Every GDPR obligation attaches to a role, so classifying your organization correctly is the first compliance decision. The controller determines the purposes and means of processing. The processor handles data only on the controller’s documented instructions. Get the classification wrong and you build the wrong compliance program: notices and lawful bases where you needed instructions and DPAs, or the reverse.
| Regulation | GDPR, Articles 24 to 28 and 82 |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Key case | Fashion ID, CJEU C-40/17 (2019) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
Classification is factual, not contractual
Labels in the contract do not decide the question; actual influence does. A payroll provider following the client’s instructions is a processor. An analytics vendor that uses client data to improve its own products has become a controller for that use, whatever the contract says. The EDPB’s Guidelines 07/2020 walk through the tests: whoever decides why data is processed and the essential elements of how (what data, whose data, how long, who gets access) is a controller.
The classification also shifts within one relationship. A processor that steps outside its instructions is treated under Article 28(10) as a controller for that processing, which means full exposure to controller fines and claims.
The Article 28 contract
Processing by a processor without a compliant DPA is itself a violation by both parties. Article 28(3) fixes the minimum content: documented instructions, confidentiality, Article 32 security measures, sub-processor authorization and flow-down, assistance with data subject rights, assistance with breach notification and DPIAs, end-of-contract deletion or return, and audit rights. Two practical points get missed constantly. First, the instructions need to be genuinely documented, usually as an annex describing the processing. Second, the sub-processor list needs a change-notification mechanism you actually operate.
Joint controllers and embedded tools
Article 26 applies whenever parties jointly determine purposes and means, and the CJEU has read it broadly. In Fashion ID (C-40/17), a retailer embedding the Facebook Like button was a joint controller with Facebook for the collection and transmission the button performed. The same logic reaches modern pixels, social plugins, and ad tags: embedding a tracker on your site makes you responsible for what it collects. Joint controllers must allocate duties in an arrangement and expose its essence to users.
That is worth verifying empirically. A free scan lists every third party your site sends visitor data to, which is effectively a list of relationships needing either a DPA or a joint-controller analysis. For the record-keeping that documents all of this, see our ROPA guide.