Am I a controller, a processor, or both?

Controllers of personal information are the ones with all the liability under the GDPR, right? Wrong. Processors have obligations under the GDPR too. And then there’s joint controllers as well. They are jointly liable to people who have suffered damage because of a GDPR breach. To confuse matters further, an organisation can be both a controller and a processor at the same time (although not in relation to the same processing activity).

By Claire Heaphy

Privacy Compliance Hub Information Officer

The GDPR imposes obligations on both controllers and processors of personal information.  But these responsibilities are different, with controllers subject to the most wide reaching obligations.  Organisations need to know their status for each processing activity they undertake as failure to comply with the relevant obligations is a breach of the GDPR.   This may attract fines or other penalties imposed by supervisory authorities (the ICO in the UK) and even court action for damages by individuals whose privacy rights have not been upheld.   

Controllers and joint controllers and processors, oh my!

Controllers

A controller is the party which determines the purposes and means of the processing of personal information.  

Controllers are responsible for GDPR compliance and they have primary responsibility for the protection of the privacy rights of individuals.  If they engage a processor, they remain ultimately accountable to the supervisory authorities for GDPR compliance of their processing. They cannot outsource that responsibility to their processors.  Controllers must appoint any processors by written contract containing compulsory terms governing specific areas of GDPR compliance. 

Note that controllers are responsible for paying the annual Data Protection Fee to the ICO.

Joint controllers 

Two or more controllers who jointly determine the purposes and means of processing.  Two or more controllers are not joint controllers if they process the same personal information for different purposes.

Joint controllers must have a ‘transparent arrangement’ between them which apportions responsibility for their obligations under the GDPR (particularly those concerning the rights of individuals).  This must be made available to individuals and the ICO recommends it is included in privacy policies. Regardless of what has been decided in terms of who is responsible for which GDPR obligation, each joint controller remains liable to the supervisory authorities and to individuals for compliance with all of the controller obligations in the GDPR.  

Processors

A processor is a party which processes personal data on behalf of the controller.  A sub-processor is someone who the processor has outsourced some or all of the processing to eg. a cloud service to store personal information.

Processors’ obligations under the GDPR are more limited than controllers’.  They must act in accordance with the controller’s written instructions (unless otherwise required by law).  If a processor acts against or without the controller’s instructions, it will be deemed to be the controller for that part of the processing and will have the same, more extensive, GDPR liability as controllers.  

How to tell whether you are a controller or a processor 

This depends ultimately, on who decides the purposes for which personal information is processed and the means of processing.  The ICO provides useful checklists to help organisations determine whether they are a controller, joint controller or processor for any particular processing activity.

This exercise must be carried out for all the different processing activities an organisation is involved in.  This is because many organisations will be acting as a controller, a joint controller and a processor all at the same time in respect of different processing activities.  You should record your status for each one of your processing activities. Identifying your role in processing personal information is a vital step in your GDPR compliance and organisations using the Privacy Compliance Hub know how to do this.

Our short product walkthrough video shows you how The Privacy Compliance Hub and its Eight Privacy Promises helps organisations like yours build a culture of continuous privacy compliance.

Watch video

A culture of continuous privacy compliance

In our view, the very best way to ensure that your business understands its obligations under the GDPR is through a cultural shift in your organisation.  At The Privacy Compliance Hub, we help organisations establish and maintain a culture of continuous privacy compliance by making everyone in an organisation understand privacy, care about privacy and to do their bit to protect personal information.  Our platform contains a structure, a programme, a route map, records, information, reporting and training to enable all organisations to comply with the GDPR and other privacy rules. It contains everything that you need.

More to watch and read