Data Controller versus Processor: The Difference for Our Own Assessment
As a HeadFirst employee, you process personal data of professionals, candidates, and clients on a daily basis. This article explains the difference between a data controller and a processor, how to recognize this difference when setting up or assessing a collaboration, and what role the processing agreement plays in this.
Why this distinction matters for your work
When setting up or assessing a collaboration, you help determine who has which role in the processing of personal data. Data controller and processor are two different roles under the GDPR, with different legal consequences. If you assess this incorrectly, you risk an incorrect qualification of the collaboration, with possible consequences for GDPR compliance and for our client.
What is personal data
Personal data is any data that says something about an identified or identifiable natural person. So it's not just about a name, but about any piece of data that can be traced back to a person, directly or indirectly. Think of:
- Name, address, date of birth, and contact details
- Email address, phone number, and IP address
- CV, work experience, education details, and assessments
- Social security number (BSN), financial data, and passport photos
- Some personal data is extra sensitive: so-called special categories of personal data, such as data about health, ethnic origin, religion, or trade union membership. If you come across this in a CV or job application, handle it with extra care.
What is processing
Processing is a broad concept: it covers virtually any action you carry out with personal data, whether automated or not. Think of collecting, storing, consulting, altering, sharing, linking to other data, and even deleting. So even simply viewing a CV or forwarding an application to a client is a form of processing.
Examples from daily practice at HeadFirst:
- Receiving and storing a CV in our system
- Matching a professional's details to an assignment
- Carrying out a screening or assessment
- Sharing data with a client or supplier
- Because the concept is so broad, you essentially always fall under the GDPR as soon as you work with personal data.
What is a data controller
A data controller is the party that itself determines the purpose and means of a processing of personal data. This party therefore determines why data is processed and in what way. There is controllership when the following characteristics apply:
- The party itself determines why personal data is processed (the purpose)
- The party itself determines what that processing looks like (the means)
- The party bears responsibility for GDPR compliance for that processing
Consider HeadFirst using a professional's data to match them with an assignment. We ourselves determine why and how we use that data for that purpose. That makes us the data controller for that processing. In most cases, HeadFirst qualifies as the data controller.
What is a processor
A processor processes personal data on behalf of and under the instructions of a data controller, without having a purpose of its own for doing so. The processor follows the instructions of the data controller. Characteristic of a processor:
- The processing takes place solely according to the instructions of the data controller
- The processor has no purpose of its own for the use of the data
- The division of responsibility between the parties is laid down in a data processing agreement
Consider an IT supplier that merely hosts or processes data in a system we use. This supplier does not determine why the data is processed; it only carries out what we instruct it to do.
The key difference
It comes down to who determines the purpose and means of the processing. Does a party itself determine why and how personal data is processed? Then it is probably a data controller. Does a party process solely on instruction, without a purpose of its own? Then it is a processor.
Important to remember in your assessment: it is not the name of the agreement that is decisive, but the actual, factual situation. Does a contract call a party a "processor," but does this party, in practice, still determine itself why and how data is used? Then this can still qualify as (joint) controllership. Pay attention to this when drafting contracts and in conversations with clients and suppliers.
The role of the data processing agreement: instruction versus own purpose
The way a party handles data also gives an important signal about the nature of its role.
Does a party work under a processing agreement and process personal data solely on the basis of instructions, without a purpose of its own? Then this fits the role of processor. The processing agreement then sets out which data is processed, for what purpose, and which security measures apply.
Does a party itself determine how and why the data is processed, independently of another party's instructions? Then this fits the role of data controller, even if the contract calls it a "processor." The risk of an incorrect allocation of responsibility then lies with the party that drafted the contract this way.
Watch out for this combination
Does a party work under a processing agreement, but does it still determine the purpose of the processing itself — for example, by also using the data for its own analyses, marketing, or product development? Then this is a signal that the role of this party actually leans toward (joint) controllership. A purpose of one's own for the use of data often indicates independent direction over the processing, rather than execution on instruction. Flag this in good time, even if the agreement itself refers to it as a processing agreement.
Why this is relevant to the GDPR
The General Data Protection Regulation (GDPR) requires every party that processes personal data to organize this processing on the correct legal basis and according to the correct division of roles. If we assess a collaboration incorrectly, the client, the partner, and HeadFirst risk:
- An incorrect qualification of the processing and the associated responsibilities
- The absence of a proper processing agreement where one is actually required
- Fines of up to €20 million, or 4% of worldwide annual turnover if that is higher, per infringement
Does a party work under a processing agreement, but does it nevertheless determine the purpose and means of the processing itself in practice? Then this may still fall under controllership, even if the agreement does not describe it that way.
How to assess a collaboration
In case of doubt, ask the following questions:
- Does the party itself determine why and how personal data is processed? Then this points to a data controller.
- Does the party process solely according to instructions, without a purpose of its own? Then this points to a processor.
- Does the party also use the data for its own purposes, separate from the assignment? Then this points to (joint) controllership.
- Has a processing agreement been concluded, and does it match what happens in practice? If not, this is a signal to review the division of roles.
Pay attention when it comes to personal data of candidates and professionals. CVs, job applications, screenings, and assessments are sensitive data. Handle these with extra care, and always have a final decision about candidates reviewed by a human, even when you use tools or automation for pre-selection or ranking. If you want to deploy a new tool, automation, or AI application that works with this kind of data, report this via the WISE intake process, so that it is properly assessed and supported within the Shadow AI framework.
Rules of thumb
For every processing of personal data, observe these rules of thumb:
- Legal basis: there must always be a legal basis to process personal data, for example consent, a contract, or a legitimate interest. Without a legal basis, you may not process.
- Necessity: only process data if it is actually necessary for the purpose you have in mind.
- Not more than necessary: do not collect or use more data than strictly necessary for that purpose. Collecting more "just to be safe" is not permitted.
- Sharing with third parties: you do not simply share personal data with another party. Check whether there is a legal basis for this, whether agreements have been recorded (for example in a processing agreement), and whether the receiving party is legally permitted to receive the data.
If you have doubts about a specific collaboration or processing activity, consult with your manager or the Privacy Officer/DPO and, if necessary, Legal, so that you correctly qualify the division of roles before setting this up further.