Regulation
Controller or processor: decide it per activity, not per company
The question is usually answered once for the whole business, and that answer is usually wrong for some of it.
Facts checked — 2026-09-11
Are you a controller or a processor?
A controller determines the purposes and means of processing; a processor acts on documented instructions. A firm running a platform for customers is a processor for the data those customers put into it — and a controller for its own employee records, its marketing list, and the account data of the customers themselves.
The role decides who owes notice, who answers a rights request, who notifies a breach and to whom. Getting it wrong in a contract creates duties you cannot discharge or leaves real ones unowned, and it is far cheaper to determine per processing activity at the start than to unpick later.
The bottom line
List your processing activities and label each one. It is an afternoon, and everything else in a privacy programme depends on it.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.