Processing and Data Roles - Subject, Controller, Processor
Processing covers almost anything done with personal data. The data controller decides how and why data is processed and bears most obligations; the data processor acts on the controller's behalf - under HIPAA, processors are 'business associates'.
How this supports CIPP/US study
Use this lesson to identify the legal source, actor, data and activity before applying a rule to a scenario. Continue with the CIPP/US exam format and blueprint.
Processing refers to almost anything done with personal information - collection, recording, storage, use, disclosure, combination, blocking, erasure, or destruction. These terms were first widely used in the EU.
| Role | Definition |
|---|---|
| Data subject | The individual the information is about (patient, employee, customer) |
| Data controller | Decides how and why data is processed; focus of most obligations |
| Data processor | Processes data on the controller's behalf (often a third party); 'business associate' under HIPAA |
Each link in the chain - controller, processor, sub-processor - must act consistently with the controller's direction. A processor is not authorized to process data beyond what is permitted for the controller.
Key terms - quick answers
What is “Processing”?
What is “Data subject”?
What is “Data controller”?
What is “Data processor”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.