Key terminology: controller, processor, personal data, processing
Sign in to track progress on this lesson.
01 — Main lesson
Full walk-through. · 5.9 MB
Spoken script — useful when names or terms sound ambiguous.
Welcome back. This is the next lesson in your data protection walking series, and today we are unpacking four words that make the whole United Kingdom General Data Protection Regulation come alive in everyday situations.
You already know the history, how British privacy law evolved from the early Data Protection Act to the modern framework we have now. But when you actually read a privacy policy or hear about a company being fined by the Information Commissioner's Office, you need to understand exactly what personal data, processing, controller, and processor mean.
Let us start with personal data. The United Kingdom General Data Protection Regulation defines it as any information relating to an identified or identifiable living individual. That sounds simple, but the net is cast surprisingly wide. It is not just your name, address, and national insurance number. It is your email address, your phone's internet protocol address, the location data your fitness app logs, and even the unique cookie identifier that follows you around websites. If a piece of information can be linked back to you, directly or indirectly, it is personal data.
Imagine you sign up to a local gym. You hand over your name, your email, your home address, and your date of birth. That is clearly personal data. But the gym also notes your blood pressure and any injuries before you start training. That health information is still personal data, though the law treats it as a special category that needs extra protection. Even your membership number, if the gym keeps it alongside your name, counts as personal data. And if the gym has closed-circuit television cameras at the entrance, footage that shows your face clearly enough to recognise you is personal data too. The key idea is identifiability. If the data, combined with other information the gym holds, points to you, it falls under the regulation.
Now, what is processing? This is another word that sounds narrower than it really is. Processing means any operation performed on personal data. That includes collecting it, recording it, organising it, structuring it, storing it, adapting it, altering it, retrieving it, consulting it, using it, disclosing it by transmission, erasing it, or destroying it. Essentially, if you so much as glance at the data, you are probably processing it. Even anonymising your data later, if the gym decides to strip out names for a statistical report, counts as processing because an operation is still being performed on that data set.
Stay with the gym example. When the receptionist types your details into their computer system, that is processing. When the system stores your file on a server, that is processing. When the personal trainer opens your record to check your old shoulder injury, that is processing. When the gym sends your email address to a marketing company to promote a new yoga class, that is processing. When the gym finally deletes your record because you cancelled three years ago, that is also processing. The law covers the entire lifecycle of the data from the moment it is collected to the moment it disappears.
So now you know what personal data is and what processing means. The next question is who is doing it and why. This brings us to the controller. A controller is the natural or legal person, public authority, agency, or other body which determines the purposes and means of the processing. In plain English, the controller is the organisation that decides why your data is needed and how it will be handled.
In our gym scenario, the gym itself is the controller. The gym decided it needs your contact details to manage your membership. It decided it needs your health information to design a safe exercise programme. It chose the software system where your records live. It controls the relationship with you. Because it makes those decisions, it carries the main burden of complying with the United Kingdom General Data Protection Regulation. It must tell you what it is doing with your data. It must have a lawful basis for every type of processing. It must respect your rights when you ask to see your data or ask for it to be deleted.
But here is where it gets interesting. Very few organisations operate entirely alone. Our gym probably does not build its own computer servers from scratch. It likely rents cloud storage from a technology company. Suppose the gym hires an external company to run its booking app. The app company stores member names, email addresses, and class bookings on its cloud platform. The app company does not decide that it wants your email for its own business purposes. It is simply providing a service to the gym, following the gym's instructions about what data to hold and how to secure it. That makes the app company a processor.
A processor is a person or organisation that processes personal data on behalf of the controller. The processor does not decide the why or the how. It acts under the controller's instructions. Under the old Data Protection Act, processors had fewer direct duties. Under United Kingdom General Data Protection Regulation, processors have real legal obligations too. They must keep records, they must help the controller respond to your rights requests, and they must report certain data breaches to the controller without delay. The law also says there must be a written contract between the controller and the processor. That contract sets out exactly what the processor is allowed to do with the data, how long it can keep it, and what security measures it must follow. If a processor ignores those instructions and goes off script, it breaks the rules and can be fined directly by the Information Commissioner's Office.
Let me give you another everyday example to cement this. Imagine you buy a coffee table from an online furniture shop based in Manchester. You type your name, address, and payment details into their website. The shop is the controller. It decided it needs your address to deliver the table and your payment details to take your money. It also decided to use an email marketing platform to send you an order confirmation. That platform sees your name and email address, but only to help the shop communicate with you.
Now the shop does not actually make the table. It uses a factory in Birmingham. To ship the table, the shop passes your name, address, and phone number to a national courier company. The courier is acting on the shop's instructions to deliver your parcel. The courier is a processor. It should not use your phone number to start sending you its own promotional texts. If it did, it would be stepping outside its processor role and acting like a controller for that new purpose.
