A data controller and a data processor are two roles defined by data-protection laws such as the GDPR. The controller decides why and how personal data is processed; the processor handles that data only on the controller's instructions. In email marketing, the business that owns the subscriber list is the controller, and its email platform is the processor.
How the roles differ
The controller determines the purposes and means of processing — what data to collect, why, and how long to keep it — and is primarily responsible to the individuals whose data it holds. The processor acts for the controller and must not use the data for its own purposes. Their responsibilities are set out in a data processing agreement, a contract the GDPR requires between the two parties.
Why the distinction matters for email
When you send campaigns, you are the controller of your contacts' data and your email service provider is the processor — so you choose what data to collect and rely on the provider to safeguard it. Choosing a processor with strong privacy practices reduces your risk. Capture clear consent, and consider where data lives — see data residency. Mailpro acts as a privacy-first, Swiss-hosted processor. Read our guide to GDPR-compliant email software or our GDPR privacy-policy FAQ.
Mailpro and privacy
A processor you can trust with your data
As your data processor, Mailpro is built privacy-first and hosted in Switzerland, safeguarding your contacts' data so you can meet your obligations as the controller.