Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is the foundation of any data protection programme. This is one of the reasons why every organisation should maintain a record of processing activities (ROPA).

Most organisations have many relationships in which they process personal information with other organisations, including customer-service-provider, vendor-buyer, and contractor-client relationships.

POPIA distinguishes between the ‘responsible party’ and the ‘operator’, while the GDPR distinguishes between the ‘data controller’ and the ‘data processor’. We will refer to them simply as the ‘responsible party’ and the ‘operator’. The ‘responsible party’ decides the purpose or ‘way’ of processing the personal information, and the ‘operator’ processes the personal information on behalf of a responsible party without being directly controlled by them. The responsible party carries most of the responsibility, while the operator carries much less.

Where you process personal information together with someone else, whether you are the responsible party or the operator depends on your relationship with them.

What different types of relationships are there?

Organisations often instruct other organisations to process personal information on their behalf or are instructed to do so by them. In a client-service provider relationship, the customer generally instructs the service provider. But the organisation doing the instructing isn’t always the responsible party and the organisation being instructed isn’t always the operator. It can be difficult to pinpoint who is playing which role. We will examine the three types of relationships: authority, liberty, and equality. Please click through the tabs to read about them.

We can help you to understand your relationships and responsibilities under data protection legislation with a Data Protection Responsibility Assessment.

Your relationships and working out who is responsible

Most relationships are more complicated than these examples and fall somewhere between these three categories. They may also shift categories from one activity to another.

Actions you can take

  1. Understand your relationships and responsibilities under data protection legislation by asking us to conduct a Data Protection Responsibility Assessment.
  2. Find out more about a ROPA by reading our guidance.
  3. Learn more about mapping activities by reading our insights.