Privacy
Interactive role check

Role check: controller, processor or joint controller?

Classify your role in a processing activity as controller, processor or joint controller. The check shows which questions and documents matter for the next review.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

The label used in an agreement does not decide the role on its own. The key questions are who determines the purposes and essential means of processing and whether another organisation processes data only on documented instructions.

Mag. Bernhard Brandauer, Rechtsanwalt

Interactive role check

Role check: controller, processor or joint controller?

Classify your role in a processing activity as controller, processor or joint controller. The check shows which questions and documents matter for the next review.

01 Question 1

Who decides why the personal data is used?

Ergebnis

Ihre Orientierung

01

Likely controller

Your answers suggest that your organisation sets the purposes and essential means of processing. Responsibility for the legal basis, transparency, data subject rights and appropriate security measures therefore generally rests with your organisation.

Review the records of processing, privacy information, legal basis and responsibilities for data subject requests together with the process.

02

Likely processor

Your answers point to processing on behalf of another organisation and within documented instructions. It remains important to check that your organisation does not pursue its own purposes and which decisions the agreement or actual practice leaves to you.

Compare the service description, instructions, security measures, sub-processors and the Article 28 GDPR agreement.

03

Review joint controllership more closely

Your answers indicate that several organisations determine purposes or essential means together. Responsibilities should then be set out transparently. The arrangement must still allow data subjects to exercise their rights effectively.

Document the joint purposes, each organisation’s decisions, information duties and allocation of responsibilities under Article 26 GDPR.

04

Clarify the role and actual processes first

Your answers contain conflicting or open points. A contract label alone cannot establish the role. Compare the actual data flow, decision-making powers and use of the data with the available documents.

Record the data flow, purposes, systems, instructions and own uses in a short process description, then compare it with the legal requirements.

A useful next step

Secure the agreement, instructions and a short description of the actual data flow. This makes it possible to discuss whether the roles, responsibilities and security requirements align.

Documents for the review

  • Agreement and schedules, including the service description
  • Instructions, process description and data flow
  • Records of processing activities and privacy information
  • Access and security concept
  • List of sub-processors

Legal framework

  • Articles 4(7) and 4(8), 26 and 28 GDPR
  • Sections 46 to 48 Austrian Data Protection Act
  • EDPB Guidelines 07/2020 on controller and processor concepts

Controller and processor

Under Article 4(7) GDPR, the controller determines the purposes and means of processing, alone or jointly with others. A processor processes personal data on behalf of the controller. The role therefore follows the actual decision-making and use of the data, not merely a heading in an agreement.

Joint controllers

Where two or more organisations jointly determine the purposes and means, Article 26 GDPR may apply. The parties should transparently allocate responsibilities for information, data subject rights and other duties, and make the substance available to data subjects.

Align the agreement with practice

The agreement is only one part of the review. Useful material includes the data flow, process description, roles and access rights, instructions, security measures, sub-processors and any use of the data for the organisation’s own purposes. Differences between the documents and practice should be addressed before the next rollout.

Is calling a party a processor in the agreement enough?

No. The label is an indication, but it does not replace an assessment of the actual purposes, means, instructions and use. If a service provider pursues its own purposes or determines essential means, the role may be different.

Is an IT service provider always a processor?

Not automatically. The answer depends on the service, data access, instructions and whether the provider determines its own purposes or essential means. Technical access alone does not settle the role.

What should a joint controller arrangement cover?

Article 26 GDPR requires a transparent allocation of responsibilities. The exercise of data subject rights and the information duties under Articles 13 and 14 GDPR are particularly important. The arrangement should match the actual cooperation.

Subscribe to legal updates

Receive new articles and practical legal information from the firm with BRANDaktuelle Rechtsnews.

Subscribe to legal updates →

Processors and service providers

Agreements, instructions and security requirements for external service providers.

Privacy compliance and governance

Structure privacy organisation and responsibilities in your business.

Contact

Discuss the documents for a specific role review.

First orientation, not a binding role determination. The outcome depends on the specific agreements, data flows, decision-making powers and actual processes.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich