The roles of a Controller and a Processor are the two most important distinctions in
data protection law, like the General Data Protection Regulation (GDPR). The key
difference is who makes the decisions about the personal data.
Think of it like a customer ordering a meal at a restaurant.
1. The Controller: The Decision-Maker
The Controller is the person or company that determines the "why" and "how" of
processing personal data. They are the ones who decide:
WHY is the data being collected (the purpose)?
WHAT data is needed?
HOW is it going to be used (the means)?
The Controller has the primary responsibility for complying with all aspects of the
GDPR. They are the ones ultimately accountable if something goes wrong.
Restaurant Analogy: The Customer 🍽️
The customer is the Controller.
They decide they want to eat (the purpose).
They choose the specific dish (the data needed for the chef).
They specify any customizations (the means of processing).
Real-World Example 🏢
A retail company (Controller) runs an online store and collects customer
information.
Decision They Make Role as Controller
Why they collect a customer's They want to send the order and email
email and address. marketing. (Determines the Purpose)
What data they collect (name, They decide the types of personal data.
address, phone number). (Determines the Means)
Which third-party to use for They make the high-level business
storage or shipping. decisions about data flow.
2. The Processor: The Action-Taker
The Processor is a person or company that processes personal data strictly on
behalf of and under the instructions of the Controller. They are essentially a
service provider for the Controller.
They do not decide why the data is being used.
They must follow the documented instructions given by the Controller.
They are primarily responsible for data security and assisting the Controller
with their obligations.
Restaurant Analogy: The Chef 🧑🍳
The chef is the Processor.
They process the ingredients (personal data) to cook the meal.
They follow the customer's (Controller's) order and specific instructions (e.g.,
"no onions").
They don't get to decide to cook a completely different meal.
Real-World Example ☁️
The retail company (Controller) decides to use a Cloud Storage Provider
(Processor) to store all of its customer data.
Action They Take Role as Processor
Storing the customer's name, They process data on behalf of the
address, and order history. Controller.
Applying the security measures (like They follow the technical and
encryption) agreed upon in the organisational instructions of the
contract. Controller.
Deleting the data when the contract They act only on the Controller's
ends. documented instruction.
Key Takeaway: The Contract is Essential
For every relationship between a Controller and a Processor, the GDPR legally
requires a written contract (often called a Data Processing Agreement or DPA).
This contract details the Processor's instructions, obligations, and security
measures.
It ensures the Processor knows exactly what they are—and are not—allowed
to do with the data.
The Golden Rule: If an entity has the power to decide "Why are we using this
data?" and "How are we going to use it?", they are a Controller. If they are
simply a service following a specific set of rules given by someone else, they are a
Processor.
JOINT CONTROLLER
This is an excellent question, as the concept of "Joint Controllers" is one of the most
complex and important parts of the GDPR.
Here is an explanation of Article 26 (Joint Controllers) in simple terms, along with
examples, key case law, and related provisions.
1. What is a Joint Controller? (Article 26, Clause 1)
In short, you are a joint controller if you and another organization "jointly determine
the purposes and means" of processing personal data.
Term Simple Meaning
Purposes (The What is the reason or goal for collecting and using this
"Why") data?
Term Simple Meaning
Means (The What are the technical and organizational methods used to
"How") collect, store, and use the data?
If two parties decide on the purpose and the means together, they are Joint
Controllers. If one party is just following the instructions of the other, they are a
Controller and a Processor (Article 28).
Example: A Co-Branded Marketing Event
1. A Car Company and a Sports Drink Company decide to host a joint
promotional event.
2. They agree to run a prize draw to collect attendees' names, phone numbers,
and emails.
3. Joint Determination:
o Purpose: They both agree the data will be used to send both
companies' separate marketing emails (Common purpose: marketing
to attendees).
o Means: They both agree to use the same sign-up tablet and the same
database structure to collect the data.
Since they agreed on the why (joint marketing) and the how (common collection
method), they are Joint Controllers for the data collected at the event.
