What is the difference between a data controller and a data processor?
Who decides what happens to the data. The controller determines the purposes and means of processing; the processor acts on the controller's instructions. The distinction sets who carries which legal obligations under UK GDPR.
Controller. Decides why personal data is processed and how — what is collected, for what purpose, how long it is kept, who it is shared with.
Their obligations are the heavy ones: establishing a lawful basis, providing privacy information, honouring individual rights, assessing risk, reporting breaches to the regulator, and accountability for the whole arrangement.
Processor. Processes personal data on behalf of a controller, with no independent decision-making about purpose. Cloud hosting providers, payroll bureaux, email delivery services and most SaaS tools acting on your data.
Their obligations are narrower but real: act only on documented instructions, keep data secure, assist the controller, notify the controller of breaches without undue delay, and not engage sub-processors without authorisation.
Joint controllers exist where two organisations jointly determine purposes and means — and this is a genuinely common situation people get wrong, particularly with analytics and advertising tools where both the organisation and the platform decide something about the processing. Joint controllers must have an arrangement setting out respective responsibilities.
The test is substance, not the contract label. Calling someone a processor does not make them one. If a supplier uses your data for their own purposes — improving their own product, building their own profiles — they are acting as a controller for that activity, whatever the agreement says. This is where many standard supplier arrangements are misdescribed.
What must be in place between them. A written contract with specified terms — subject matter, duration, nature and purpose, types of data, categories of individuals, and obligations on both parties. This is not optional, and the required contents are set out in the legislation.
Why it matters practically: individuals exercise rights against the controller; the regulator holds the controller accountable for the arrangement; and a controller who chooses a poor processor remains responsible for having chosen them.
General information, not legal advice.