Last updated: 4 August 2026.
Quick answer. Whether you are a controller or a processor is not settled by the contract: it is settled by who gives the orders. The controller fixes the why and the how; the processor merely carries out documented instructions. These 10 rules, drawn from Spanish Supreme Court judgments and from AEPD penalty decisions, explain when a supplier turns into a controller, why the Article 28 GDPR contract is mandatory, and why an indemnity clause does not erase the fine. Updated 4 August 2026.
Introduction
The 10 essential points for distinguishing the ‘controller’ from the ‘processor’
In the business world, outsourcing services and relying on suppliers is common practice. However, when it comes to data protection, the distinction between being the ‘controller’ and the ‘processor’ determines who bears the primary obligations and who is liable for fines in the event of a breach. Below are 10 essential points, supported by case law and rulings from the Spanish Data Protection Agency (AEPD), to draw a clear line between the two roles.
1. The distinction is a purely functional concept and does not depend on formal contracts
The concepts of ‘controller’ and ‘processor’ are functional; their purpose is to assign responsibilities according to the actual role assumed by each party. Legal status is not determined by the formal title used in a commercial contract (for example, calling someone a ‘subcontractor’ or a ‘processor’), but rather by analysing the specific facts of who, in practice, decides the actual activities.
- AEPD: Penalty Decisions EXP202414356 (Case No. PS/00177/2025) and EXP202414366 (Case No. PS/00190/2025), dated 26 March 2025.
- AEPD: Penalty Decision EXP202304148 (Case No. PS/00247/2024), dated 10 October 2025.
2. The ‘controller’ is the one who decides the ‘why’ and the ‘how’ of the processing
The controller is the organisation or individual that determines the purposes and the essential means. In other words, it holds the decision-making power to answer two key questions: why is the processing taking place? (the purpose) and who has decided that it should be carried out? (the means). Whoever gives the instructions for inclusion in a data file assumes this role.
- Case law: Supreme Court, Contentious-Administrative Chamber (Section 3), Judgments No. 121/2019 of 5 February 2019, and No. 1690/2019 of 10 December 2019.
3. The ‘processor’ acts solely on the instructions of the controller
For a supplier to be considered a ‘processor’, it must meet two requirements: it must be an independent entity, and it must process the data exclusively ‘on behalf of’ or in the name of the controller. The processor does not act under direct control in the way an employee does, but its legal role is strictly limited to applying the documented instructions provided by the controller in order to serve the latter’s interests.
- Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.
4. Risk mutation: when the processor uses the data for its own purposes it becomes a controller
If a supplier engaged as a ‘processor’ decides to disregard or exceed its instructions and uses the personal data for a purpose of its own (for example, taking the telephone numbers of parcel recipients to create a ‘block’ list unrelated to the contracted service), it automatically becomes an independent controller, assuming the full legal burden and the penalties arising from that infringement.
- AEPD: Penalty Decision EXP202304148 (Case No. PS/00247/2024), dated 10 October 2025.
5. The inescapable obligation to sign a written data processing agreement
Legal control over the processor is lost where there are no mandatory documented instructions. The relationship between controller and processor requires a formal contract (or written legal act) in accordance with Article 28 of the GDPR. A merely verbal communication of guidelines is not valid; the absence of such a contract constitutes a direct infringement attributable to the controller that delegates the service.
- AEPD: Penalty Decision EXP202407910 (Case No. PS/00248/2024), dated 30 September 2025.
- Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.
6. Structuring and organising someone else’s information turns the business owner into a controller
A business owner cannot escape liability by arguing that the data comes from a ‘third-party’ or ‘public’ file and that they are a mere recipient. If the company carries out acts of its own to structure, consult, cross-check or organise that information on its premises (for example, a pharmacy organising lists of patients from a care home), it establishes itself, both materially and functionally, as the controller vis-à-vis the data subject.
- AEPD: Penalty Decisions EXP202414356 (Case No. PS/00177/2025) and EXP202414366 (Case No. PS/00190/2025), dated 26 March 2025.
7. Duties of diligence and control cannot be delegated
Fundamental obligations, such as ensuring data quality, verifying that consent has been obtained or ensuring security, rest with the controller and cannot be transferred to the processor. The controller has a legal duty to exercise diligent supervision and cannot rely on the errors of the companies it contracts as a defence.
- Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.
8. IT and hosting providers are processors
Any technology service provider that supplies cloud storage or IT solutions, and that stores the data of the business owner’s customers, must systematically be regarded as a processor. These providers are bound by the security instructions given by the business that contracts them.
- Legal Source: Legal Note ‘Data Processing and Ownership’ (ILP Abogados).
- AEPD: Penalty Decision EXP202414356 (Case No. PS/00177/2025), dated 26 March 2025.
9. The controller behind a marketing campaign is liable even if the processor uses its own databases
In commercial activities, the company that promotes the campaign, sets the marketing means and benefits from it acts as the controller. It retains full responsibility for actively supervising its partners and external advertising agencies (which act as processors), even where those agencies use databases of their own to send mailings or make calls.
- Case law: Order of the Supreme Court (Contentious-Administrative Chamber, Section 1), dated 23 April 2025.
10. ‘Indemnity clauses’ do not exempt you from AEPD fines
It is common practice to include indemnity clauses in contracts so that the processor bears the financial cost of any errors made. Although these clauses allow the ‘controller’ to bring a recourse action (a civil claim) against the ‘processor’ to recover the amount of the penalty, they do not operate as absolute insurance; the controller will remain the principal offender penalised by the AEPD vis-à-vis the individual, and the clause will not be valid where the error arose from defective instructions or from the controller’s own breaches.
- Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.
None of these ten rules is settled by a label on the cover of a contract: they are settled by mapping who decides each data flow, drafting the documented instructions required by Article 28 and defending that position with evidence when the Agency asks. That work of allocating roles, drafting contracts and mounting a defence is what our data protection and GDPR compliance practice covers.
Glossary
DATA CONTROLLER
The organisation or individual that determines the purpose and the essential means of data processing, holding the power to decide the ‘why’ and the ‘how’ of that processing.
DATA PROCESSOR
An independent entity that processes personal data exclusively on behalf of and in the name of the controller, strictly applying the controller’s documented instructions.
FUNCTIONAL CRITERION
The legal principle whereby the status of controller or processor is not fixed by the formal label used in a contract, but by the actual and practical role played by each party.
RISK MUTATION
The situation arising where a processor disregards or exceeds the controller’s instructions in order to use the data for purposes of its own, thereby automatically becoming an independent controller and assuming the full burden of penalties.
DATA PROCESSING AGREEMENT
The formal, written legal act (in accordance with Article 28 of the GDPR) that must be signed in order to govern the relationship between controller and processor, securing legal control through documented instructions.
NON-DELEGABLE OBLIGATIONS
The fundamental duties of diligence, data quality and active supervision that rest on the controller and cannot be transferred, preventing it from relying on the failings or errors of its subcontractors.
HOSTING AND CLOUD SERVICE PROVIDERS
Technology providers that store the personal data of the business owner’s customers and are systematically regarded as processors, subject to security requirements.
INDEMNITY CLAUSES
Contractual provisions on financial cover between the parties which enable civil recourse actions to recover the amount of a penalty, but which neither mitigate nor exempt a party from direct liability or from the fine imposed by the AEPD.
Do you know whether your supplier contracts make you a controller or a processor, and whether that label matches what actually happens in practice? We review your data processing agreements, your documented instructions and your technology suppliers to show you where the AEPD would penalise you rather than them: tell us about your case and we will go through it with you.
Frequently asked questions
The controller determines the purposes and the essential means: it decides why the data is processed and who ordered that processing. The processor is an independent entity that processes the data exclusively on behalf of and in the name of the controller, confining itself to applying the controller’s documented instructions.
Not on its own. These concepts are functional: legal status is not fixed by the formal label used in a commercial contract, but by analysing the specific facts of who actually decides the activities in practice. A contract that calls someone a processor does not prevent the AEPD from treating them as a controller if they decide the purposes and means.
When it disregards or exceeds its instructions and uses the personal data for its own purposes. The AEPD has penalised, for example, the use of parcel recipients’ telephone numbers to build a block list unrelated to the contracted service. At that point it becomes an independent controller and assumes the full burden of penalties for that infringement.
Yes. The relationship requires a formal contract or written legal act in accordance with Article 28 of the GDPR. A merely verbal communication of guidelines is not valid, and the absence of that contract constitutes a direct infringement attributable to the controller delegating the service, not to the supplier.
Yes. Any technology service provider that supplies cloud storage or IT solutions and stores the data of the business owner’s customers is systematically regarded as a processor, and is bound by the security instructions given by the company that contracts it.
No. Ensuring data quality, verifying that consent was obtained and ensuring security are obligations that rest with the controller and cannot be transferred. The controller has a legal duty to exercise diligent supervision and cannot rely on the errors of the companies it contracts as a defence.
The company promoting the campaign. Whoever sets the marketing means and benefits from the commercial action acts as controller and retains responsibility for actively supervising its partners and external advertising agencies, even where those agencies use databases of their own to send mailings or make calls.
No. It allows the controller to bring a recourse action in the civil courts against the processor to recover the amount, but it does not operate as absolute insurance: the controller remains the principal offender penalised by the AEPD vis-à-vis the individual, and the clause will not be valid where the error arose from defective instructions or from the controller’s own breaches.
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Artículos relacionados
- The Price of Data: 15 Legal Commandments Every Business Owner Should Know to Avoid Penalties (Data Protection Series V)
- Article 14 GDPR Before the Courts and the Supervisory Authorities (Data Protection Series IV)
- Article 14 GDPR: The Duty to Inform When Personal Data Comes From Other Sources (Data Protection Series III)