Meanwhile, the shop also uses a payment gateway company to handle your card details. That gateway is another processor. It runs the technical operation of charging your card, but it does not decide to start analysing your buying habits for its own ends. If it did, it would breach its processor status.
This distinction matters enormously when things go wrong. If the courier loses a handheld device containing hundreds of customer addresses, who is responsible to the regulators? The shop as controller remains ultimately accountable to the Information Commissioner's Office for the security of your data. However, the courier as processor also has its own direct legal duties, like reporting the loss quickly and helping to fix the situation. They are in it together, but the controller is the captain of the ship.
There is one more layer worth knowing. Sometimes two organisations decide together why and how to process data. Maybe the gym and a health insurance company run a joint wellness programme. They both decide to collect your step count and share the results. In that case, they can be joint controllers. But in most day-to-day situations, the roles are clear. One party decides, the other carries out the technical work.
Let us bring all four terms together. Personal data is the raw material, the information about you. Processing is anything that is done with that information. The controller is the decision maker who sets the purposes and the means. The processor is the helper who handles the data under the controller's instructions.
If you can identify those four pieces in any real-world situation, you instantly understand who is doing what and who is answerable. When you read a news headline about a major fine, you can now ask the right questions. What personal data was involved? What processing went wrong? Who was the controller who made the decisions? Were they using a processor who failed to keep the data safe? Did the processor have a proper contract in place?
As you near the end of this walk, try looking at your own phone. Every app that knows your name, your location, or your preferences is handling personal data. Every company behind those apps is either a controller or a processor. The law you learned about last time gives you rights over all of them, but those rights only make sense once you know which role each party plays.
So keep these four words in your pocket. Personal data. Processing. Controller. Processor. They are the building blocks that turn abstract legal history into something you can spot on every website, in every shop, and in every news story. Well done.
You already know the history, how British privacy law evolved from the early Data Protection Act to the modern framework we have now. But when you actually read a privacy policy or hear about a company being fined by the Information Commissioner's Office, you need to understand exactly what personal data, processing, controller, and processor mean.
Let us start with personal data. The United Kingdom General Data Protection Regulation defines it as any information relating to an identified or identifiable living individual. That sounds simple, but the net is cast surprisingly wide. It is not just your name, address, and national insurance number. It is your email address, your phone's internet protocol address, the location data your fitness app logs, and even the unique cookie identifier that follows you around websites. If a piece of information can be linked back to you, directly or indirectly, it is personal data.
Imagine you sign up to a local gym. You hand over your name, your email, your home address, and your date of birth. That is clearly personal data. But the gym also notes your blood pressure and any injuries before you start training. That health information is still personal data, though the law treats it as a special category that needs extra protection. Even your membership number, if the gym keeps it alongside your name, counts as personal data. And if the gym has closed-circuit television cameras at the entrance, footage that shows your face clearly enough to recognise you is personal data too. The key idea is identifiability. If the data, combined with other information the gym holds, points to you, it falls under the regulation.
Now, what is processing? This is another word that sounds narrower than it really is. Processing means any operation performed on personal data. That includes collecting it, recording it, organising it, structuring it, storing it, adapting it, altering it, retrieving it, consulting it, using it, disclosing it by transmission, erasing it, or destroying it. Essentially, if you so much as glance at the data, you are probably processing it. Even anonymising your data later, if the gym decides to strip out names for a statistical report, counts as processing because an operation is still being performed on that data set.
Stay with the gym example. When the receptionist types your details into their computer system, that is processing. When the system stores your file on a server, that is processing. When the personal trainer opens your record to check your old shoulder injury, that is processing. When the gym sends your email address to a marketing company to promote a new yoga class, that is processing. When the gym finally deletes your record because you cancelled three years ago, that is also processing. The law covers the entire lifecycle of the data from the moment it is collected to the moment it disappears.
So now you know what personal data is and what processing means. The next question is who is doing it and why. This brings us to the controller. A controller is the natural or legal person, public authority, agency, or other body which determines the purposes and means of the processing. In plain English, the controller is the organisation that decides why your data is needed and how it will be handled.
In our gym scenario, the gym itself is the controller. The gym decided it needs your contact details to manage your membership. It decided it needs your health information to design a safe exercise programme. It chose the software system where your records live. It controls the relationship with you. Because it makes those decisions, it carries the main burden of complying with the United Kingdom General Data Protection Regulation. It must tell you what it is doing with your data. It must have a lawful basis for every type of processing. It must respect your rights when you ask to see your data or ask for it to be deleted.
But here is where it gets interesting. Very few organisations operate entirely alone. Our gym probably does not build its own computer servers from scratch. It likely rents cloud storage from a technology company. Suppose the gym hires an external company to run its booking app. The app company stores member names, email addresses, and class bookings on its cloud platform. The app company does not decide that it wants your email for its own business purposes. It is simply providing a service to the gym, following the gym's instructions about what data to hold and how to secure it. That makes the app company a processor.
