CIPP/E Study Guide
Ch 17.2.2 - Controller vs processor

Cloud: controllership issues

In most supply-of-services cases the customer is the controller (it decides purposes and means) and the supplier is a processor. But in cloud this can't be assumed. A processor can choose non-essential means (e.g. hardware) without becoming a controller, but deciding essential means like retention periods, or processing data for its own purposes, makes it a controller. The contract matters but is not conclusive on its own.

Controller vs processor in cloud
QuestionEffect on supplier's status
Supplier decides only non-essential means (e.g. hardware)?Can remain a processor
Supplier decides essential means (e.g. retention periods)?Becomes a controller
Supplier processes customer data for its OWN purposes?Becomes a controller of that data
Supplier acts outside the controller's instructions?Becomes a controller

Why it matters: controller|controllers (and joint controllers) carry significantly more GDPR obligations than processors. The contract helps allocate roles but the contractual relationship in isolation is not conclusive - otherwise parties could artificially shift a controller's responsibilities. A processor must act only on the controller's instructions, but those instructions can be general.

Modern trap

Cloud providers increasingly want to use customer data for their own purposes (e.g. to improve services). The moment they do, they become a controller of that data - a growing source of disputes.

Key terms - quick answers

What is “Controller”?
The body that, alone or jointly, determines the purposes and means of processing - the key is deciding how and why data is processed.
What is “Processor”?
A body (not an employee of the controller) that processes data on the controller's behalf, on its instructions.
What is “Joint controllers”?
Two or more entities that jointly determine the purposes and means of processing.
What is “Essential means”?
Core decisions about processing (e.g. retention periods) - deciding these makes a party a controller, unlike non-essential means such as hardware choice.