ILP Abogados
Madrid · Internacional
Dos profesionales sentados frente a frente en una oficina revisando y firmando un contrato junto a un ordenador portátil y carpetas de documentos

Controllers versus Processors: The Definitive Legal Guide to Liability and Subcontracting in Data Processing (Data Protection Series VI)

Last updated: 4 August 2026.

Quick answer. Whether you are a controller or a processor is not settled by the contract: it is settled by who gives the orders. The controller fixes the why and the how; the processor merely carries out documented instructions. These 10 rules, drawn from Spanish Supreme Court judgments and from AEPD penalty decisions, explain when a supplier turns into a controller, why the Article 28 GDPR contract is mandatory, and why an indemnity clause does not erase the fine. Updated 4 August 2026.

Introduction

The 10 essential points for distinguishing the ‘controller’ from the ‘processor’

In the business world, outsourcing services and relying on suppliers is common practice. However, when it comes to data protection, the distinction between being the ‘controller’ and the ‘processor’ determines who bears the primary obligations and who is liable for fines in the event of a breach. Below are 10 essential points, supported by case law and rulings from the Spanish Data Protection Agency (AEPD), to draw a clear line between the two roles.

1. The distinction is a purely functional concept and does not depend on formal contracts

The concepts of ‘controller’ and ‘processor’ are functional; their purpose is to assign responsibilities according to the actual role assumed by each party. Legal status is not determined by the formal title used in a commercial contract (for example, calling someone a ‘subcontractor’ or a ‘processor’), but rather by analysing the specific facts of who, in practice, decides the actual activities.

  • AEPD: Penalty Decisions EXP202414356 (Case No. PS/00177/2025) and EXP202414366 (Case No. PS/00190/2025), dated 26 March 2025.
  • AEPD: Penalty Decision EXP202304148 (Case No. PS/00247/2024), dated 10 October 2025.

2. The ‘controller’ is the one who decides the ‘why’ and the ‘how’ of the processing

The controller is the organisation or individual that determines the purposes and the essential means. In other words, it holds the decision-making power to answer two key questions: why is the processing taking place? (the purpose) and who has decided that it should be carried out? (the means). Whoever gives the instructions for inclusion in a data file assumes this role.

  • Case law: Supreme Court, Contentious-Administrative Chamber (Section 3), Judgments No. 121/2019 of 5 February 2019, and No. 1690/2019 of 10 December 2019.

3. The ‘processor’ acts solely on the instructions of the controller

For a supplier to be considered a ‘processor’, it must meet two requirements: it must be an independent entity, and it must process the data exclusively ‘on behalf of’ or in the name of the controller. The processor does not act under direct control in the way an employee does, but its legal role is strictly limited to applying the documented instructions provided by the controller in order to serve the latter’s interests.

  • Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.

4. Risk mutation: when the processor uses the data for its own purposes it becomes a controller

If a supplier engaged as a ‘processor’ decides to disregard or exceed its instructions and uses the personal data for a purpose of its own (for example, taking the telephone numbers of parcel recipients to create a ‘block’ list unrelated to the contracted service), it automatically becomes an independent controller, assuming the full legal burden and the penalties arising from that infringement.

  • AEPD: Penalty Decision EXP202304148 (Case No. PS/00247/2024), dated 10 October 2025.

5. The inescapable obligation to sign a written data processing agreement

Legal control over the processor is lost where there are no mandatory documented instructions. The relationship between controller and processor requires a formal contract (or written legal act) in accordance with Article 28 of the GDPR. A merely verbal communication of guidelines is not valid; the absence of such a contract constitutes a direct infringement attributable to the controller that delegates the service.

  • AEPD: Penalty Decision EXP202407910 (Case No. PS/00248/2024), dated 30 September 2025.
  • Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.

6. Structuring and organising someone else’s information turns the business owner into a controller

A business owner cannot escape liability by arguing that the data comes from a ‘third-party’ or ‘public’ file and that they are a mere recipient. If the company carries out acts of its own to structure, consult, cross-check or organise that information on its premises (for example, a pharmacy organising lists of patients from a care home), it establishes itself, both materially and functionally, as the controller vis-à-vis the data subject.

  • AEPD: Penalty Decisions EXP202414356 (Case No. PS/00177/2025) and EXP202414366 (Case No. PS/00190/2025), dated 26 March 2025.

7. Duties of diligence and control cannot be delegated

Fundamental obligations, such as ensuring data quality, verifying that consent has been obtained or ensuring security, rest with the controller and cannot be transferred to the processor. The controller has a legal duty to exercise diligent supervision and cannot rely on the errors of the companies it contracts as a defence.

  • Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.

8. IT and hosting providers are processors

Any technology service provider that supplies cloud storage or IT solutions, and that stores the data of the business owner’s customers, must systematically be regarded as a processor. These providers are bound by the security instructions given by the business that contracts them.

  • Legal Source: Legal Note ‘Data Processing and Ownership’ (ILP Abogados).
  • AEPD: Penalty Decision EXP202414356 (Case No. PS/00177/2025), dated 26 March 2025.

