For the complete documentation index, see llms.txt. This page is also available as Markdown.

Is your business a data controller or a data processor?

Contents

1. What is a data controller?

If your business is making decisions about what personal data is processed, why it is processed, and how it is processed, then it is likely a data controller under the GDPR.

  • For example, if your business runs an app which collects patient symptoms to provide health recommendations, you decide what data to collect, why to collect it and how to collect it. This makes your business a data controller.

2. What is a data processor?

If your business performs operations on personal data on behalf of a data controller (who has made the decisions about the whys and hows of that processing), it is a data processor under the GDPR.

  • For example, if hospitals use your platform to store patient records, your business is processing personal data on their behalf. This makes your business a data processor.

In practice, given the broad definition of processing, if your business is a data controller it is likely also a data processor. However, the processor role under the GDPR is really designed to capture a separate entity that processes personal data on the controller’s behalf.

  • For example, if your app analyses patient symptoms using a third-party AI system, that AI system provider is working as your data processor.

Data processors might also engage third parties to assist with data processing on behalf of the originaln controller. These entities are known as subprocessors under the GDPR. Here, we explore the role and obligations of subprocessors and their linked controllers.

Last updated