All Masterclasses
    Past Masterclass June 25, 2026

    Controller vs. Processor under the Saudi PDPL: Classification and Contract Governance

    Deciding whether a party is a controller or a processor under the Saudi Personal Data Protection Law (PDPL) is one of the most consequential, and most frequently rushed, judgments a privacy team makes. In this masterclass, Muneeb Imran argues that classification is a risk decision before it is a legal one: the label two organizations agree on in a contract does not change the operational reality of who decides why and how personal data is processed, and a regulator examines the reality, not the wording. Moving across controller, processor, joint controller and independent controller roles, he shows how the wrong classification quietly inflates regulatory exposure, weakens the remedies available to data subjects, and leaves a data processing agreement that cannot be enforced when it matters. The session connects classification to the contract requirements in Article 17 of the Implementing Regulations and to the due diligence, monitoring and audit obligations that follow from it.

    Presenters

    Muneeb Imran
    Muneeb Imran
    Data Privacy & AI Governance Expert. DPO, Co-author, Data Privacy: A Practical Handbook for Governance and Operations

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Classification drives every downstream duty. Whether a party is a controller, processor, joint controller or independent controller determines its legal obligations, regulatory exposure, contractual burden, data subject duties, breach responsibilities, cross-border obligations and audit rights.
    • Operational reality overrides the contractual label. Two privacy teams can reach full agreement on who is the controller and who is the processor and still be wrong; a regulator assesses actual decision-making and data flows, not the words in the agreement.
    • The defining test is choice. A controller decides why personal data is processed, which is the lawful basis, and how it is processed; a processor acts on documented instructions and cannot set the purpose on its own.
    • A legal mandate is not a choice. Where a law compels an organization to share data with another, that sharing is not an act of choice, so it does not by itself make the sender a controller or the recipient a processor.
    • The law names only two roles, but four matter. The PDPL and its Implementing Regulations define only controller and processor; the transfer rules and standard contractual clauses recognize controller-to-controller arrangements, and treating joint or independent controller status as a deliberate option aligns with the law's purpose of protecting data subjects.
    • Joint and independent controller arrangements are risk-mitigating choices. They let an organization avoid absorbing another party's compliance failures, and they often fit better than forcing a smaller or differently regulated party into a processor role.
    • Independent controller status suits parties under different regulators. When two organizations report to separate authorities, for example the Saudi Central Bank (SAMA) and the Communications, Space and Technology Commission (CST), a controller-processor arrangement can collapse, because the recipient answers to its own regulator before it answers to a contractual controller.
    • Every processor enlarges your own risk landscape. A controller is accountable to its regulator for what happens inside its processors, so taking on more processors, or accepting processor status yourself, should follow a clear view of whether the commercial benefit justifies the compliance burden.
    • Lawful basis comes first, and consent is not the only one. Identifying why the data is processed precedes classifying the parties; treating consent as the sole lawful basis under the Saudi PDPL builds an architecture that fractures over time.
    • Not every vendor is a processor. A supplier of hardware, a reseller of a licence or subscription, or an analytics tool that never touches personal data may need no data processing agreement at all; the test is whether the party actually processes personal data.
    • Hosting introduces a subprocessor chain. A small software vendor can be your processor while the hyperscale cloud it runs on sits behind it as a subprocessor, so the whole value chain must be examined, not only the immediate counterparty.
    • Authority to classify sits with the privacy function. The determination is the competence and responsibility of the data protection officer (DPO) and privacy team, drawing facts from legal, compliance, IT, security and the business; it is not a decision the legal department makes alone.
    • Article 17 of the Implementing Regulations governs the processor contract. The controller-processor relationship is carried by a written agreement, supported by due diligence before signing and by monitoring, evidence and periodic audit afterward.
    • Roles drift, so contracts must be revisited. New functionality, added subprocessors or the introduction of AI can shift a party's role; a vendor that begins making independent decisions on the means of processing takes on controller liability, which the agreement should anticipate.
    • Wrong classification has concrete failure modes. It weakens data subject remedies, creates a false sense of contractual protection, produces audit rights that cannot be exercised across regulatory lines, and turns the data processing agreement into the first casualty of a breach.

    Frequently Asked Questions