Get the free guide
Enter your email and we'll unlock the download immediately. No spam, ever.
Your guide is ready
Click below to download — and check your inbox, we've sent a copy there too.
⬇ Download PDF (19 pages)What this guide covers: almost every other GDPR obligation depends on correctly answering one question first — are you a controller, a processor, or a joint controller for this specific processing activity? This guide works through the Article 4(7)/4(8) "purposes and means" test, Article 26 joint controllers, ten worked examples across common business relationships, why the label matters for liability and fines, Article 28 processor obligations, what a compliant Data Processing Agreement must contain, sub-processor authorisation and liability, international transfer duties, the misclassifications that get businesses in trouble, and a decision flowchart plus a 15-point documentation checklist. It's informational, not legal advice; full detail is in the PDF.
Fourteen chapters. One decision, made correctly.
Substance over labels
What a contract calls you doesn't decide your legal role — this guide teaches the actual EDPB test, so you classify correctly even when a vendor's paperwork says otherwise.
Real vendor relationships, worked through
SaaS hosts, payment processors, marketing agencies, payroll bureaus, accountants, recruiters — ten common relationships classified with the reasoning shown.
A flowchart and checklist you can run today
A step-by-step decision flowchart per processing activity, plus a 15-point checklist for documenting controller, processor, and joint-controller relationships correctly.
The GDPR articles that define who's responsible.
Article 4(7) Controller Definition · Article 4(8) Processor Definition · Article 26 Joint Controllers · Article 28 Processor Obligations · Article 44–49 International Transfers · Article 83 Fine Tiers
Pair this guide with the Complete Guide
This guide covers controller/processor classification in depth. Our free 29-page Complete Guide covers every other GDPR article — lawful basis, DSARs, DPIAs, and a 20-point SMB compliance checklist of its own.
Get the free guide →