Skip to main content
Back to the wiki
Privacy & Compliance

What Is a Data Controller vs. a Data Processor?

Last updated on July 20, 2026

Data controller and data processor are the two central roles the GDPR assigns to anyone handling personal data. The controller determines the purposes and means of processing — why data is collected and how it will be used — while the processor handles data solely on the controller's documented instructions. The distinction is anything but academic: it decides who must inform users, who answers their rights requests, who reports breaches to whom, and who regulators hold accountable when something goes wrong.

How the Roles Divide in Practice

A website operator collecting signups is a controller; the cloud platform hosting the database, the email service sending the confirmations, and the analytics vendor counting the visits are typically processors. The controller carries the primary duties — establishing a legal basis, providing privacy notices, honoring access and deletion requests — while the processor must follow instructions, secure the data, and assist the controller in meeting those duties. Article 28 of the GDPR requires the relationship to be fixed in a data processing agreement (DPA), and any sub-processor the vendor engages needs the controller's authorization. Two variations complicate the picture: joint controllership arises when two parties decide on purposes together, and a vendor that starts using the data for its own goals — training its models, building advertising profiles — becomes a controller for that use, with all the duties that follow.

Why the Distinction Matters for Security Tools

Every third-party widget embedded in a page — analytics, chat, verification — processes visitor data on the operator's behalf, making the operator the controller of whatever that script collects. Bot protection is a pointed example, since detection inherently examines visitor signals such as network origin and browser characteristics. The controller must therefore know exactly what its verification vendor processes, on what legal basis, where the data flows, and whether the vendor uses any of it for its own purposes. A security vendor that recycles verification data into advertising or profiling shifts the operator's risk position substantially — and the operator, as controller, owns the consequences of that choice.

Choosing and Governing Processors

The GDPR obliges controllers to engage only processors offering sufficient guarantees, so vendor selection is itself a compliance act. The practical review: read the DPA before integrating, confirm the vendor acts strictly as a processor, and prefer services built on data minimization — privacy-first verification such as CaptchaFox processes signals transiently without cookies or persistent identifiers, which keeps the personal-data footprint the controller answers for small. Where servers stand matters too, since data residency determines whether cross-border transfer rules come into play. The guiding question for any embedded service stays the same: what would you have to defend if a regulator asked tomorrow?

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is a Web Cookie?

A web cookie is a small piece of data a website stores in the browser to remember state — the mechanism behind sessions, preferences, and tracking.

Read more
What Is Data Minimization?

Data minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires — collect less, keep it shorter.

Read more
What Is Data Residency?

Data residency is the question of where data is physically stored and processed — and which country's laws and authorities can reach it as a result.

Read more
What Is PII (Personally Identifiable Information)?

PII is any information that can identify a specific person, directly or in combination — from names and emails to IP addresses and device identifiers.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices