All resources
Blog 6 min read

Controller or processor? The ISO 27701 question that decides everything

C1The Compliance One team28 August 2026

Most privacy frameworks throw controls at you immediately. ISO 27701 does something smarter first: it makes you decide what you actually are. Because a privacy programme for a company that decides how personal data is used looks quite different from one for a company that just holds data on someone else's instructions. Everything downstream depends on this one call.

The two roles, in plain terms

A PII controller decides the why and the how: your own employee records, your marketing list, your customer accounts. You set the purposes, so you carry the obligations to the individuals, lawful basis, consent, rights requests, transparency.

A PII processor handles personal data on a customer's documented instructions, and only those. A SaaS platform storing its customers' data is the classic example. You do not decide why the data exists; you protect it, follow instructions, and help your customer meet their obligations.

Ask one question: for this data, do we decide why it is being used, or is someone else telling us? Decide-why is controller. Told-what-to-do is processor. Many companies are both, on different data.

Why it is not just semantics

The role decides your controls. ISO 27701's Annex A is split into controller controls (A.1) and processor controls (A.2), plus security controls (A.3) that apply to everyone. A pure controller does not need the subprocessor-disclosure machinery; a pure processor does not run consent capture. Applying the wrong set means either drowning in irrelevant controls or, worse, missing the ones that actually protect you and your customers.

The catch is that most real companies are both. You are a controller of your own staff and prospect data, and a processor of the data your customers push into your product. 27701 handles this cleanly: you determine the role per processing activity, and maintain separate control sets where you wear both hats.

How Compliance One removes the guesswork

The platform enables the controller and security controls by default, since every organisation is a controller of its own data, and makes the processor controls one click to promote when you handle personal data for customers. A clear banner on the Statement of Applicability explains the distinction in plain language, so the person doing the work can pick the right set with confidence. The hardest conceptual step in 27701 becomes a decision the tool walks you through, not a debate you have with a consultant.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.