Compliance

Controller / Processor

GDPR roles applicable to AI providers and deployers.

Definitions (3)

The GDPR roles that determine legal responsibilities in AI contexts: a controller decides purposes and means of processing, while a processor acts on behalf of a controller; the guidance explains how these roles apply to AI providers, deployers and third‑party suppliers depending on decision‑making and purposes.

As defined under the Personal Data Protection Law (PDPL) and SDAIA national data governance policies, controllers and processors are entities that determine the purposes and means of processing personal data (controllers) or process personal data on behalf of controllers (processors); they are subject to PDPL obligations and, where applicable, registration with SDAIA's national register and compliance tools.

Designated public-entity roles where a Controller determines the purposes and means of processing personal data and a Processor acts on behalf of the Controller to perform processing tasks, with delineated responsibilities for compliance and safeguards.