EDPB 07/2020
Guidelines 07/2020 on the concepts of controller and processor in the GDPR
What it covers
This document provides detailed interpretation of the concepts of controller, joint controller, processor and third party/recipient under the GDPR, and explains the consequences of these roles, including the required content of processor contracts under Article 28 and the arrangements joint controllers must put in place under Article 26.
Why it matters
Correctly identifying controller, joint controller and processor roles determines which party bears which GDPR obligations, making this a foundational reference for structuring data processing relationships and contracts.
Refer to it when
- determining whether an entity is a controller, joint controller or processor
- drafting or reviewing a data processing agreement
- allocating responsibilities in a joint controllership arrangement
- assessing whether a processor has become a controller by exceeding instructions
Questions this document addresses
- What distinguishes a controller from a processor?
- When do two or more entities become joint controllers?
- What must a processing contract under Article 28 contain?
- How should joint controllers allocate and transparently document their respective responsibilities?
Topics
- Controller & processor
- Security of processing
- Personal data breaches
- International transfers
Defines controller, joint controller, processor and third party, explains how to determine who decides purposes and means, and sets out the consequences of each role including the required content of controller-processor contracts and joint controller arrangements.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.