Controllers and Processors
Overview of the data protection roles under the GDPR: controller, joint controllers, processors, and persons acting under the authority of the controller, the distinction according to purposes and means, the allocation of obligations, and liability.
The GDPR allocates obligations and liability according to one fundamental principle: they fall on the party that determines the processing. Whoever determines for what purposes and in what manner data is processed is a "controller" and must fulfill the obligations of the GDPR. A large number of further consequences depend on this classification as a controller: the contracts required, the allocation of obligations, the content of the privacy notices, and liability in the event of damage. Determining the data protection roles correctly (separate controller, joint controller, or processor) therefore stands at the beginning of every data protection assessment and sets the course for everything that follows.
Key takeaways
- The GDPR recognizes four roles: controller (Article 4(7), Article 24 GDPR), joint controllers (Article 26 GDPR), processor (Article 28 GDPR), and the person acting under the authority of the controller (Article 29 GDPR).
- What matters is solely who in fact determines the purposes and the (essential) means of the processing, not the designation used in the contract.
- Only the controller may determine the purposes (the what for and the why); non-essential means (the software used, the specific security measures) may also be determined by a processor.
- Contracts that have been concluded have only indicative effect. What is decisive is the actual allocation of roles. A relationship that has been classified incorrectly can trigger controllership of one's own, administrative fines, and an unlawful passing on of data.
- The simplest case is separate (independent) controllership: no joint contracts, no liability for the other party.
1 The actors under the GDPR
A single processing operation can involve several parties. The GDPR assigns them to a fixed structure of roles:
- Controller (Article 4(7) GDPR): the legal person, public authority, or body that determines the purposes and means alone. It is the central addressee of the obligations and, in principle, bears all obligations under the GDPR. More at 1.3.6.2 Controller.
- Person acting under the authority of the controller (Article 29 GDPR): employees or civil servants who act for the controller. They are not controllers themselves but are bound by the controller's instructions and are attributed to the controller as part of its sphere. Their conduct therefore counts as conduct of the controller. An exception is the case of excess: where the person acts contrary to instructions for its own purposes, that conduct is not attributed to the controller, and the person may to that extent itself become a controller (on this, see the end of 1.3.6.2 Controller).
- Joint controllers (Article 26 GDPR): two or more controllers that jointly determine the purposes and means. More at 1.3.6.3 Joint controllers.
- Processor (Article 28 GDPR): a party that processes data on behalf of a controller and on its instructions, without determining the purposes or the essential means. More at 1.3.6.4 Processor.
Alongside these stands the third party as any party outside this inner circle (Article 4(10) GDPR), and the recipient as any party to which data is disclosed (Article 4(9) GDPR). Processors and persons acting under the authority of the controller are precisely not third parties, but part of the controller's sphere. These terms are explained separately as reference entries (1.2.9 Recipient, 1.2.10 Third party).
2 Distinction: who determines the purposes and means
All roles derive from a single question: who in fact determines the purposes and means of the processing? In fact means: how the matter is actually handled in practice, not how it is worded in contracts.
- Purposes answer the what for and why of the processing, that is, the objective (for example customer administration, billing, advertising). Only the controller may determine the purposes. Whoever takes part in determining the purpose is never a mere processor.
- Means answer the how of the processing. Here a distinction must be drawn:
- Essential means directly affect the lawfulness of the processing: which categories of data are processed, how long they are stored, who is granted access, and to whom data is passed on. Only the controller may determine them.
- Non-essential means concern the purely technical implementation: which specific software is used and which specific security measures are taken. These decisions may be left to a processor.
The point of reference is always a specific processing operation involving specific data for a specific purpose, where applicable at a specific stage. The same party can be a processor for one processing operation and a controller in its own right for another. Moreover, the role is always held by the legal person, for example the German limited liability company (GmbH), the university, or the hospital, not by an individual department or an individual employee.
The roles cannot be freely agreed. A party that is designated as a processor in the contract but that in fact takes part in determining the purposes or the essential means is considered a controller to that extent (Article 28(10) GDPR), with all the obligations and fine risks that this entails.
3 The roles at a glance
| Role | Determines purpose/essential means? | Contract or instrument | Own GDPR obligations | External liability |
|---|---|---|---|---|
| Controller | yes, alone | not required | all obligations (Article 24 GDPR) | full liability (Article 82 GDPR) |
| Joint controllers | yes, jointly with others | arrangement under Article 26 GDPR | all obligations, allocated internally | joint and several (Article 82 GDPR) |
| Processor | no (only non-essential means) | data processing agreement (Article 28 GDPR) | limited obligations of its own | limited to its own obligations |
| Person acting under authority | no | instructions (Article 29 GDPR) | none of its own | none of its own |
4 Relevance of the classification
The role is not an academic question; it governs the entire data protection compliance of a relationship:
- Contracts. A data processing agreement must be concluded with a processor (Article 28(3) GDPR), and an arrangement on the allocation of obligations must be concluded with joint controllers (Article 26(1) GDPR). Where controllership is separate, no data protection contract is generally required.
- Allocation of obligations. The role determines who maintains the records of processing activities (1.3.7), who notifies a data breach, who answers data subject requests, and who drafts the privacy notices.
- Passing on data. Passing data on to a processor is privileged and, in principle, permissible without a separate legal basis being required for the transfer. Passing data on to another controller is a disclosure that requires justification.
- Liability and administrative fines. The controller is liable for the entire handling of the data, including the conduct of its processor. Joint controllers are jointly and severally liable externally.
In practice, the simplest case is separate controllership: as a rule, no contracts are required here, and no liability arises for the other party. In the case of general project data (contact details of those involved, related emails, minutes of meetings), separate controllership can usually be assumed.
Because the classification is tied to the actual allocation of roles, contracts that have been concluded have only indicative effect. They can, however, give rise to a prima facie appearance: a party that concludes a data processing agreement signals that it proceeds on the assumption of processing on behalf of a controller. An incorrect classification therefore cannot be cured by the contract; instead, it creates additional risks (on this, see 1.3.6.4).
5 Structure of this section
1.3.6.2 Controller
Concept and scope (Article 4(7)), obligations (Article 24), and persons acting under the authority of the controller (Article 29 GDPR).
1.3.6.3 Joint Controllers
When joint controllership exists and the arrangement under Article 26 GDPR.
1.3.6.4 Processor
When processing on behalf of a controller exists and the data processing agreement under Article 28 GDPR.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Design and Practice of the Privacy Policy
How to structure a privacy policy: structural patterns, the layered model, the level of detail for each item, delivery channels, typical mistakes, updating and a checklist.
Controller (Article 4(7), Article 24 GDPR)
The controller as the central figure of the GDPR: the concept and its broad interpretation under Article 4(7), who can be a controller, the obligations under Article 24, and persons acting under the controller's authority pursuant to Article 29 GDPR.