A processor is a person or organisation that processes personal data on behalf of the controller. The processor does not decide the why or the how. It acts under the controller's instructions. Under the old Data Protection Act, processors had fewer direct duties. Under United Kingdom General Data Protection Regulation, processors have real legal obligations too. They must keep records, they must help the controller respond to your rights requests, and they must report certain data breaches to the controller without delay. The law also says there must be a written contract between the controller and the processor. That contract sets out exactly what the processor is allowed to do with the data, how long it can keep it, and what security measures it must follow. If a processor ignores those instructions and goes off script, it breaks the rules and can be fined directly by the Information Commissioner's Office.
Let me give you another everyday example to cement this. Imagine you buy a coffee table from an online furniture shop based in Manchester. You type your name, address, and payment details into their website. The shop is the controller. It decided it needs your address to deliver the table and your payment details to take your money. It also decided to use an email marketing platform to send you an order confirmation. That platform sees your name and email address, but only to help the shop communicate with you.
Now the shop does not actually make the table. It uses a factory in Birmingham. To ship the table, the shop passes your name, address, and phone number to a national courier company. The courier is acting on the shop's instructions to deliver your parcel. The courier is a processor. It should not use your phone number to start sending you its own promotional texts. If it did, it would be stepping outside its processor role and acting like a controller for that new purpose.
Meanwhile, the shop also uses a payment gateway company to handle your card details. That gateway is another processor. It runs the technical operation of charging your card, but it does not decide to start analysing your buying habits for its own ends. If it did, it would breach its processor status.
This distinction matters enormously when things go wrong. If the courier loses a handheld device containing hundreds of customer addresses, who is responsible to the regulators? The shop as controller remains ultimately accountable to the Information Commissioner's Office for the security of your data. However, the courier as processor also has its own direct legal duties, like reporting the loss quickly and helping to fix the situation. They are in it together, but the controller is the captain of the ship.
There is one more layer worth knowing. Sometimes two organisations decide together why and how to process data. Maybe the gym and a health insurance company run a joint wellness programme. They both decide to collect your step count and share the results. In that case, they can be joint controllers. But in most day-to-day situations, the roles are clear. One party decides, the other carries out the technical work.
Let us bring all four terms together. Personal data is the raw material, the information about you. Processing is anything that is done with that information. The controller is the decision maker who sets the purposes and the means. The processor is the helper who handles the data under the controller's instructions.
If you can identify those four pieces in any real-world situation, you instantly understand who is doing what and who is answerable. When you read a news headline about a major fine, you can now ask the right questions. What personal data was involved? What processing went wrong? Who was the controller who made the decisions? Were they using a processor who failed to keep the data safe? Did the processor have a proper contract in place?
As you near the end of this walk, try looking at your own phone. Every app that knows your name, your location, or your preferences is handling personal data. Every company behind those apps is either a controller or a processor. The law you learned about last time gives you rights over all of them, but those rights only make sense once you know which role each party plays.
So keep these four words in your pocket. Personal data. Processing. Controller. Processor. They are the building blocks that turn abstract legal history into something you can spot on every website, in every shop, and in every news story. Well done.
02 — Refresh
Short recap. · 904 KB
Spoken script — useful when names or terms sound ambiguous.
Let us do a quick recap of what you just learned. Personal data is any information relating to an identifiable living person. It is not just names and addresses. It includes email addresses, internet protocol addresses, location data, and even closed-circuit television footage that can recognise you.
Processing means any operation performed on that data. Collecting, storing, retrieving, using, sharing, and deleting all count. The law covers the entire lifecycle from collection to destruction.
A controller is the organisation that decides why personal data is needed and how it will be handled. It carries the main legal responsibility under the United Kingdom General Data Protection Regulation.
A processor acts on the controller's behalf and follows its instructions. Processors have direct legal duties too, including helping with your rights requests and reporting breaches quickly. They must also have a written contract with the controller.
Remember the online furniture shop. The shop was the controller because it decided to collect your address and payment details. The courier and payment gateway were processors, only handling data to fulfil the shop's instructions.
Those four building blocks, personal data, processing, controller, and processor, make the rest of data protection law understandable. Keep them in mind on your next walk. Well done.
Processing means any operation performed on that data. Collecting, storing, retrieving, using, sharing, and deleting all count. The law covers the entire lifecycle from collection to destruction.
A controller is the organisation that decides why personal data is needed and how it will be handled. It carries the main legal responsibility under the United Kingdom General Data Protection Regulation.
A processor acts on the controller's behalf and follows its instructions. Processors have direct legal duties too, including helping with your rights requests and reporting breaches quickly. They must also have a written contract with the controller.
Remember the online furniture shop. The shop was the controller because it decided to collect your address and payment details. The courier and payment gateway were processors, only handling data to fulfil the shop's instructions.
Those four building blocks, personal data, processing, controller, and processor, make the rest of data protection law understandable. Keep them in mind on your next walk. Well done.