This website uses cookies

Read our Privacy policy and Terms of use for more information.

A critical question for anyone working on deals with personal data is which party to the contract is the controller and which is the processor under European General Data Protection Regulation (GDPR). That determination tells us whether we need a data processing agreement (DPA) at all, who has to answer an individual asking about their data, and who bears primary responsibility.

Marta Hovanesian and Robby Reggers recently addressed this question during our webinar on GDPR requirements for negotiating DPAs, standard contractual clauses (SCCs) and vendor terms. The discussion focused on ways to help U.S. contract lawyers and teams understand the roles and requirements.

To help reinforce their valuable guidance, I created a video lesson and checklist specific to the controller and processor dynamics.

PART 1: PDF Checklist to Download

I created a three-page mini-checklist with my takeaways on GDPR controller and processor roles. You can use this as a shortcut to remember the most important things to know about assigning the roles and what impact that assignment has on the contract.

PART 2: Video Lesson on Controller and Processor Roles

Here's a link to watch this five-minute segment featuring one of my favorite moments from the webinar, when Marta explained the difference between controller and processor roles.

PART 3: Webinar Highlights

The webinar answered one of my main questions. How do you tell a controller from a processor in a contract?

Robby explained it this way. The controller is the company that holds the data and decides what happens to it. He keeps the employer in mind. An employer controls its employees' data and uses what is necessary in accordance with the law. The processor is the platform the employer puts that data into, and it does only what the employer said it can do with that data. Robby offered a second example. Netflix decides what to do with user data and which movies to present to you and how. You cannot change that, so Netflix controls it.

Marta suggested looking at the controller versus processor role through the lens of who decides what data is processed, whose data it is, who gets access, whom it is shared with, and how long it is stored. Marta added that we should also look at whether a legal obligation to process the data exists. The law often names the controller in that situation. An employer has legal requirements to process employee records, and Marta said that reason alone makes the employer a controller.

Join us at ContractsCon 2026 for a full training day on AI contract drafting

ContractsCon 2026 includes five training sessions on critical provisions in AI product contracts. Join us in Philadelphia on October 13-14 and virtually on October 21-22. You'll learn from our AI contracting experts and practice drafting revisions with your small group. Don't miss out on the contract training event of the year! Prices go up soon.

PART 4: 3 Things I Learned From the Webinar

Here are three things I learned from the webinar’s discussion:

1. A contract party can be a processor and a controller in the same relationship

Robby told a story about a large company where everyone assumed the company was a processor. A new data protection officer spent her first month reviewing the documents and reached a different conclusion. For one part of the services, the company was a controller. The company then had to update all of its contracts. Robby's point is that the details decide the role, and a privacy lawyer needs to check them rather than accept what everyone assumes. He also noted that controller-to-controller relationships exist.

2. The role decides whether the deal needs a DPA

Robby uses the simplest version of the rule. A processor means you need a DPA. Two controllers means no DPA in principle. He said he got this wrong himself ten years ago and told people they needed a DPA when both parties were controllers. Marta added that a processor can only process on the controller's documented instructions, and the services agreement scopes those instructions. If a processor stops following them, the law moves it into the controller role automatically.

3. Joint controllers and co-controllers need different things

Marta explained how joint controllership happens. A multinational group has local entities that legally employ the staff, and a parent company that runs the human resources system, runs analytics on employee data, and decides where to send people. Both have a say in how the data is processed, so there can be a joint controllership. She distinguished co-controllers, where there is no joint decision-making and each party controls a separate part of the processing. Marta said real joint controllership looks like a joint marketing effort between two companies, where neither one follows the other's instructions and their interests are inextricably linked.

Joint controllers do not need a DPA. What they need is an arrangement covering who handles what. Marta listed the questions it answers. An individual has a question about an email they received, so which of the two parties do they contact, and how do you communicate that. A data breach happens, so who resolves it. Both parties process the data for their own purposes, so how do you cooperate on GDPR compliance. The arrangement does not have to be a contract, though Marta said a contract is the easiest way. A written document or an email also works. The substance does have to be public, on your privacy notice or a sign-up page, so individuals know who to approach.

Marta finished the discussion with a point about liability. An individual can claim the full amount from either joint controller. That makes it worth deciding between yourselves how you handle liability, and putting those provisions in the commercial agreement.

Want to learn more? Read this article with 10 takeaways from the full webinar.

Join our membership to access this and all 120+ contract training webinars we’ve offered since March 2025.

How to Contract members have access to all our webinars. That includes 80+ webinars recorded in 2026 so far plus 40 webinars on AI contract drafting in 2025. That is just part of our library with over 260+ hours of training videos from the last five years of How to Contract contract training programs. Plus members access our 12 courses, including certification courses on NDAs and indemnification. If you are looking to uplevel your or your team’s contract skills, it’s worth checking out.