Free Guide

Controller vs Processor.

Article 4(7), 4(8) and 26 explained in plain language — the purposes-and-means test, joint controllers, ten worked examples across common vendor relationships, Article 28 processor duties, what a compliant DPA must contain, and a decision flowchart you can run today. Free to download.

14
chapters
10
worked examples
19
pages
2026
edition
Share this
GDPRGard.eu · Free Guide
Controller vs Processor
The complete GDPR guide to getting your role right — Article 4(7), 4(8), 26 and 28, with a decision flowchart.
© 2026 GDPRGard.eu

Get the free guide

Enter your email and we'll unlock the download immediately. No spam, ever.

🔒 GDPR compliant · We never share your email · Unsubscribe anytime

Your guide is ready

Click below to download — and check your inbox, we've sent a copy there too.

⬇ Download PDF (19 pages)
ℹ️

What this guide covers: almost every other GDPR obligation depends on correctly answering one question first — are you a controller, a processor, or a joint controller for this specific processing activity? This guide works through the Article 4(7)/4(8) "purposes and means" test, Article 26 joint controllers, ten worked examples across common business relationships, why the label matters for liability and fines, Article 28 processor obligations, what a compliant Data Processing Agreement must contain, sub-processor authorisation and liability, international transfer duties, the misclassifications that get businesses in trouble, and a decision flowchart plus a 15-point documentation checklist. It's informational, not legal advice; full detail is in the PDF.

Prefer to listen? Click play for AI narration

Fourteen chapters. One decision, made correctly.

01
Why This Is the First Question, Not a Footnote
Everything else flows from getting this right
02
Controller Defined
Article 4(7) and the purposes-and-means test
03
Processor Defined
Article 4(8) and the line a processor cannot cross
04
Joint Controllers
Article 26 — when two businesses share the decision
05
The Test in Practice
Ten worked examples across real vendor relationships
06
Why the Label Matters
Liability, fine tiers, and who regulators call first
07
Processor Obligations
The full Article 28 duty list, direct and enforceable
08
What a DPA Must Contain
Mandatory clauses and the red flags to check for
09
Sub-Processors
Authorisation, notification, and the liability chain
10
International Transfers
Controller duties vs processor duties, post-Schrems II
11
Common Misclassifications
The patterns that get businesses in trouble
12
Decision Flowchart
Controller, processor, or both — run it per activity
🧭

Substance over labels

What a contract calls you doesn't decide your legal role — this guide teaches the actual EDPB test, so you classify correctly even when a vendor's paperwork says otherwise.

🔗

Real vendor relationships, worked through

SaaS hosts, payment processors, marketing agencies, payroll bureaus, accountants, recruiters — ten common relationships classified with the reasoning shown.

A flowchart and checklist you can run today

A step-by-step decision flowchart per processing activity, plus a 15-point checklist for documenting controller, processor, and joint-controller relationships correctly.

The GDPR articles that define who's responsible.

Article 4(7) Controller Definition · Article 4(8) Processor Definition · Article 26 Joint Controllers · Article 28 Processor Obligations · Article 44–49 International Transfers · Article 83 Fine Tiers

Want the full picture?

Pair this guide with the Complete Guide

This guide covers controller/processor classification in depth. Our free 29-page Complete Guide covers every other GDPR article — lawful basis, DSARs, DPIAs, and a 20-point SMB compliance checklist of its own.

Get the free guide →