What is Data Controller vs. Data Processor?
The data controller decides why and how personal data is collected and used; the data processor handles personal data on the controller’s instructions. Knowing which role your organisation plays determines legal responsibilities for compliance, security and responding to people’s data requests.
A data controller determines the purposes and means of processing personal data — for example, which questions to ask, who to invite, how long answers are kept, and the legal basis for collecting them. A data processor processes personal data on behalf of the controller, following the controller’s instructions (for example, storing survey responses, running translations, or hosting databases). Under regulations like the EU GDPR, controllers carry primary responsibility for compliance with data protection principles; processors have duties to implement appropriate technical and organisational measures and to act only as instructed. In some situations two organisations can be joint controllers (they jointly decide why and how data is processed), which requires a clear agreement describing each party’s responsibilities.
Usage example
A school runs a multilingual parent survey using Hearo. The school chooses the questions, the audience and the retention period — so the school is the data controller. Hearo stores the survey responses, performs automatic translation and provides the admin interface on behalf of the school — so Hearo is the data processor. If Hearo used anonymised data from responses to improve its translation models for other customers, the parties would need to agree whether that counts as additional processing and who is responsible for it.
Practical application
Correctly identifying controller and processor roles matters because it determines who must: establish a lawful basis for collecting personal data (e.g., consent or legitimate interest); provide privacy notices to participants; respond to data subject access, correction or deletion requests; report breaches to authorities and affected people; and sign a data processing agreement (DPA) that sets security, subprocessors and cross-border transfer terms. For teams running multilingual surveys, clarifying roles early makes it easier to draft contracts, reduce regulatory risk, map data flows (including how translations and open-text answers are handled), and build participant-facing privacy information that accurately explains who is responsible for their data.
FAQ
Who is the controller and who is the processor when I use a survey platform like Hearo?
Typically the organisation that creates and owns the survey (for example a school, council or charity) is the data controller because it decides what data to collect and why. The survey platform (Hearo) usually acts as the processor, storing responses and performing operations (like translations) on the controller’s instructions. If the platform starts determining purposes itself (for example using response data for its own analytics), roles should be checked and documented.
What practical steps should we take to meet controller/processor obligations?
Identify and document which party is controller or processor for each project; sign a Data Processing Agreement (DPA) with clear instructions, security measures and subprocessors; map where data is stored and transferred; agree retention and deletion rules; include clear privacy notices for participants; and set procedures for handling subject access requests and breach notifications.
What happens if two organisations jointly decide how data is used?
If both parties jointly determine purposes and means, they are joint controllers. They must document their arrangements and clearly tell participants how responsibilities are divided (for example, who handles access requests or breach notifications). Joint controller agreements should be proportionate and transparent to participants.
Can a processor use subprocessors (e.g., third-party translation services) and what should we check?
Yes, processors commonly engage subprocessors. Controllers should require that the processor obtain permission or notify them before appointing subprocessors, and that any subprocessor provides equivalent data protection through contracts and technical safeguards. Check the DPA for subprocessors, transfer mechanisms for data leaving your jurisdiction, and the processor’s security and incident response practices.