Reinier Russell

managing partner

Reinier advises national and international companies

reinier.russell@russell.nl
+31 20 301 55 55

GDPR: Are you a processor or a controller?

Publication date 12 November 2018

Since the GDPR has entered into force, companies have been breaching the new privacy legislation on a large scale. This is mainly caused by ignorance. Companies are often confused about the terms controller and processor when processing personal data. This may lead to incorrect fulfilment of the obligations arising from the mandatory processing agreement.

persoonsgegevens - ubo

On 25 May 2018, the General Data Protection Regulation (GDPR) entered into force. This European privacy regulation includes rules for (automatic) processing of personal data. By now, several months have passed and it turns out that companies unintendedly breach the new legislation often and on a large scale. In particular, it is unclear when one qualifies as a “processor” of personal data and when as a “controller”. This is crucial when it comes to introducing a Privacy Statement and concluding the required processing agreements. So how are the roles defined exactly?

General Data Protection Regulation (GDPR)

The new European privacy legislation is intended to protect the privacy of EU citizens. The GDPR applies to all companies and institutions holding and processing personal data of EU citizens both within and outside the EU.

The GDPR requires organisations to make clear in advance which personal data they will be processing, for which purposes, who the personal data might have to be shared with, and how long personal data will be stored. This can be done by means of a Privacy Statement on the website of the organisation.

Who is a controller?

The controller is the organisation who, alone or jointly with others, will establish the purpose for and means of personal data processing. This person decides “why” and “how” personal data will be processed.

Under the GDPR, the controller is accountable; this means the organisation must be able to demonstrate that it complies with the GDPR rules. Part of this could be the aforementioned Privacy Statement on the company website. As almost every company processes personal data – even if it’s just the data of their own personnel – you will soon qualify as a controller.

Who is a processor?

The processor is the party engaged by the controller to process personal data. In this situation, the controller defines ”what” has to be done and “how” it has to be done. It is important that the person who processes the data is not under the direct authority of the controller. An employee of the organisation itself will not be considered as a processor under the GDPR. Usually, the processor will be a party outside of the enterprise. Here are a few (easy) examples:

  • An administrative office engaged to process salary payments.
  • A cloud service provider offering IT solutions.

Under the GDPR the processor has several new obligations. Permission must be asked for hiring another processor (a so-called “sub-processor), data leaks must be reported and processing lists must be made.

Difficult cases

Sometimes it is rather difficult to say whether you deal with a “processor”’. A key factor is that there must be assessed how much scope a service provider has to determine what it does. As a processor you don’t have any control over the data processing. The processor may only act under the responsibility of the controller and upon its instructions. When the processor takes decisions by itself about the purposes and means of the processing it will become responsible for the (new) processing of data. This means, just the fact that you will get an assignment from a controller is not sufficient to qualify as a “processor”.

Some examples:

  • A cloud service provider provides a fitness-app for companies and for this purpose processes the personal data of members. The cloud service provider will qualify as a controller as it determines which kind of personal data will be processed and how they are used.
  • A cloud service provider offers data storage only. The cloud service provider will qualify as a processor as it will process the personal data on behalf of and upon instruction of the controller.

The decisive factor is thus: How much scope does the service provider have to independently determine the purposes and means to perform its task(s)?

Controller and processor

Organisations can be both processor and controller. The aforementioned administrative office which processes the personal data of others will also be the controller of the personal data of its own employees.

Processing agreement

Under the GDPR, the processor has been given several new independent obligations. The most important ones – which create a lot of confusion – must be included in the processing agreement. The purpose of the processing agreement is to lay down which data processing will be carried out by a processor on behalf of a controller.

Both controller and processor can be held accountable for the absence of the agreement. This means, both are required to conclude a processing agreement subject to a fine.

Content of processing agreement

A processing agreement mainly contains the obligations of a processor, such as:

  • Personal data are to be processed solely on the basis of written instructions from the controller.
  • Ensuring that employees processing personal data comply with confidentiality.
  • Taking suitable technical and organisational measures for the protection of the processing and, where possible, assisting the controller in doing so.
  • Requesting permission for hiring another processor (“sub-processor”).
  • Answering requests regarding the rights of data subjects under the law.
  • Deleting or returning of personal data, or deleting of existing copies upon completion of processing services.
  • Making available all information to the controller during inspections or to demonstrate the controller fulfils its obligation to use best efforts.

In addition, the following has to be included in a processing agreement:

  • the subject
  • the duration of processing
  • the nature and purposes of processing
  • the type of personal data
  • the categories of data subjects (persons whose data are processed)
  • the rights and obligations of the processor and controller.

Difficult cases

In practice, it is often unclear to companies who is a “processor” and who is a “controller”. As a result, in agreements the roles are often reversed and the person who places an order will be qualified as “processor”. As these persons have different responsibilities towards each other it is crucial to accurately determine whether you are a processor or a controller.

Fines in the event of a breach

By now, the GDPR has been in force for several months. Under the GDPR, the controller and processor are required to comply with the stipulations of the regulation. If companies do not (yet) comply with the new legislation, they could be fined by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens; AP). The penalty can be up to 20 million euros or 4% to the global annual turnover if that amount is higher.

Our advice

  • Make sure to always conclude a processing agreement if you have third parties process personal data.
  • Get legal advice if you are not sure whether you are a processor or controller.

More information

Would you like to know whether your company is “GDPR proof”? Would you like Russell Advocaten to draft a processing agreement or check your existing agreements? Please contact us:

    We process the personal data above with your permission. You can withdraw your permission at any time. For more information please see our Privacy Statement.

    Related publications

    Is your staff management ready for the GDPR?

    At the end of the week, on 25 May 2018, the General Data Protection Regulation (GDPR) comes into force. This does not just have consequences for your website or online shop but also for your staff management. Is it ready for the GDPR?

    Read more

    Privacy: New European Data Protection Regulation

    In this newsletter Russell Advocaten will inform you, in short, about the most important changes to be expected in the European data protection regulations. More detailed information on this topic can be found in our previous newsletters.

    Read more

    25 September 2024: Cybersecurity and Data Protection in Litigation

    Wednesday 25 September 2024, Reinier Russell will discuss cybersecurity and data protection in litigation at the European meeting of the World Litigation Forum in Barcelona.

    Read more

    Expedited liquidation

    Expedited liquidation is a quick way to terminate a legal entity. However, the scheme was also abused, disadvantaging creditors. A new law should prevent this. What requirements does an expedited liquidation have to meet from now on? And what options do creditors have to collect their claims?

    Read more

    4 steps for terminating a BV

    Entrepreneurs may have various reasons for ending their businesses. Expected profits may be disappointing, retirement may be approaching or a partnership (joint venture) may be ending. What should entrepreneurs bear in mind when terminating a business?

    Read more

    Foreign judgments in the Netherlands

    In principle, the enforcement of foreign judgments is a national matter. But what if a dispute has already been dealt with by a foreign court? Can such a foreign judgment be enforced in the Netherlands or not?

    Read more