A vendor contract calls both parties “joint owners of the data.” Which GDPR role analysis is correct?
Select an answer to reveal the explanation.
Short Explanation
Ignore the contract’s poetry about “owning” data. GDPR asks who picks the why and how of processing—that party is the controller—and who just processes on instructions—that’s the processor. Fancy ownership wording does not rewrite those roles.
Full Explanation
Under Article 4 GDPR, a controller determines the purposes and means of processing personal data, whereas a processor processes personal data on behalf of the controller. Contractual marketing language such as “joint owners” is not dispositive; factual decision-making authority is. Hosting alone does not automatically make a party controller, “joint owners” is not a defined substitute role, and processors do not generally determine purposes and means.