A data controller and a data processor are two roles defined by data-protection laws such as the GDPR. The controller decides why and how personal data is processed; the processor handles that data only on the controller's instructions. In email marketing, the business that owns the subscriber list is the controller, and its email platform is the processor.

How the roles differ

The controller determines the purposes and means of processing — what data to collect, why, and how long to keep it — and is primarily responsible to the individuals whose data it holds. The processor acts for the controller and must not use the data for its own purposes. Their responsibilities are set out in a data processing agreement, a contract the GDPR requires between the two parties.

Why the distinction matters for email

When you send campaigns, you are the controller of your contacts' data and your email service provider is the processor — so you choose what data to collect and rely on the provider to safeguard it. Choosing a processor with strong privacy practices reduces your risk. Capture clear consent, and consider where data lives — see data residency. Mailpro acts as a privacy-first, Swiss-hosted processor. Read our guide to GDPR-compliant email software or our GDPR privacy-policy FAQ.

Mailpro and privacy

A processor you can trust with your data

As your data processor, Mailpro is built privacy-first and hosted in Switzerland, safeguarding your contacts' data so you can meet your obligations as the controller.

Start free with MailproSet up double opt-in

Previous Article

   

Next Article

You might also be interested in:

Data residency refers to the physical country or jurisdiction where data is stored. In simple terms, it answers the question: where does your data live? When a business stores contact lists, form responses, email content, custo...
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, required under Article 28 of the GDPR, that sets out how the processor may handle personal data on the controller'...
A data controller and a data processor are two roles defined by data-protection laws such as the GDPR. The controller decides why and how personal data is processed; the processor handles that data only on the controller's instruc...