Data controller and data processor

Also called controller vs processor, data processing agreement, DPA

Under the GDPR and the laws modelled on it, the data controller decides why and how personal data is processed, and the data processor handles it on the controller's instructions. For a clinic using software, the clinic is the controller of its patients' data and the software vendor is a processor acting for it.

This is not a technicality about who stores the file. It decides who answers to the patient, who answers to a regulator, and what has to be written down between the two of you.

Which one is the clinic

The clinic, essentially always. You decided to collect the record, you decide what is in it, how long it stays and who may see it. A vendor who told you they were the controller of your patient data would be telling you something alarming.

The vendor is a processor: it holds and moves the data to do the job you are paying for, and may not decide to do something else with it. Its own sub-vendors — hosting, email delivery, payments — are sub-processors, and you are entitled to know who they are.

What that requires in practice

  • A written agreement between controller and processor. Usually called a data processing agreement, and it is the vendor's job to have one ready rather than to promise one by email.
  • A list of sub-processors, and notice when it changes.
  • Somewhere the data lives, stated. If it leaves the region, a lawful basis for the transfer — standard contractual clauses being the usual instrument.
  • A way to answer a patient. Access, correction, deletion and export are the controller's obligation, so the software has to let you do them without asking the vendor.
Note

This is the general shape rather than legal advice, and the details differ by country — the UK, the EU member states and Türkiye each have their own version. If you operate across more than one, building against the strictest is the cheapest rule.

The question worth asking a vendor

Not "are you GDPR compliant", which everybody answers yes to. Ask to see the agreement they would sign with you, the list of who else processes the data, and where it is stored. A vendor who has thought about it has three documents; one who has not has an email promising them.

Common questions

Is the clinic or the software company the data controller?
The clinic. You decide why the data is collected and what happens to it; the vendor processes it on your instructions. That is why the obligation to answer a patient's access or deletion request sits with you.
Do we need a data processing agreement with our software vendor?
Yes, wherever the GDPR or a law modelled on it applies. It should be available to read before you buy rather than produced after you ask — and a vendor who publishes it has made your due diligence a five-minute job.

Read next

Clinic+ is a practice management system for clinics

Scheduling, patient records, billing and stock in one place, with an assistant that answers your website and books real slots. Free to start, no card.