The PDPL provides for two main roles in the data processing: a Controller and a Processor. They have different levels of responsibility in respect of the processing. The PDPL defines these terms as following.
Article 1 (18) of the PDPL
Controller: Any Public Entity, natural person or private legal person that specifies the purpose and manner of Processing Personal Data, whether the data is processed by that Controller or by the Processor.
Article 1 (19) of the PDPL
Processor: Any Public Entity, natural person or private legal person that processes Personal Data for the benefit and on behalf of the Controller.
A Controller is an entity that makes decisions about the purposes and manner of the processing. The responsibility for making such decisions can either be borne wholly by a single controller or shared among multiple controllers (e.g. if there are several Controllers in relation to the same processing activity). The Controller(s) is/are held ultimately accountable for the processing undertaken and have a larger set of obligations under the PDPL as compared to Processor(s).
A Processor is another role that is regulated by the PDPL. The Processor processes personal data on behalf of a Controller. As opposed to the Controller, the Processor does not make decisions about the purposes and manner of the processing.
Regardless of which of the two above roles you assume, the PDPL will apply to the processing of personal data by your organization in each role. Depending on the sector in which you operate, you may also need to comply with other data protection rules of the laws applicable to your sector (for example, healthcare sector, banking and financial sector).
At all times, a Controller must ensure that the Processor(s) it engages fully complies with the PDPL.