Gdpr data controller vs.
Gdpr controller vs processor.
This is a major difference between the original dpd legislation in 1995.
Gdpr data controllers and data processors since gdpr was launched in may 2018 controllers have specific obligations.
As a data controller one must ensure that the data processor s remain aware of their gdpr obligations.
Generally data controllers have more accountability and liability but processors will have new responsibilities and new added layers of liability written into their roles.
The third party data processor does not own the data that they process nor do they control it.
Controller means the natural or legal person public authority agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
Processor according to article 4 of the eu gdpr different roles are identified as indicated below.
As a common recommendation confirm that there exists a clear and specific data processing agreement before handing over the processing to a third party.
In addition processors have legal obligations of their own.
Following the example above the data processor is the third party company that the data controller chose to use and process the data.