9. The controller behind a marketing campaign is liable even if the processor uses its own databases

In commercial activities, the company that promotes the campaign, sets the marketing means and benefits from it acts as the controller. It retains full responsibility for actively supervising its partners and external advertising agencies (which act as processors), even where those agencies use databases of their own to send mailings or make calls.

  • Case law: Order of the Supreme Court (Contentious-Administrative Chamber, Section 1), dated 23 April 2025.

10. ‘Indemnity clauses’ do not exempt you from AEPD fines

It is common practice to include indemnity clauses in contracts so that the processor bears the financial cost of any errors made. Although these clauses allow the ‘controller’ to bring a recourse action (a civil claim) against the ‘processor’ to recover the amount of the penalty, they do not operate as absolute insurance; the controller will remain the principal offender penalised by the AEPD vis-à-vis the individual, and the clause will not be valid where the error arose from defective instructions or from the controller’s own breaches.

  • Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.

None of these ten rules is settled by a label on the cover of a contract: they are settled by mapping who decides each data flow, drafting the documented instructions required by Article 28 and defending that position with evidence when the Agency asks. That work of allocating roles, drafting contracts and mounting a defence is what our data protection and GDPR compliance practice covers.

Glossary

DATA CONTROLLER

The organisation or individual that determines the purpose and the essential means of data processing, holding the power to decide the ‘why’ and the ‘how’ of that processing.

DATA PROCESSOR

An independent entity that processes personal data exclusively on behalf of and in the name of the controller, strictly applying the controller’s documented instructions.

FUNCTIONAL CRITERION

The legal principle whereby the status of controller or processor is not fixed by the formal label used in a contract, but by the actual and practical role played by each party.

RISK MUTATION

The situation arising where a processor disregards or exceeds the controller’s instructions in order to use the data for purposes of its own, thereby automatically becoming an independent controller and assuming the full burden of penalties.

DATA PROCESSING AGREEMENT

The formal, written legal act (in accordance with Article 28 of the GDPR) that must be signed in order to govern the relationship between controller and processor, securing legal control through documented instructions.

NON-DELEGABLE OBLIGATIONS

The fundamental duties of diligence, data quality and active supervision that rest on the controller and cannot be transferred, preventing it from relying on the failings or errors of its subcontractors.

HOSTING AND CLOUD SERVICE PROVIDERS

Technology providers that store the personal data of the business owner’s customers and are systematically regarded as processors, subject to security requirements.

INDEMNITY CLAUSES

Contractual provisions on financial cover between the parties which enable civil recourse actions to recover the amount of a penalty, but which neither mitigate nor exempt a party from direct liability or from the fine imposed by the AEPD.

Do you know whether your supplier contracts make you a controller or a processor, and whether that label matches what actually happens in practice? We review your data processing agreements, your documented instructions and your technology suppliers to show you where the AEPD would penalise you rather than them: tell us about your case and we will go through it with you.

Frequently asked questions

Who is the controller and who is the processor?

The controller determines the purposes and the essential means: it decides why the data is processed and who ordered that processing. The processor is an independent entity that processes the data exclusively on behalf of and in the name of the controller, confining itself to applying the controller’s documented instructions.

Does calling a supplier a ‘processor’ in the contract settle the matter?

Not on its own. These concepts are functional: legal status is not fixed by the formal label used in a commercial contract, but by analysing the specific facts of who actually decides the activities in practice. A contract that calls someone a processor does not prevent the AEPD from treating them as a controller if they decide the purposes and means.

When does a processor become a controller?

When it disregards or exceeds its instructions and uses the personal data for its own purposes. The AEPD has penalised, for example, the use of parcel recipients’ telephone numbers to build a block list unrelated to the contracted service. At that point it becomes an independent controller and assumes the full burden of penalties for that infringement.

Is a written data processing agreement mandatory?

Yes. The relationship requires a formal contract or written legal act in accordance with Article 28 of the GDPR. A merely verbal communication of guidelines is not valid, and the absence of that contract constitutes a direct infringement attributable to the controller delegating the service, not to the supplier.

Is my hosting or software provider a processor?

Yes. Any technology service provider that supplies cloud storage or IT solutions and stores the data of the business owner’s customers is systematically regarded as a processor, and is bound by the security instructions given by the company that contracts it.

Can I delegate the duty to supervise and control to the processor?

No. Ensuring data quality, verifying that consent was obtained and ensuring security are obligations that rest with the controller and cannot be transferred. The controller has a legal duty to exercise diligent supervision and cannot rely on the errors of the companies it contracts as a defence.

Who is liable if a marketing agency uses its own database?

The company promoting the campaign. Whoever sets the marketing means and benefits from the commercial action acts as controller and retains responsibility for actively supervising its partners and external advertising agencies, even where those agencies use databases of their own to send mailings or make calls.

Does an indemnity clause protect me from an AEPD fine?

No. It allows the controller to bring a recourse action in the civil courts against the processor to recover the amount, but it does not operate as absolute insurance: the controller remains the principal offender penalised by the AEPD vis-à-vis the individual, and the clause will not be valid where the error arose from defective instructions or from the controller’s own breaches.



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading