Key takeaway

One organization can occupy different roles for different operations. A contract label cannot replace the facts about who decides why and how personal data is used.

Replace the company label with a processing operation

The same recipient might clean a file under the owner's instructions and later use selected records to build its own product. Calling that recipient a processor throughout the agreement leaves the second operation unexplained. Start with verbs and purposes: store for the owner, correct for the owner, select for an independent benchmark, train for the recipient's product, or disclose to another organization.

EDPB Guidelines 07/2020 explain that controller and processor roles depend on actual decisions over purposes and essential means. A processor is a separate entity acting on a controller's behalf. Own-purpose processing can make that actor a controller for that operation. Shared infrastructure or a shared dataset alone does not establish joint control.

This is an EU personal-data role review. It does not decide whether the proposed purpose is lawful, whether a transfer is permitted or whether a license should be signed. Those decisions need the role facts, but cannot be inferred from them. Keep the processing purpose precise enough that the reviewer can distinguish the original owner's activity from the recipient's proposed activity.

Worked example: three purposes, three role questions

In this hypothetical proposal, owner Atlas sends selected maintenance narratives containing worker-related personal data to a separate company, North Lab. The parties' first draft calls North Lab a processor. Their operational interviews reveal three different proposed uses. The completed matrix below records the decisions that matter and a provisional review position rather than pretending the label resolves all three.

Technical discretion is described separately. Choosing a storage service or implementing routine processing can differ from deciding which people are analyzed, what data is used, how long it is retained and who receives it. The interview asks what decisions are actually permitted and exercised, not merely what the software is capable of doing.

Operation and purposeActual decision facts in this hypotheticalRole question for review
Correct record formatting for AtlasAtlas defines fields, correction rules, recipients and deletion point; North Lab chooses implementationProcessor candidate for this instructed operation
Train North Lab's independent diagnostic productNorth Lab chooses target task, additional sources, retention and future customersIndependent-controller candidate for this new purpose; processor label insufficient
Design a shared worker-scoring studyBoth organizations approve intended scoring use and essential study design; responsibilities unresolvedInvestigate possible joint control of this operation; do not infer it from the shared file
Store an internal copy within AtlasAtlas employees act within their organizationAn internal team is not a separate processor entity merely because it hosts the export

Test the decisions with an actual disagreement

For the hypothetical formatting operation, ask what happens if North Lab wants to retain the file for product development after correction is complete. Atlas's instruction says delete it. If the recipient can override that instruction to pursue its own research goal, the operation under review has changed. Record the new purpose and its decision maker instead of treating retention as a harmless technical detail.

For the diagnostic-product proposal, the completed interview records that North Lab selects its own customers and combines the records with another archive. Atlas approves a possible disclosure but does not design North Lab's product objective. Those facts support an independent-controller inquiry; approval to disclose is not itself proof of joint control.

For the shared scoring study, the team records the precise points of joint influence: the group of workers included, score purpose, assessment period and recipients of the results. Purchasing a report or benefiting from it is not enough detail. The reviewer needs evidence of how essential decisions are made, including meeting approvals and the power to change the design.

Translate the role record into document requirements

In the hypothetical review, the formatting purpose can proceed to a processor-terms review. The diagnostic-product use is removed from that instruction schedule and placed in a separate disclosure and licensing proposal. The shared scoring study stays on hold while its purpose, governance and appropriate role arrangement are resolved. None of these actions amounts to approval of a real sample.

The Commission’s business explanation also recognizes different roles across processing parts and describes binding obligations for a processor. Use the role matrix to route each purpose to the relevant document review, rather than assuming one service contract silently covers every use.

Make the matrix useful to the agreement drafter by attaching the actual legal entities, operation identifiers, instruction owner, purpose statement, retention decision maker and onward-recipient decision maker. Record a disagreement field. If two interviewees give conflicting accounts, preserve both and resolve the conflict before selecting a form of agreement.

Do not use a single check box saying GDPR compliant. A role finding does not supply an appropriate lawful basis, notices, safeguards or international-transfer mechanism. If the purpose changes during negotiation, reopen the role row and the dependent reviews. The earlier conclusion should remain traceable to the earlier operation rather than silently stretching to cover the new one.

A completed role review produces a bounded decision

The final hypothetical decision is narrower than the original draft: Atlas has not authorized own-product training within a formatting instruction, and the shared scoring proposal has not been cleared. The record states which operation was examined, what facts remain disputed and who owns the next decision. This is considerably more useful than signing a processor label and discovering the mismatch after delivery.

Use due diligence to turn the unresolved decision facts into recipient questions. Use rights review to retain the actual purpose and entity boundaries. The separate EU transfer-recipient guide helps once the organization, access location and actor roles are known; it should not be used to shortcut the purpose analysis.

At VOID, an approved introduction concerns the named recipient and approved metadata. The data owner separately decides whether to permit a sample or license. Clear role facts make those later decisions better informed without converting a referral into authority for the recipient's new processing purpose.

Tools for this decision

Rights & privacy review →Diligence question builder →