EU Privacy Law EU/EEA

GDPR Controller vs. Processor: Obligations, Contracts, and Liability Allocation

How GDPR splits duties between controllers and processors, the mandatory Article 28 contract clauses, joint controllership, and who pays when things fail.

Regulation

GDPR, Articles 24 to 28 and 82

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • The controller determines the purposes and means of processing (Article 4(7)); the processor processes on the controller's documented instructions (Article 4(8)).
  • Every controller-processor relationship needs an Article 28(3) contract containing eight mandatory elements, commonly called a DPA.
  • Processors carry direct obligations under GDPR too: security, breach notification to the controller, records, and transfer rules all bind them directly.
  • Joint controllership (Article 26) arises whenever two parties jointly determine purposes and means, including via embedded tools like the Facebook Like button (CJEU Fashion ID, C-40/17).
  • A processor that exceeds its instructions becomes a controller for that processing, inheriting full controller liability.

Every GDPR obligation attaches to a role, so classifying your organization correctly is the first compliance decision. The controller determines the purposes and means of processing. The processor handles data only on the controller’s documented instructions. Get the classification wrong and you build the wrong compliance program: notices and lawful bases where you needed instructions and DPAs, or the reverse.

RegulationGDPR, Articles 24 to 28 and 82
Max penaltyEUR 20M or 4% of global annual turnover
Key caseFashion ID, CJEU C-40/17 (2019)
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

Classification is factual, not contractual

Labels in the contract do not decide the question; actual influence does. A payroll provider following the client’s instructions is a processor. An analytics vendor that uses client data to improve its own products has become a controller for that use, whatever the contract says. The EDPB’s Guidelines 07/2020 walk through the tests: whoever decides why data is processed and the essential elements of how (what data, whose data, how long, who gets access) is a controller.

The classification also shifts within one relationship. A processor that steps outside its instructions is treated under Article 28(10) as a controller for that processing, which means full exposure to controller fines and claims.

The Article 28 contract

Processing by a processor without a compliant DPA is itself a violation by both parties. Article 28(3) fixes the minimum content: documented instructions, confidentiality, Article 32 security measures, sub-processor authorization and flow-down, assistance with data subject rights, assistance with breach notification and DPIAs, end-of-contract deletion or return, and audit rights. Two practical points get missed constantly. First, the instructions need to be genuinely documented, usually as an annex describing the processing. Second, the sub-processor list needs a change-notification mechanism you actually operate.

Joint controllers and embedded tools

Article 26 applies whenever parties jointly determine purposes and means, and the CJEU has read it broadly. In Fashion ID (C-40/17), a retailer embedding the Facebook Like button was a joint controller with Facebook for the collection and transmission the button performed. The same logic reaches modern pixels, social plugins, and ad tags: embedding a tracker on your site makes you responsible for what it collects. Joint controllers must allocate duties in an arrangement and expose its essence to users.

That is worth verifying empirically. A free scan lists every third party your site sends visitor data to, which is effectively a list of relationships needing either a DPA or a joint-controller analysis. For the record-keeping that documents all of this, see our ROPA guide.

Frequently Asked Questions

What is the difference between a controller and a processor?

The controller decides why and how personal data is processed. The processor acts only on the controller's documented instructions. The test is factual influence, not what the contract labels the parties.

What must an Article 28 data processing agreement contain?

Eight elements: processing only on documented instructions, confidentiality commitments, Article 32 security, sub-processor rules, assistance with data subject rights, assistance with breaches and DPIAs, deletion or return at contract end, and audit rights.

Can a processor use sub-processors?

Only with the controller's prior written authorization, general or specific (Article 28(2)). Under general authorization the processor must give notice of changes and pass down the same contractual duties. The processor stays fully liable for its sub-processors.

What is a joint controller?

Two or more parties that jointly determine purposes and means (Article 26). They must agree transparently on who handles which obligations and make the essence of that arrangement available to data subjects. Individuals can enforce their rights against either party.

Can data subjects sue a processor directly?

Yes. Article 82 lets individuals claim compensation from processors where the processor breached its own GDPR obligations or acted outside lawful controller instructions. Controllers and processors in the same processing can each be held liable for the full damage, with recourse between them afterward.

Regulatory Crosswalk

UK GDPRLGPDSwiss FADP

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.