
Understanding Who’s Responsible for What Under UK Data Protection Law
One of the most common questions we receive from clients relates to their data. “Why is Sarah’s mailbox full?” “What’s using all the space on our file server?” “Can you tell us what emails John has been deleting?”
These are perfectly reasonable questions, but the answers often surprise business owners. As your IT provider, we can tell you how much data exists and where it’s stored—but we can’t tell you what that data contains or make decisions about it. That’s not us being unhelpful; it’s data protection law working exactly as it should.
Understanding the difference between a data controller and a data processor is essential for every business owner. It clarifies responsibilities, prevents misunderstandings, and ensures your business remains compliant.
The Two Key Roles in Data Protection
UK data protection law defines two distinct roles when it comes to handling personal data. Most businesses will act as both at different times, but understanding which hat you’re wearing in each situation is crucial. Continue reading