2. Key Provisions of Article 26
Article 26 has three main requirements for Joint Controllers:
Provision 1: The Arrangement (Article 26, Clause 1)
Joint Controllers must "in a transparent manner determine their respective
responsibilities... by means of an arrangement."
Simple Meaning: You need a formal, documented agreement (often called a
Joint Controller Agreement or JCA) that clearly spells out who is
responsible for which GDPR duties.
What it Covers: The JCA must cover who handles:
o Data Subject Rights (e.g., who responds to a "Right to be Forgotten"
request).
o Providing transparency information (Articles 13 and 14, i.e., the Privacy
Policy).
Designating a Contact Point: The agreement may designate a single point
of contact for the person whose data is being processed, to make things
easier for them.
Provision 2: Transparency (Article 26, Clause 2)
"The essence of the arrangement shall be made available to the data subject."
Simple Meaning: The public needs to know the most important points of your
internal agreement. You can't just keep it a secret business contract.
How to Comply: The easiest way is to include a clear, plain-language
summary of the arrangement (e.g., which company is responsible for data
rights requests) in your public Privacy Policy.
Provision 3: Data Subject's Rights (Article 26, Clause 3)
"Irrespective of the terms of the arrangement... the data subject may exercise his or
her rights... against each of the controllers."
Simple Meaning: Even if your internal JCA says "Company A handles all
requests," a customer can legally send a request to Company B, and
Company B is still legally obliged to handle it or forward it correctly. The JCA
is an internal promise; it does not limit the individual's legal rights.
3. Key Case Law: The Facebook Fan Page Decision
The most important court ruling that defined Joint Controllership comes from the
Court of Justice of the European Union (CJEU):
Case: Wirtschaftsakademie Schleswig-Holstein (2018)
The Scenario: A German company (Wirtschaftsakademie) ran an official
Facebook Fan Page to share information and attract visitors. Facebook
provides the page administrator with anonymous visitor statistics ("Page
Insights") using cookies.
The Dispute: The German Authority said the company was responsible for
how Facebook collected data via the Fan Page's cookies. The company
argued, "We only use the anonymous data; Facebook handles the collection,
so Facebook is the only Controller."
The Ruling: The CJEU ruled that the German company and Facebook were
Joint Controllers.
The Principle: Joint Controllership exists even if the parties have different
purposes for the processing and one party does not have access to all the
data. The German company chose to use the Fan Page and, by doing so,
gave Facebook the platform to collect the visitor data. This joint decision on
the means (using the platform/setting up the cookies) was enough to establish
joint control, even though the company's purpose (marketing) was different
from Facebook's purpose (ad-targeting).
4. Exceptions and Related Provisions
Exceptions to Article 26
The concept of Joint Controllership itself has very few exceptions. It either applies or
it doesn't, based on the principle of joint determination.
Key "Non-Exception" (Distinction): You are not a Joint Controller if you are
an Independent Controller.
o Example: A bank processes your data to give you a loan. An
insurance company processes your data to give you insurance. They
both use your name and address, but they decide on the purposes and
means completely on their own, with no agreement. They are two
separate, Independent Controllers, not Joint Controllers. Article 26
does not apply.
Other Related GDPR Provisions
Article Simple Connection to Joint Controllers
Definition of "Controller" is the party which, "alone or jointly with
Article
others, determines the purposes and means of processing." This is
4(7)
the foundation for Article 26.
Right to Compensation and Liability. It states that all Controllers
(including Joint Controllers) are liable for damage caused by
Article
processing that violates the GDPR. The individual can claim
82
damages from any of the joint controllers, regardless of the internal
JCA.
Records of Processing Activities (RoPA). Joint Controllers must
Article
still keep their own records of the joint processing activities, which
30
should clearly reference the JCA.
Data Protection Impact Assessment (DPIA). If the joint processing
Article
is likely to result in a high risk, the Joint Controllers must cooperate
35
to carry out a DPIA.