Start with the processing, not the contract label
The GDPR distinguishes controllers, which determine the purposes and means of processing, from processors, which process personal data on a controller's behalf. Those roles are functional: the facts of each processing activity matter more than the name used in a services agreement. [1][2]
- List each purpose separately, such as inviting a patient, collecting answers, calculating a score, preparing a report, supporting users, and securing the service.
- For each purpose, record who decides why the data is processed and who decides the essential means.
- Identify processing a supplier performs only on instructions and processing it may undertake for its own legitimate purposes.
- Revisit the map when a new integration, analytics use, model, or subprocessor changes the decisions being made.
Treat assessment data as sensitive health information
Assessment answers, scores, clinician notes, and associated identifiers may reveal information about physical or mental health. GDPR Article 9 prohibits processing special-category data unless a listed condition applies in addition to an Article 6 lawful basis. The appropriate bases depend on the service, organisation, and national law. [1]
From processing purpose to accountable role
A five-step process for assigning and maintaining GDPR roles in a digital assessment workflow.
- Name the purpose
Describe why each distinct processing activity exists.
- Trace decisions
Identify who chooses the purpose and essential means.
- Assign roles
Apply controller, joint-controller, or processor criteria to that activity.
- Bind duties
Document lawful bases, instructions, safeguards, and assistance.
- Review change
Repeat the analysis when data use, integrations, or suppliers change.
Document the common clinic and supplier pattern carefully
In a typical clinic-directed workflow, the clinic determines the clinical purpose, chooses the measure, selects recipients, sets review procedures, and controls retention. A software supplier may process the resulting personal data on documented instructions. That pattern often supports controller and processor roles, but it is not automatic and does not decide every secondary processing purpose. [2]
- Record the controller's instructions, confidentiality requirements, security obligations, subprocessor controls, deletion or return arrangements, and assistance duties in an Article 28 agreement.
- Do not describe two parties as joint controllers merely because both participate in the service. Joint control requires jointly determined purposes or essential means for the processing at issue.
- Separate supplier account administration and security processing from clinic-directed patient-data processing when their purposes and legal roles differ.
Build one accountable record of the workflow
A useful record links the role analysis to the actual data journey. It should show data categories, recipients, international transfers, retention, security controls, transparency notices, rights-request handling, breach escalation, and whether a data protection impact assessment is required. [1][3]
- Name an owner for the record and a trigger for review.
- Link each subprocessor and transfer mechanism to the data it can access.
- Test how correction, access, restriction, export, and deletion requests move between clinic and supplier.
- Keep the record aligned with the live configuration rather than the intended design alone.
Resolve five questions before launch
- What exact purposes require each category of assessment data?
- Who makes the decisive choices for each purpose?
- Which Article 6 basis and Article 9 condition has the controller documented?
- What instructions, safeguards, retention rules, and incident duties bind every processor?
- What event will cause the role and risk analysis to be reviewed?
Sources and further reading
- Regulation (EU) 2016/679 (General Data Protection Regulation) (opens in a new tab)European Union. Accessed 2026-07-13. Primary EU law for controller and processor definitions, lawful processing, special-category data, processor contracts, security, and DPIAs.
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR (opens in a new tab)European Data Protection Board. Published 2021-07-07. Accessed 2026-07-13. Authoritative EU guidance on functional role allocation, essential means, joint control, and processor obligations.
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 (WP248 rev.01) (opens in a new tab)Article 29 Working Party. Published 2017-10-13. Accessed 2026-07-13. EU supervisory-authority guidance on high-risk indicators and DPIA expectations. The EDPB endorsed this WP29 guideline.