Legal and Compliance

Data Controller and Data Processor

Also called controller, processor, joint controller

The controller decides why and how personal data is used; the processor handles it on the controller's instructions. Joint controllers decide together.

Quick facts: Data Controller and Data Processor

Category
Legal and Compliance
Also called
controller, processor, joint controller
Level
Intermediate
Affects
Privacy notices, supplier contracts, cookie consent, breach reporting, agency arrangements
Where to see it
ICO guidance on controllers and processors, Google and Meta data processing terms, supplier contracts
In this article4
  1. How the controller and processor roles work
  2. Why it matters for a UK business
  3. Common mistakes
  4. How to act on it

Under UK GDPR, a data controller is the organisation that decides why and how personal data is used, and a data processor is an organisation that handles that data on the controller’s behalf and only on its instructions. When two organisations decide those things together, they are joint controllers.

How the controller and processor roles work

The test is who makes the decisions, not what a contract calls each party. If you decide to collect enquiry form details so you can call people back, you are the controller. The company that hosts your form or stores your contacts is usually a processor, because it only does what its service and your settings tell it to. If that same company also uses the data for its own purposes, such as training its products or building its own audiences, it becomes a controller for that separate use.

Here is how the roles usually fall for common marketing tools. Always check the provider’s current terms, because the position depends on your settings and contract.

SituationUsual role of the other partyWhat you need in place
CRM or email platform storing your contactsProcessorA processing contract and a check of where data is stored
Google Analytics 4 on your siteProcessor for the measurement service; controller for any use you allow through data-sharing settingsGoogle’s data processing terms accepted and sharing settings reviewed
Meta Pixel or Conversions APIJoint controller with you for collecting and sending the data; controller for Meta’s own later useMeta’s controller terms accepted and the arrangement explained in your privacy notice
Agency or freelancer running your campaignsProcessor while acting on your instructionsA processing clause in the engagement terms

The joint-controller position for tracking pixels traces back to a 2019 EU court ruling about an embedded social plugin, given while the UK was still bound by EU law. The reasoning is simple: by placing the Meta Pixel on your site, you decide that visitor data will be collected and sent to Meta, so you share responsibility for that step.

Why it matters for a UK business

The role decides the duties. A controller needs a lawful basis, a privacy notice, a way to handle rights requests, a process for reporting notifiable breaches to the ICO within 72 hours, and processors chosen with care and bound by a data processing agreement. A processor must follow instructions, keep the data secure and tell the controller about breaches without undue delay. Joint controllers must agree who does what and make the essence of that arrangement available to the people concerned.

Getting it wrong has practical knock-on effects. If you treat Meta as a mere supplier, your privacy notice will understate where visitor data goes, and your cookie banner may not ask for the right consent. If an agency starts reusing your customer list for its own prospecting, it has stepped out of the processor role and you may have a data protection problem you did not create.

Common mistakes

  • Assuming that because you pay a supplier, it must be a processor.
  • Accepting default data-sharing settings in GA4 or ad platforms without reading what they allow.
  • Having no written processing terms with freelancers and agencies who log in to your CRM or ad accounts.
  • Listing tools in the privacy notice by vague category instead of naming the recipients and their role.
  • Forgetting that data uploaded for audience matching is also covered.

How to act on it

List every tool and supplier that touches personal data: website forms, analytics, ad pixels, CRM, email platform, booking system, call tracking and anyone with a login. For each, note its role, whether a contract is in place, where it stores data and which settings affect its role. Then update your privacy notice so it matches that list.

Review the list whenever you add a tool or change agency. My performance marketing work starts with this kind of tracking inventory, because measurement built on unclear roles and missing consent tends to fail later.

Do and do not

Do

  • Map every tool that touches personal data and its role
  • Read data-sharing settings in analytics and ad platforms
  • Put processing terms in agency and freelancer contracts

Do not

  • Assume every paid supplier is a processor
  • Treat Meta as a simple supplier when you use its pixel
  • Let an agency reuse your customer data for its own purposes

Questions people ask about this

Is Google a data controller or processor for Google Analytics?

For the core measurement service, Google describes itself as a processor acting on your behalf under its data processing terms. If you switch on data-sharing settings that let Google use the data for its own purposes, it acts as a controller for that use. Check your account's settings and the current terms rather than relying on a general answer.

Is my marketing agency a data processor?

Usually, yes, while it works on your data only to deliver what you asked for. If it uses your customer data for its own purposes, such as building audiences for other clients, it becomes a controller for that activity. Put written processing terms in the engagement contract so the boundaries are clear.

What does joint controller mean for a small business using the Meta Pixel?

It means you share responsibility with Meta for collecting visitor data on your site and passing it to Meta. You need consent before the pixel fires, your privacy notice should explain the arrangement, and you should accept Meta's controller terms. Meta is responsible on its own for what it does with the data afterwards.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.