Saltar al contenido

Glossary

Controller and processor

Two words used as synonyms that mean very different things: one decides, the other executes.

Updated on 13/08/2026

These are the two figures the whole of data protection law rests on, and in everyday conversation they are used interchangeably. The difference is not about size or importance: it is about who makes the decision.

Controller

Whoever decides what data is collected, what for and for how long. Normally, your company.

Processor

Whoever handles that data following your instructions, because you hired them to. Normally, the tool's provider.

What falls to each of them

DecisionWho makes itWhat it means in practice
What data is asked of a supplierYouAsking for too much is also a decision
What it is used forYouUsing it for something else later is not automatic
How long it is keptYouThe tool keeps what you tell it, for as long as you tell it
How it is protected technicallyThe providerEncryption, access, backups, isolation between clients
Who can get inside your accountYouPermissions are given and taken away by you

Important

The costliest mistake is assuming that **hiring a good tool transfers the responsibility**. It does not. The provider answers for protecting what you entrust to it and for doing only what you ask; deciding what is kept, what for and until when remains yours, and it is exactly what gets checked when somebody asks.

What is worth demanding from a provider

Watch out

That last point surprises people: **a processor usually relies on other processors** — hosting, email, messaging. That is not irregular, but you are entitled to know about it, and you are the one who will be asked, not them. When a large client sends its questionnaire, the question lands at your door.

In practice this turns into one very concrete decision when setting up any tool: do not switch on fields «just in case». Every field you ask for is data you must justify, safeguard and eventually delete.

Worth knowing

How this translates into specific documents, contracts and deadlines depends on your case and the framework that applies to you — the **GDPR** for anyone operating in Europe, among others. **Your adviser settles that**; here we only explain who is who so the conversation starts on the right foot.

If the provider suffers an incident, am I liable?

Each side answers for its own part, which is why it matters to have written down who owed what.

Can I ask them to delete everything?

Yes: they work on your instructions, and that includes the end of the relationship.

What if two companies decide together?

That figure exists and changes the obligations; it is a conversation for your adviser.

A real case

The situation

A client asks a company who handles its data and under what safeguards.

What you do

  1. Answers with its own collection and retention criteria, attaching what the provider supplies

What you get

The answer comes from whoever decides, which is who owed it.

The situation

A client asks how long their data is kept.

What you do

  1. Answers with their own retention policy

What you get

Whoever decides answers, not whoever executes.

The situation

A question that belongs to the company is passed to the provider.

What you do

  1. Distinguishes what each party decides

What you get

The answer comes from whoever can give it.

The situation

A provider's safeguards must be evidenced to a client.

What you do

  1. Attaches the documentation the provider supplies

What you get

The provider's material is supplied without assuming their role.

The situation

A contract is signed without defining who decides what.

What you do

  1. Clarifies it with the adviser before signing

What you get

The split is written down before it is needed.

The situation

A third party asks the provider for data directly.

What you do

  1. The request is redirected to whoever decides

What you get

The decision chain is respected.

This article answers

  • difference between controller and processor
  • who is the data controller if I use a platform
  • what is a data processor
  • is the provider responsible for my data