Law and definitions

Data Controller vs Data Processor: Differences and Examples

Compare data controller and data processor roles with website, analytics and agency examples, joint-controller rules and a practical vendor review checklist.

Published
Reading time
9 min

A data controller decides why personal data is processed and the essential means of that processing. A data processor processes personal data on the controller's behalf. The difference depends on the actual decisions and activities, not simply the label in a vendor contract.

For a website, the business operating the site may be a controller while a hosting provider processes data on its instructions. Analytics, advertising, consent platforms and agencies require closer examination: the same organisation can have different roles for different uses of data.

This guide explains the EU GDPR framework with practical examples for website and privacy teams. Sources were reviewed on 19 September 2026. Other laws, including California's CCPA, have their own definitions and contractual requirements.

Data controller versus data processor at a glance

QuestionData controllerData processor
Who decides the purpose?Determines why the processing happensCarries out the controller's processing purposes
Who decides essential means?Determines matters such as whose data, which data and the intended processingCan choose practical technical details within the permitted instructions
Can it reuse data for its own purposes?Must establish a lawful basis and meet the applicable requirements for its processingCannot treat the controller's data as available for independent reuse merely because it receives it
What documents the relationship?Must assess the relationship and put the appropriate arrangement in placeMust be bound by an Article 28 contract or other qualifying legal act for processing on behalf of the controller
Does it have direct GDPR duties?YesYes; following instructions does not remove its own obligations

The statutory definitions are in Article 4(7) and (8). Article 28 governs processing on behalf of a controller, including the situation where a processor starts determining purposes and means itself. GDPR, Articles 4 and 28

How to identify the role for a specific activity

Start by describing one processing operation. “Our relationship with the analytics supplier” is too broad. “Collecting selected website events to produce reports for our shop” is a better starting point.

Ask who decides the purpose, the categories of people and data involved, recipients, and retention. Then separate those decisions from practical choices such as selecting suitable infrastructure to carry out instructions.

A processor can have technical expertise and some discretion without becoming a controller. Conversely, a provider that determines an independent purpose cannot resolve that by calling itself a processor. Contract terms are evidence of the arrangement, but must match the facts. EDPB Guidelines 07/2020, sections on essential means and processors

A useful review record has four fields: processing operation, decision-maker, proposed role and supporting evidence. If a supplier performs several operations, give them separate rows.

Website examples: hosting, analytics, CMPs and agencies

These examples illustrate how to assess roles. They do not assign a fixed role to every provider in a product category.

Website hosting

A retailer chooses to operate an online shop and hires a hosting provider to store and serve customer records under documented instructions. For that activity, the retailer is the controller and the host is a processor.

The host may separately decide how to process its own business contacts for billing. Assess that separate activity on its own facts. One processor relationship does not describe everything the hosting company does.

Website analytics

A publisher chooses the reporting purpose and permitted event fields. A supplier processes those events solely to deliver the publisher's reports under instructions. That can support a controller-processor relationship.

If the supplier also uses identifiable visitor data for independent advertising or other purposes, assess those operations separately. Examine enabled features, terms and actual data flows rather than assuming that all activity under an “analytics” product has the same role.

Role classification does not answer whether analytics may load before consent. Our analytics cookie consent guide covers that separate question.

A business decides the purposes presented in its banner and uses a CMP to record and apply visitors' choices on its behalf. The provider may be a processor for that recordkeeping activity.

Review what the CMP receives, how consent records are used, retention and any separate provider purposes. Installing the platform does not transfer the website business's responsibility for its own processing decisions.

Marketing and implementation agencies

An agency configuring tags or handling a customer list solely under the client's documented instructions may act as a processor for that work. An agency deciding independent uses of the data needs a different assessment for those uses.

An agency that only supplies designs or advice, without processing personal data on behalf of the client, is not automatically a processor. Access, responsibilities and actual activities matter more than the job title.

Advertising platforms and embedded tools

Do not assume an advertising recipient is a processor because the website pays for its service. Examine who determines collection, audience selection, matching, subsequent use and disclosures.

Separate the collection and transmission stage from later processing. A relationship can require different role assessments at each stage, including joint controllership where its conditions are met.

What is a joint controller?

Joint controllers jointly determine the purposes and means of processing. Sharing a supplier or exchanging data does not automatically establish this relationship. Equally, the parties do not need identical involvement or equal responsibility.

For joint processing, Article 26 requires a transparent arrangement allocating GDPR responsibilities, particularly rights handling and information duties, unless applicable law determines those responsibilities. The essence of the arrangement must be made available to individuals. People can exercise their rights against each joint controller regardless of the allocation. GDPR, Article 26

Why the Fashion ID case matters for websites

In Fashion ID, the Court of Justice examined a website embedding a Facebook Like button. Under the predecessor Data Protection Directive, it found that a website operator could be a joint controller for collecting and transmitting visitor data, without being a controller for subsequent processing whose purposes and means it did not determine.

The case illustrates why the processing stage matters. It does not establish that every current advertising or social integration has the same classification. Court of Justice, Fashion ID, C-40/17

For a current implementation, document which party decides each operation before selecting an Article 26 arrangement, an Article 28 contract or another appropriate arrangement.

What must a data processing agreement cover?

An Article 28 data processing agreement, often called a DPA, must describe the processing and impose the required obligations. It is more than a statement that the supplier “complies with GDPR”.

Check that it addresses:

  • The subject matter, duration, nature and purpose of processing, types of data and categories of individuals.
  • Documented instructions, including relevant instructions concerning international transfers, subject to the statutory legal-requirement exception.
  • Confidentiality and appropriate security measures.
  • Conditions for appointing subprocessors.
  • Assistance with individual rights, security, breach obligations and impact assessments as applicable.
  • Returning or deleting data at the end of services, subject to legally required storage.
  • Information needed to demonstrate compliance and provisions for audits and inspections.

The processor must also inform the controller immediately if, in its opinion, an instruction infringes the relevant data protection law. GDPR, Article 28(3)

A subprocessor is engaged by a processor to carry out processing on behalf of the controller. Prior specific or general written authorisation is required. With general authorisation, the controller must be informed of intended additions or replacements and have an opportunity to object. Relevant data protection obligations must flow down to the subprocessor. EDPB's controller and processor guide

Signing a DPA does not by itself establish lawful collection, valid cookie consent or a valid international-transfer mechanism. Check those issues separately. The GDPR and ePrivacy overview explains the website consent distinction.

Who handles requests, security and breaches?

The controller must arrange an effective process for exercising rights. The processor assists according to the nature of the processing and the Article 28 requirements. Teams should know who receives requests, locates records, communicates decisions and carries out agreed actions.

Both controllers and processors have Article 32 security obligations. Under Article 33, a processor must notify its controller without undue delay after becoming aware of a personal data breach. A controller's supervisory-authority notification has a separate test and, where required, a deadline of 72 hours after awareness where feasible. Do not give a processor a blanket 72-hour waiting period copied from the controller's rule. GDPR, Articles 28, 32 and 33

Neither role guarantees immunity from liability. Article 82 distinguishes controllers' and processors' liability for damage, including processor-specific obligations and acting outside or contrary to lawful instructions. Contractual allocation does not erase statutory responsibilities. GDPR, Article 82

A vendor review checklist for website teams

Use this workflow before activating a new integration or materially changing an existing one:

  1. List the operations. Include collection, storage, analysis, matching, onward disclosure and deletion.
  2. Map the decisions. Identify who decides purposes and essential means for each operation.
  3. Inspect the evidence. Compare terms, instructions, product settings, retention controls and actual browser and server requests.
  4. Resolve independent uses. Ask whether the provider combines data across customers or uses it for separate purposes, and assess the relevant role.
  5. Choose the right arrangement. Document processor, joint-controller or separate-controller relationships as appropriate.
  6. Check additional requirements. Review lawful basis, sensitive data, device access, transfers, security and assessments where applicable.
  7. Assign operational contacts. Establish how rights requests, incidents, subprocessor changes and deletion will be handled.
  8. Verify and revisit. Check the deployed behaviour with synthetic data and reassess when purposes, features or recipients change.

Our sensitive personal information guide helps identify data needing additional review. Our server-side tracking guide explains why moving processing off the browser does not remove recipient and purpose questions.

If you need help translating approved privacy decisions into banner and tag behaviour, see cookie consent implementation.

FAQ

Can a company be both a data controller and a data processor?

Yes, for different processing activities. A supplier may process a client's customer data under instructions while acting as controller for its own employment records. Record the role for each activity rather than assigning one label to the whole company.

Is a marketing agency always a data processor?

No. An agency processing data on a client's behalf under instructions may be a processor. Independent decisions about purposes can change the assessment. An agency providing advice without processing personal data on the client's behalf is not automatically a processor.

Is an analytics provider a controller or processor?

It depends on the particular processing and configuration. Review reporting, advertising features, data combination and independent uses separately. A product category or supplier name is not enough to decide the role.

Does a data processing agreement make a vendor a processor?

No. The contract must reflect the actual relationship. Calling a vendor a processor cannot override its independent decisions about the purposes and essential means of processing.

No. Role classification and device-access requirements are separate questions. A processor relationship does not itself exempt cookies or other tracking operations from applicable consent rules.

What is the difference between a processor and a subprocessor?

A processor processes personal data on behalf of a controller. A subprocessor is engaged by that processor to carry out relevant processing for the controller. Article 28 requires authorisation and appropriate contractual obligations for that appointment.

Portrait of Doğancan Doğan
Written bySolution Engineer, Privacy Engineering

Solution engineer who has implemented consent management on 200+ corporate websites globally. Specialises in CCPA and GDPR operational compliance.

Keep reading

Related guides.

All of Law and definitions →
  1. 01Sensitive Personal Information: Definition and ExamplesLaw and definitions · Mar 2025
  2. 02US State Privacy Laws 2026: Tracker and Compliance GuideLaw and definitions · Apr 2026
  3. 03GDPR Cookie Consent in 2026: ePrivacy Rules and ChecksGDPR and ePrivacy · Apr 2026

See what fires before consent on your own site.

A free audit of your current banner and tags across regions, with the findings in writing and a 30-minute call to go through them.