Controller vs Processor
The GDPR distinguishes between the controller, who decides on the purposes and means of processing (Article 4(7)), and the processor, who handles personal data only on the controller's instructions (Article 4(8)). This distinction determines who carries which obligations, for example concluding a data processing agreement under Article 28.
In practice
In practice, almost every company with its own website uses processors such as hosting providers, email marketing tools or cloud storage – and the company itself remains the controller, obliged to conclude a data processing agreement under Article 28 with each provider. It gets harder when two parties decide jointly on purposes and means, for example with shared analytics or marketing tools: Article 26 on joint controllership then applies, with its own agreement on how tasks are divided. Getting the role wrong can lead to fines and to gaps in the processes for handling data subject rights.