The short answer
Responsibility follows real decision-making, not the label in a contract. Whoever decides why personal data on a site is processed and the essential how — what footage is captured, how long it is kept, who can see it — is the controller. If two organisations decide these things together, they are joint controllers. A company acting only on documented instructions is a processor, with narrower but real duties. Misclassify the role and you can still be held liable.
Key takeaways
- Classification is decided by facts — who actually determines purpose and essential means — not by a contract label, and regulators can reclassify roles during an investigation.
- The controller carries the heaviest load: responsibility for the data protection principles, transparency, data subject rights, impact assessment and the compliance of its processors.
- A processor may act only on documented instructions but has its own duties: security, helping the controller, notifying about incidents and obtaining authorisation before appointing sub-processors.
- If a processor determines the purpose or essential means itself, it leaves its role and is treated as a controller for that processing.
- Joint controllers must allocate duties in a transparent written arrangement, yet a data subject can turn to any of them, and liability need not be equal.
- The role is assessed per processing activity, so the same organisation can be a controller on one part of a site and a processor on another.
The one test that decides your role
On any site — a retail park, a warehouse, a campus, a residential block with cameras — data processing usually starts with video surveillance and access control. Before asking what you must do, you need to answer who you are in each processing operation. Under the GDPR and UK GDPR this turns on two things: the purpose (why you process) and the means (how you process).
The subtlety sits inside the means. Essential means are the decisions about which data are collected, who can access them and how long they are kept — these belong to the controller. Non-essential means are technical implementation, such as choosing which video recorder software to run, and may be left to a processor. This boundary is where many disputes begin.
The role is assessed per processing activity and in substance, not on paper. One site operator can be a controller for its own cameras and a processor for a tenant's camera it operates on instructions.
- Purpose = why: security, incident investigation, time and attendance.
- Essential means = which data, who may see them, how long we keep them.
- Non-essential means = which software or hardware we use to deliver the result.
Controller: why the heavier burden is yours
A controller is the organisation that determines the purpose and the essential means of processing. It carries the highest level of compliance responsibility: it must comply with, and be able to demonstrate compliance with, the data protection principles, ensure transparency and respond to data subjects exercising their rights.
On a site this translates into concrete choices: how many days recordings are kept, which staff can review the archive, where footage is released after an incident, and whether a data protection impact assessment is needed for high-risk processing such as systematic surveillance of people.
A controller does not have to physically hold the data to be the controller. Even when footage sits in a cloud provider's storage, the controller is the party deciding the purpose and the essential parameters. The controller is also accountable for the processors it engages and for checking the guarantees they offer.
Processor: narrower duties, real liability
A processor handles data on behalf of a controller and strictly on documented instructions. A typical example is a security firm monitoring cameras under a site owner's instruction, or a cloud video provider hosting the archive.
Yet processors carry obligations of their own: they must ensure security and confidentiality, assist the controller with data subject requests and impact assessments, notify the controller without undue delay of breaches, and obtain authorisation before bringing in sub-processors. A written contract covering the Article 28 requirements is mandatory between controller and processor.
The boundary matters for liability. If a processor itself decides the purpose or the essential means — for example, choosing on its own who may view recordings and for its own commercial benefit — it steps out of the processor role and is treated as a controller for that activity, with a controller's obligations.
Joint controllers: deciding together, accountable to each data subject
Joint controllership exists when two or more organisations together determine both the purpose and the means of a single processing operation. A common site example is a building owner and an operating tenant who jointly install a shared camera system in a lobby or car park and together decide which areas are covered, who reviews the archive and how long it is kept.
Joint controllers must transparently and in writing allocate their responsibilities under Article 26 — who informs people, who answers rights requests, who manages security and breaches. This arrangement does not reduce anyone's overall responsibility.
The practical point: a data subject can exercise rights against any of the joint controllers regardless of the internal split. Liability does not have to be equal and is assessed on each party's actual contribution to the operation. Two organisations processing the same data for their own separate purposes are usually not joint controllers but separate controllers.
Applying the roles on a real operating site
Practice comes down to mapping: take each processing activity on the site and honestly record who determines its purpose and essential means. For perimeter cameras the answer is often the owner or managing company; a security firm running monitoring on instruction is the processor; a cloud vendor is a processor or sub-processor.
The danger zone is a contractor going beyond simple execution. If a security company decides on its own which footage to analyse for its own commercial aims, or an integrator sets capture scope and retention without the customer, the likely findings are joint controllership or that the contractor became a controller for that part.
Courts and regulators have repeatedly found joint controllership where parties shared the benefit and influenced the parameters even when a contract called one side a processor. Document your reasoning about classification rather than simply signing labels.
- List every operation: perimeter/car park, lobby, till, access control, visitor log.
- For each, record who decides why, which data, who may see it and retention.
- Classify: sole controller, joint controllers, or processor on instructions.
- Save the reasoning and the conclusion; when in doubt, involve your DPO or counsel.
Where classification commonly goes wrong
Common mistakes include believing the contract determines the role; assuming that holding the data makes you the controller (it does not); confusing joint controllership with two separate controllers sharing data; and thinking a processor is accountable for nothing.
Reclassification has real consequences: duties you never performed as a controller — records of processing, a DPIA, answering data subjects — become violations, and a processor that exceeded its instructions is assessed as a controller. Supervisory authorities are not bound by the parties' contractual labels and look at actual influence over the processing.
Jurisdiction matters. The roles described here — controller, joint controller, processor — are concepts of the GDPR (EU) and UK GDPR (UK). Other legal systems differ, so confirm which law applies to your operation. This article is general information, not legal advice for any specific case or jurisdiction.
Put it into practice
Site role-mapping worksheet: who is controller, joint controller or processor
Fill in one row for every processing activity on your site — perimeter and car park cameras, lobby, access control, visitor log, cloud archive. Answering the five prompts gives you a reasoned classification you can keep as evidence of your analysis.
- Activity and data: which cameras or systems and what personal data (video, stills, access records) are involved.
- Who set the purpose (why): security, investigation, attendance, marketing? Name the organisation.
- Who set the essential means: coverage zones, who can access the archive, retention period?
- Does a second organisation jointly take these decisions with you (shared system design or operation)?
- Conclusion for the activity: sole controller / joint controllers / processor on instructions.
- Paperwork: is there an Article 28 contract (processor) or an Article 26 arrangement (joint controllers)?
- Risk check: is a DPIA required and who carries it out.
- Transparency: who informs data subjects and who handles requests to exercise rights.
- Record: date, person responsible for the analysis and any DPO or legal consultation.
Questions people ask
What is the difference between a controller and a processor if both signed the same contract?
The difference lies in the actual role, not the contract. The controller determines the purpose of the processing and its essential means: what data are collected, who may access them and how long they are kept. The processor acts on documented instructions from the controller and may choose only non-essential technical details, such as which software to use. Regulators examine the real allocation of influence and can reclassify the parties regardless of the wording in the contract.
When do two organisations become joint controllers on the same site?
Joint controllership arises when two or more organisations together determine both the purpose and the means of one processing operation. For example, a building owner and an operator jointly install a camera system in shared areas and together decide coverage, who may access the archive and how long recordings are kept. If they process the same data for separate purposes of their own, they are usually separate controllers rather than joint controllers.
Is a written arrangement required for joint controllers and what should it contain?
Yes. Under Article 26 of the GDPR, joint controllers must transparently allocate their responsibilities in writing. The arrangement should set out who informs data subjects, who handles rights requests, who is responsible for security and breach notification, and who carries out impact assessments. A data subject may exercise rights against any of the joint controllers regardless of the internal allocation, and liability can be unequal depending on each party's actual contribution.
Can a processor turn into a controller?
Yes. If a processor starts determining the purpose of the processing or its essential means, going beyond the controller's documented instructions, it is treated as a controller for that activity and bears the corresponding duties and liability. A typical site scenario is a security or integration firm using footage for its own commercial ends or deciding on its own who may view and how long to keep the video.
How can an organisation prove it classified its role correctly?
By documenting the reasoning behind the classification for each processing activity, together with the supporting paperwork. That means a written record of who determines purpose and essential means, an Article 28 contract where a processor is used, an Article 26 arrangement where controllers are joint, and a completed DPIA where high-risk processing requires one. Because supervisors assess facts rather than labels, a documented, good-faith analysis shows diligence and makes later reclassification easier to defend.
Is this article about the GDPR only, or does it apply worldwide?
The controller, joint controller and processor roles described here are legal concepts of the EU GDPR and the UK GDPR. Many countries have their own data protection laws with different terminology and obligations — for example a single 'operator' concept in Russia's 152-FZ regime rather than a controller/processor split. You should confirm which law applies to your operation and its data subjects. The content is general information and is not a substitute for legal advice in any specific jurisdiction.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Responsable du traitement, sous-traitants : comment bien identifier son rôle ?CNIL (Commission nationale de l'informatique et des libertés)
- Les rôles et responsabilités dans la protection des données (qualification juridique des acteurs)CNIL (Commission nationale de l'informatique et des libertés)
- Controllers and processors (UK GDPR guidance)Information Commissioner's Office (ICO)
- Controllers, joint controllers and processors (political campaigning guidance)Information Commissioner's Office (ICO)