Statement of Guidance
Controller, Joint Controller, Processor or Secondary Processor?
Status not confirmedView on ODPA's website Source document
Summary
This is guidance from the Guernsey Office of the Data Protection Authority explaining how to determine whether an organisation is acting as a controller, joint controller, processor or secondary processor when working with personal data, since the role held determines the legal obligations that apply. It forms part of a wider suite of guidance on engaging processors and does not itself create new legal requirements, but it explains how existing obligations under the Law attach depending on role.
- Controller: The party that decides the purposes and means of processing personal data, e.g. what data to collect, why, and for how long.
- Processor: A party that processes personal data only on a controller's instructions and does not determine the purpose or manner of processing, though it may make technical implementation decisions if the contract allows.
- Secondary processor: A processor engaged by another processor to help carry out work assigned by the original controller.
- Joint controllers: Two or more controllers who jointly determine the purpose and means of processing the same personal data; each remains individually liable for compliance.
- Dual role: An organisation can be a controller for some processing and a processor for other processing, or even both for the same data if used for different purposes, provided it can distinguish between the two capacities operationally.
The guidance includes self-assessment checklists (appendices) and worked examples to help organisations classify their role in a given processing activity, noting that misclassification (e.g. failing to separate controller and processor functions) can result in being treated as a joint controller with fuller compliance obligations.
Key obligations
- Joint controllers must arrange between themselves who takes primary responsibility for complying with the Law, particularly transparency obligations and individuals' rights, and must make this arrangement information available to individuals
- A processor must only process personal data in accordance with the controller's instructions unless required to do otherwise by law, or it will be treated as a controller and bear controller-level liability for that processing
- An organisation acting as both controller and processor must maintain systems and procedures that clearly distinguish which personal data it processes in each capacity, applying different processes and measures accordingly, or risk being treated as a joint controller
Applies to
controllers, joint controllers, processors, secondary processors