GuidelinesFinal · v1.0Adopted 2021-07-07

EDPB 07/2020

Guidelines 07/2020 on the concepts of controller and processor in the GDPR

What it covers

This document provides detailed interpretation of the concepts of controller, joint controller, processor and third party/recipient under the GDPR, and explains the consequences of these roles, including the required content of processor contracts under Article 28 and the arrangements joint controllers must put in place under Article 26.

Why it matters

Correctly identifying controller, joint controller and processor roles determines which party bears which GDPR obligations, making this a foundational reference for structuring data processing relationships and contracts.

Refer to it when

  • determining whether an entity is a controller, joint controller or processor
  • drafting or reviewing a data processing agreement
  • allocating responsibilities in a joint controllership arrangement
  • assessing whether a processor has become a controller by exceeding instructions

Questions this document addresses

  • What distinguishes a controller from a processor?
  • When do two or more entities become joint controllers?
  • What must a processing contract under Article 28 contain?
  • How should joint controllers allocate and transparently document their respective responsibilities?

Topics

  • Controller & processor
  • Security of processing
  • Personal data breaches
  • International transfers

Official EDPB page for this document

Defines controller, joint controller, processor and third party, explains how to determine who decides purposes and means, and sets out the consequences of each role including the required content of controller-processor contracts and joint controller arrangements.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.