Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Key Stakeholders: Controller vs Processor (Art. 4.7, 4.8)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 19/54 Part 2 — Core Principles Intermediate Reviewed 2026-08-23

Key Stakeholders: Controller vs Processor (Art. 4.7, 4.8)

Stakeholder qualification rests on factual reality: who determines the purposes and essential means of the processing? The Controller decides; the Processor executes strictly on documented instruction

Open in interactive reader
⚖️ Factual Qualification 📋 EDPB Guidelines 07/2020

Key Stakeholders: Controller vs Processor (Art. 4.7 & 4.8)

⚡ In 30 seconds

The GDPR establishes a fundamental operational dichotomy: the Data Controller (Art. 4.7) determines the 'why' (purposes) and 'how' (essential means) of data handling. The Data Processor (Art. 4.8) is a distinct entity processing data solely under the documented instructions of the controller. Two entities jointly determining purposes become Joint Controllers (Art. 26).

Stakeholder Role Statutory Definition Primary GDPR Responsibility
Data Controller Art. 4(7): Natural/legal person determining purposes & means. Primary accountability, legal basis, transparency, user rights.
Data Processor Art. 4(8): Entity processing data on behalf of controller. Security measures (Art. 32), strict adherence to instructions (Art. 28).
Joint Controllers Art. 26: Two or more controllers determining purposes jointly. Transparent arrangement allocating respective GDPR obligations.
⚡ Key Takeaways
  • Substance over form: actual operational behavior overrides written contract headings.
  • A processor that exceeds instructions to repurpose data for itself becomes a de facto controller.
  • Direct liability: processors face administrative fines directly under Article 83 for Art. 28/32 breaches.
⚠️ Common Pitfall

Classifying an accounting firm or occupational physician as a processor when they operate under independent statutory obligations.

🛠️ In Practice

Systematically annex an Article 28 Data Processing Agreement (DPA) to any vendor contract touching personal data.

⚖️ Official Sources: Art. 4(7), 4(8), 26, 28 GDPR · EDPB Guidelines 07/2020 · CJEU C-210/16 Wirtschaftsakademie ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Data Controller (DC): determines the purposes and essential means of processing.
  • Data Processor (DP): processes personal data strictly on behalf and instructions of the DC.
  • An employee or team member acting within their enterprise duties is not a data processor (Art. 29).

⚠ Common pitfall: Blindly relying on contractual self-labels without evaluating the actual operational autonomy exercised by the technical vendor.

→ Actionable practice: Audit SaaS providers: third-party IT hosts are almost always processors requiring a bespoke Article 28 contract.

← Storage Limitation (Art. 5.1.e) Accountability & Proactive Responsibility (Art. 5.2 & 24) →