Controller and processor is the most consequential distinction in privacy law and the one most often assumed rather than decided. It sets who writes the privacy notice, who answers a request, who signs which contract and who is liable. This page is the test, and the three cases where the answer surprises people.
The test: who could change the purpose
A controller determines the purposes and means of processing. A processor processes only on documented instructions. The practical test is whether you could decide tomorrow to use the data for something new without asking anybody. If you could, you are a controller for that data, whatever your contract calls you.
What each one carries
The controller owes the notice, the lawful basis, the request response and the relationship with the person. The processor owes security, confidentiality, help with requests, and the conditions in Article 28 including not engaging another processor without authorisation. Both keep a record of processing, but they record different things.
Case one: the same company is both
The usual shape for a software business. You are a processor for the customer data your customers put into your product, and a controller for your own marketing list, your billing records and your employees. Two roles, two sets of paperwork, and conflating them is why privacy policies aimed at both audiences read so strangely.
Case two: the vendor who quietly became a controller
An analytics or advertising vendor that uses what it learns from your users for its own purposes is not acting only on your instructions. The contract may still say processor. The role is decided by what happens, not by the label.
Case three: joint controllers
Where two organisations genuinely decide the purposes together, both are controllers and the arrangement has to be transparent to the person. This is rarer than it is claimed, and it is not a way to share liability.
Questions people ask about data processor
Does the contract decide the role?
No. The contract records it and gets it wrong quite often. If the facts and the contract disagree, the facts win, which is why a processor agreement with a vendor that uses your data for its own product improvement is not protecting you.
Who answers an access request?
The controller. A processor that receives one should pass it on promptly and help, and its agreement should say so, but it should not answer it directly.
Do we need an agreement with every processor?
Yes, and the count is usually larger than the list people have. The builder on this site sizes it including sub-processors, which is where the chain gets long.