Under UK GDPR, a data controller is the organisation that decides why and how personal data is used, and a data processor is an organisation that handles that data on the controller’s behalf and only on its instructions. When two organisations decide those things together, they are joint controllers.
How the controller and processor roles work
The test is who makes the decisions, not what a contract calls each party. If you decide to collect enquiry form details so you can call people back, you are the controller. The company that hosts your form or stores your contacts is usually a processor, because it only does what its service and your settings tell it to. If that same company also uses the data for its own purposes, such as training its products or building its own audiences, it becomes a controller for that separate use.
Here is how the roles usually fall for common marketing tools. Always check the provider’s current terms, because the position depends on your settings and contract.
| Situation | Usual role of the other party | What you need in place |
|---|---|---|
| CRM or email platform storing your contacts | Processor | A processing contract and a check of where data is stored |
| Google Analytics 4 on your site | Processor for the measurement service; controller for any use you allow through data-sharing settings | Google’s data processing terms accepted and sharing settings reviewed |
| Meta Pixel or Conversions API | Joint controller with you for collecting and sending the data; controller for Meta’s own later use | Meta’s controller terms accepted and the arrangement explained in your privacy notice |
| Agency or freelancer running your campaigns | Processor while acting on your instructions | A processing clause in the engagement terms |
The joint-controller position for tracking pixels traces back to a 2019 EU court ruling about an embedded social plugin, given while the UK was still bound by EU law. The reasoning is simple: by placing the Meta Pixel on your site, you decide that visitor data will be collected and sent to Meta, so you share responsibility for that step.
Why it matters for a UK business
The role decides the duties. A controller needs a lawful basis, a privacy notice, a way to handle rights requests, a process for reporting notifiable breaches to the ICO within 72 hours, and processors chosen with care and bound by a data processing agreement. A processor must follow instructions, keep the data secure and tell the controller about breaches without undue delay. Joint controllers must agree who does what and make the essence of that arrangement available to the people concerned.
Getting it wrong has practical knock-on effects. If you treat Meta as a mere supplier, your privacy notice will understate where visitor data goes, and your cookie banner may not ask for the right consent. If an agency starts reusing your customer list for its own prospecting, it has stepped out of the processor role and you may have a data protection problem you did not create.
Common mistakes
- Assuming that because you pay a supplier, it must be a processor.
- Accepting default data-sharing settings in GA4 or ad platforms without reading what they allow.
- Having no written processing terms with freelancers and agencies who log in to your CRM or ad accounts.
- Listing tools in the privacy notice by vague category instead of naming the recipients and their role.
- Forgetting that data uploaded for audience matching is also covered.
How to act on it
List every tool and supplier that touches personal data: website forms, analytics, ad pixels, CRM, email platform, booking system, call tracking and anyone with a login. For each, note its role, whether a contract is in place, where it stores data and which settings affect its role. Then update your privacy notice so it matches that list.
Review the list whenever you add a tool or change agency. My performance marketing work starts with this kind of tracking inventory, because measurement built on unclear roles and missing consent tends to fail later.
