retention outcome and required security level, while the processor chooses suitable infrastructure, backup scheduling and detailed protective controls. Those implementation choices allow the service to function. They do not necessarily give the processor authority to redefine the activity.
The boundary is the documented instruction. An instruction may establish outcomes and limits without dictating every technical step. Article 28 requires the processor to act only on documented instructions, subject to the limited case where Union or Member-State law requires processing. It also gives the processor direct duties concerning matters such as confidentiality, security, subprocessors, assistance, deletion or return, and audit information 1.
Three questions expose a supposed implementation choice that has gone further:
- Does the choice introduce a new reason for using the data?
- Does it materially change whose data, which data, recipients or duration are involved?
- Could the client prohibit the choice while retaining the service it asked for?
If the first two answers point to independent decision-making, split out that use and assess it as a separate activity. If the client cannot meaningfully define or stop a use that serves the supplier's own objective, the word “processor” is unlikely to describe that use.
Joint control is a distinct third branch
Joint control arises when two or more parties jointly determine the purposes and means. It does not require identical influence, equal access to data or a single written decision.
The clearest case is a common decision: both parties design and approve the activity together. Joint control can also follow from converging decisions. The EDPB's test asks whether the decisions complement each other and are necessary for the processing to occur in the way it does. If each party's participation is indispensable to that design, their influence may be jointly decisive 2.
Commercial cooperation alone is too weak. Two companies can benefit from the same transaction while independently deciding what they do with personal data. A supplier can also deliver an important service without sharing control if the client sets the purpose and essential means and the supplier remains inside instructions.
Test converging decisions in two passes. First identify each party's decision, rather than its service, assets or commercial interest. Then ask whether those decisions complement one another and whether each is necessary for the processing to occur in the designed form. The relevant dependency is between decisions about purpose or essential means, not simply between businesses.
That distinction prevents a common false positive. A client's decision to run a support channel and a supplier's decision to sell a standard storage service may be commercially necessary to the transaction, yet the supplier may still only implement the client's purpose within instructions. By contrast, if each party decides a different essential part of a shared programme and neither design can operate without the other, the decisions may converge into joint control. Economic dependence, data access and mutual advantage cannot substitute for that analysis.
Where joint control exists, Article 26 requires a transparent arrangement allocating the parties' respective responsibilities, particularly for data-subject rights and privacy information. The arrangement must reflect the real relationship, its essence must be available to data subjects, and a data subject may exercise rights against each joint controller 1.
One service relationship can contain all three routes
Consider an abstract service company that receives a client business's customer messages. The commercial relationship is one contract, but the data uses inside it are not necessarily one activity.
Activity A: instructed message storage. The client chooses the support purpose, message categories, authorised staff and deletion period. The service company configures infrastructure and backups within those requirements. On those facts, the client is controller and the service company is processor. Their route is an Article 28 agreement.
Activity B: an independent benchmark. The service company decides to analyse message content across clients to create a benchmark that serves its own objective. The client did not instruct that purpose or choose its essential means. The service company is a controller for the benchmark activity, even if it remains processor for Activity A. The parties must decide whether the disclosure to that independent controller is lawful and use controller-to-controller terms rather than trying to stretch the Article 28 label over the new use.
Activity C: a jointly designed shared response programme. Both parties decide the programme's purpose, target group, data fields and recipients; neither design works without the other's complementary decision. If those decisions are truly indispensable, the parties may be joint controllers and need an Article 26 arrangement. If one party merely supplies technical capacity within the other's design, the branch returns to controller and processor.
This scenario shows why a relationship-level question produces unreliable answers. The useful question is not “What is the service company?” It is “What role does each party have for Activity A, B or C, and why?”
Route the result to the right terms
Classification is incomplete until it changes the paperwork. Each branch needs a document that matches the facts rather than a preferred label.
For controller and processor, Article 28 requires a binding contract or other legal act. It must cover the subject matter and duration, nature and purpose, types of personal data, categories of data subjects, and the controller's rights and obligations. It must also contain the required operational terms, including documented instructions and the processor's duties. The detailed drafting procedure belongs in a separate task; the role assessment should at least identify the correct route and owner.
For joint controllers, the Article 26 arrangement must transparently divide responsibilities and present the real relationship. Avoid allocating every visible duty to one party while the other retains decisive control without corresponding accountability. The arrangement can designate contact points, but it cannot remove a person's ability to exercise rights against either joint controller 1.
For separate controllers, do not use an Article 28 agreement merely because data moves between them. Use controller-to-controller terms that support the actual disclosure: identify each purpose, the basis and expectations for sharing, transparency ownership, security, retention, rights handling, onward disclosure and incident cooperation. The GDPR does not turn those terms into a new role; their job is to make two independent sets of duties workable.
| Recorded result | Use | Do not substitute |
|---|---|---|
| Controller to processor | Article 28 contract or other binding legal act | A generic confidentiality clause |
| Joint controllers | Article 26 arrangement reflecting actual responsibilities | An Article 28 agreement that pretends one joint decision-maker only follows instructions |
| Separate controllers | Controller-to-controller sharing terms appropriate to the activity | An Article 28 label or an Article 26 arrangement without joint determination |
Keep a reusable decision record
A short role record is more valuable than an unsupported conclusion. It lets a reviewer trace the facts, tests, result and agreement route without reconstructing the project from email.
Use one row per processing activity. Where a service contains distinct purposes, create more rows rather than compressing them into one answer.
| Field | What the record should say |
|---|---|
| Activity | A narrow description of the data action and outcome |
| Purpose | Why processing occurs and who decided it |
| Essential means | Data, people, recipients, duration and other defining choices; decision owner for each |
| Instructions | Scope, limits, change process and evidence of documented instructions |
| Decisions retained by each party | Controller choices and processor implementation discretion |
| Joint-control test | Any common or converging indispensable decisions; why benefit alone is insufficient |
| Evidence | Contract schedules, design decisions, approvals, system settings and meeting records |
| Role outcome | Role for each party for this activity, including any split use |
| Document route | Controller-to-controller terms, Article 26 arrangement or Article 28 agreement |
| Owner and change trigger | Person responsible for review and facts that require reassessment |
The reasoning matters more than the final noun. “Processor because the contract says so” records no test and will fail as soon as the service changes. A useful conclusion reads: “Processor for instructed storage because the client sets the purpose, data scope, users and deletion endpoint; supplier discretion is limited to infrastructure and detailed controls.”
Attach evidence at the level claimed. A contract schedule can show instructions, while technical settings may show actual access and reuse. The controller should have enough information to understand the processor and subprocessor chain and assess whether the required guarantees remain available; responsibility does not disappear merely because processing sits several contracts away 4.
Immediate duties follow the role
The controller remains accountable for the lawfulness and design of the processing. It needs a lawful basis, appropriate transparency, data minimisation, rights handling, security, retention and evidence that its chosen processors provide sufficient guarantees. Appointment does not transfer the controller's responsibility to the supplier 1.
A processor must stay within documented instructions, ensure authorised people are bound to confidentiality, apply appropriate security and respect the agreed subprocessor route. It must assist the controller where Article 28 requires, notify the controller after becoming aware of a personal data breach without undue delay, deal with data at the end of the service as instructed, and provide information needed to demonstrate compliance 1.
Joint controllers remain responsible for the areas assigned to them and for making the allocation transparent. Their arrangement should say who supplies privacy information, receives and routes requests, manages security and incidents, and maintains the underlying record. Allocation supports delivery; it does not erase the statutory rights a person can exercise against each party.
Separate controllers each carry their own controller duties. One controller should not assume that the other's privacy notice, lawful basis or retention choice automatically covers its separate processing. The sharing terms should expose the seam between those responsibilities before a request, complaint or incident does.
Reassess whenever the facts move
Role analysis is a maintained record, not a one-time procurement answer. A supplier that began inside instructions can gain a new purpose, new recipients or a broader data population through an apparently small feature change.
Set change triggers around the facts that determine roles: purpose, data categories, affected people, recipients, retention, authorised users, integrations, subprocessors, independent reuse, model or training uses, and the boundary of documented instructions. A material change should pause approval until the owner has re-run the activity test and updated the agreement route.
A periodic review can catch quieter drift, but it should not replace event-based review. Compare the record with current system settings, product descriptions, instructions and data flows. The EDPB's small-business guidance likewise starts with the real decision-making relationship rather than the title used by the parties 3.
Finish each review with an explicit outcome: role for each party, evidence, required document, remediation owner and date of next trigger. If the answer is uncertain because the activity is described too broadly, narrow the activity. If uncertainty remains because each party appears indispensable to the purpose or essential means, examine joint control instead of forcing the facts into a binary choice.
Frequently Asked Questions
Can a contract decide whether a supplier is a processor?
Can the same business be both controller and processor?
Does choosing software make a supplier a controller?
When are two parties joint controllers?
What if a processor starts using data for its own purpose?
Do independent controllers need an Article 28 agreement?
What must an Article 26 arrangement cover?
When should a controller-or-processor assessment be repeated?
Sources
- 1.Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · 2016
- 2.Guidelines 07/2020 on the concepts of controller and processor in the GDPR — European Data Protection Board · 2020
- 3.Data controller or data processor — European Data Protection Board
- 4.Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) — European Data Protection Board · 2024
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.