Data controller vs data processor: what is the difference for data licensing?

A data controller decides why and how personal data is processed; a data processor handles it on the controller's behalf and only on its instructions. California's CCPA uses business and service provider for similar roles. For licensing, the line is decisive: records a company holds as a processor for its clients are generally not its own to license.

The short answer: whoever decides the purpose is the controller

Under the EU's General Data Protection Regulation, a controller is the person or organization that, alone or jointly with others, determines the purposes and means of processing personal data. A processor processes personal data on the controller's behalf. Article 28 requires a processor to act only on the controller's documented instructions, and Article 28(10) adds that a processor which starts determining purposes and means itself is treated as a controller for that processing.

The same company is often both. A payroll provider is the controller of its own staff files and its sales CRM, and a processor of the employee data its clients send it. The question is always asked per dataset, never per company.

For a company weighing whether to license records to AI labs and data buyers, the line is decisive. Records it controls may be candidates, subject to its notices, contracts and policies. Records it holds as a processor for clients are generally the clients' to decide about, and using them for the company's own licensing deal would turn it into a controller without the right to be one.

Controller vs processor, side by side

FactorControllerProcessor
Core testDecides why and how personal data is processedProcesses it on the controller's behalf
Purpose of processingIts ownThe controller's, as instructed
Essential meansDecides which data, how long it is kept and who sees itChooses technical details within the instructions
ContractMust bind its processors to the required termsMust follow the processing agreement
Using the data for its own endsAllowed within the law and its own noticesNot allowed; doing so makes it a controller for that processing
Requests from individualsAnswers themHelps the controller answer them
Typical examplesAn employer for HR files; a retailer for its customer listA payroll bureau, cloud host, call center or email platform working for clients
Licensing positionMay license records it controls, within its promises and rightsGenerally cannot license client data without the client's authority

The CCPA version: business vs service provider

California uses different words for a similar split. The CCPA applies to for-profit businesses doing business in California that meet any one of three thresholds, which the California Attorney General's CCPA overview lists. Under section 1798.100 of the CCPA statute, a business that discloses personal information to a service provider or contractor must have a written agreement limiting its use to specified purposes. In practice a service provider sits where a GDPR processor sits: it may use the information for the business purposes the contract names, not sell or share it or put it to unrelated uses of its own.

RoleGDPR termCCPA termWho sets the purpose
Decides purposesControllerBusinessItself
Acts on instructionsProcessorService provider or contractorThe controller or business
Shares decisions with another partyJoint controllerNo separate defined roleBoth, under an arrangement
Receives data for its own separate purposesIndependent controllerThird partyItself, once it has the data

The last row answers a common question about licensing. When a company licenses records to an AI developer that will use them for its own training purposes, any personal data left in the delivery would generally reach the licensee as an independent controller. That is one reason de-identification and redaction requirements are agreed with the company before any work begins, and why data is delivered only after an executed agreement and the company's authorization.

Am I a controller or a processor? A self-test

Answer per dataset, not for the company as a whole.

  • Did we decide to collect this data for our own business reasons?
  • Do we decide how long it is kept and who can see it?
  • Would we still hold it if a particular client left?
  • Is it about our own staff, our own customer relationships or our own operations?
  • Does a client contract say we process it on the client's behalf, or limit us to using it to provide a service?
  • Did a client upload, send or own the underlying material?

If the first four answers are yes and the last two are no, the company is probably the controller of that dataset. If a client contract limits its use, treat the data as the client's.

Examples by business type

BusinessRecords it usually controlsRecords it usually holds for clients
Managed service providerIts own ticket workflow, runbooks, staffing and finance recordsData inside the client systems it administers
Contact center or BPOIts own training material, QA rubrics and workforce dataCalls and chats with the client's customers
B2B software companyIts CRM, its support history and its engineering historyContent customers store in the product
Staffing firmIts recruiting pipeline and placement history, subject to its noticesData a client sends for a managed program
Marketing agencyIts own proposals, project management and finance recordsClient customer lists and campaign data

Every row depends on contracts. An MSP's own ticket system, for example, may still contain client confidential information, so client agreements matter even for records the MSP controls. The licensing screen is also wider than privacy law: non-personal client material, such as a client's documents or code, belongs to the client unless a contract says otherwise.

Why this is the first screen for data licensing

SourceX treats data that belongs to someone else as a red flag: an outsourcer's or agency's client records, licensed without those clients' consent, are not a licensable asset. Even a company that controls its records has to check what it promised. FTC staff have warned that adopting more permissive data practices, such as using consumers' data for AI training, and telling people only through a surreptitious, retroactive change to terms of service or a privacy policy could be unfair or deceptive (FTC Technology Blog, February 2024).

The strongest candidates are usually a company's own operational history: internal email and chat, its own CRM and support records, finance and project files. Old archives that nobody uses are often controller data that has never been reviewed; what dark data is explains why they matter. And because a license grants rights without handing over ownership, the company keeps its records, as licensing vs selling data sets out.

Limits and open questions

  • A contract label helps but does not settle the question; what each party actually does matters.
  • GDPR can apply to organizations outside the EU that offer goods or services to, or monitor the behavior of, people in the EU.
  • Other US state privacy laws use their own terms and thresholds.
  • Health information adds HIPAA's own categories, covered in PII vs PHI.
  • Employee data raises notice and employment-law questions even when the company is the controller.

This is general information, not legal, tax or financial advice. Confirm with your own counsel or privacy officer before acting.

Next step

Owners can run a preliminary screen with the company fit checker and read the who qualifies baseline: a US company with 50+ full-time employees at peak (contractors excluded), years of documented operations, rights to what it would license and an authorized sponsor. Apply at sourcex.si/apply. Advisors who know a company whose own records pass this screen can register as a partner and make the introduction.

Common questions

Can a processor license client data if it removes names first?

Generally no, not on its own authority. Removing identifiers does not change who the records belong to or what the client contract allows. A license of client material needs the client's authorization as controller and a lawful basis, which in practice means the client, not the processor, would be the company licensing the data.

Is an AI developer that licenses company records a controller or a processor?

When it uses licensed records for its own training purposes, it decides why the data is used, so any personal data it receives would generally reach it as an independent controller rather than a processor. That is why the licensing company agrees de-identification and redaction requirements before work begins, and why delivery happens only under an executed agreement.

Does GDPR apply to a US company's records?

It can. GDPR reaches organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior there. A US company with EU customers, users or staff should identify which records contain their personal data and get advice before including any of it in a license, even if most records are about US activity.

What is the difference between joint controllers and independent controllers?

Joint controllers decide the purposes and means of the same processing together and must set out their respective responsibilities. Independent controllers each decide their own purposes, even when data passes between them, as when one company shares a dataset with another that then uses it for its own reasons. A data license usually follows the second pattern.

Is a company the controller of its employees' work email?

Generally yes, because the company decides why its email system exists and how long messages are kept. That does not make every message licensable. Employee notices and policies, employment and privacy law, and client confidential information inside the messages all need review, and personal data is handled under redaction rules agreed before any work begins.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment