Back to Publications
Regulatory Brief · GDPR

Cloud Providers Must Clarify Controller vs. Processor Status: CNIL's New Guidance

30 May 2026By NexCyber Editorial GDPR

The French data protection authority (CNIL) published guidance in May 2026 that cuts to the heart of a long-standing ambiguity in cloud computing: who is the data controller, and who is the processor under GDPR? The answer has profound implications for liability, enforcement, and the very architecture of cloud-based data processing. Yet many organizations—both cloud providers and their customers—continue to operate under outdated or incorrect assumptions about their roles, exposing themselves to

The French data protection authority (CNIL) published guidance in May 2026 that cuts to the heart of a long-standing ambiguity in cloud computing: who is the data controller, and who is the processor under GDPR? The answer has profound implications for liability, enforcement, and the very architecture of cloud-based data processing. Yet many organizations—both cloud providers and their customers—continue to operate under outdated or incorrect assumptions about their roles, exposing themselves to joint liability and regulatory action.

This article examines CNIL’s new framework for role identification, the enforcement risks of misclassification, and practical steps to audit cloud vendors and build a defensible data processing inventory.

---

Why Cloud Role Misclassification Is a Hidden Compliance Crisis

GDPR distinguishes between two primary roles in data processing: the controller (who determines the purposes and means of processing) and the processor (who processes data on behalf of the controller). The distinction is not academic. Controllers bear primary responsibility for compliance, including lawful basis, transparency, and data subject rights. Processors, while still accountable, operate under the controller’s instructions and are subject to contractual and regulatory obligations (GDPR Articles 24, 28, and 29).

In cloud environments, however, the lines blur. A provider may offer a "fully managed" service that includes data classification, retention policies, or even automated decision-making—activities that typically fall under the controller’s remit. Conversely, a customer may retain control over encryption keys, access logs, and data lifecycle management, preserving its processor status. The result is a spectrum of hybrid arrangements where neither party is certain of its role.

CNIL’s guidance highlights three common misclassification scenarios:

  1. 1Infrastructure-as-a-Service (IaaS) providers assuming processor status by default, even when customers configure services in ways that grant the provider de facto control over processing purposes.
  2. 2Software-as-a-Service (SaaS) providers claiming processor status while embedding automated data processing (e.g., analytics, profiling) that aligns with their own business objectives.
  3. 3Multi-tenant cloud platforms where shared security and compliance tools (e.g., logging, monitoring) create joint control scenarios that neither party documents.

The compliance risk is twofold. First, misclassification leads to gaps in accountability. If a provider incorrectly assumes processor status, it may fail to implement controller obligations like data protection impact assessments (DPIAs) or data subject access requests (DSARs). Second, regulators increasingly target both parties in enforcement actions, particularly when role ambiguity obscures responsibility for breaches or non-compliance.

---

CNIL's New Role-Identification Framework for Cloud Actors

CNIL’s May 2026 guidance introduces a three-step test to determine whether a cloud provider acts as a controller, processor, or joint controller. The framework builds on the European Data Protection Board’s (EDPB) 2020 guidelines on controller/processor roles (EDPB Guidelines 07/2020) but tailors the analysis to cloud-specific challenges.

Step 1: Assess the Provider’s Influence Over Processing Purposes

A provider is likely a controller if it:

  • Defines the objectives of processing (e.g., "improve service performance through analytics").
  • Determines the categories of data processed (e.g., collecting device identifiers or location data by default).
  • Uses data for its own purposes (e.g., training AI models, selling anonymized insights).

CNIL cites the example of a cloud-based customer relationship management (CRM) provider that automatically aggregates and analyzes user data to generate "engagement scores." Because the provider defines the purpose (improving customer insights) and the means (automated scoring algorithms), it acts as a controller for that processing activity—even if the customer retains control over other aspects of the service.

Step 2: Evaluate the Provider’s Discretion Over Processing Means

A provider is likely a processor if it:

  • Processes data only on documented instructions from the customer.
  • Has no independent decision-making authority over data retention, deletion, or security measures.
  • Acts as a neutral intermediary (e.g., transmitting or storing data without modification).

However, CNIL warns that even processors can cross into controller territory if they exercise significant discretion over technical or organizational means. For example, a cloud storage provider that unilaterally implements data deduplication or compression algorithms may be determining the "means" of processing, thereby assuming controller obligations for those activities.

Step 3: Identify Joint Control Scenarios

Joint control arises when two or more parties jointly determine the purposes and means of processing (GDPR Article 26). CNIL identifies three cloud-specific joint control patterns:

  1. 1Shared security tools: A provider and customer co-manage access controls, encryption keys, or audit logs.
  2. 2Integrated compliance features: A provider offers pre-configured GDPR compliance modules (e.g., consent management, data retention policies) that the customer can customize but not fully disable.
  3. 3Data pooling: Multiple customers contribute data to a shared analytics platform (e.g., benchmarking tools), where the provider and customers jointly define processing purposes.

In joint control scenarios, CNIL requires a transparent arrangement (e.g., a joint controller agreement) that allocates responsibilities for data subject rights, breach notifications, and DPIAs. The agreement must be specific, granular, and publicly accessible—vague or boilerplate language will not suffice.

---

The Joint Liability Trap: When Ambiguous Roles Trigger Enforcement

Role ambiguity does not shield organizations from liability. Under GDPR Article 83, regulators can impose fines of up to €20 million or 4% of global turnover for violations, and both controllers and processors can be held jointly and severally liable for damages (GDPR Article 82). CNIL’s guidance signals a shift toward proactive enforcement of role clarity, particularly in cloud environments where misclassification is rampant.

Case Study: The 2025 EDPB Cloud Enforcement Sweep

In late 2025, the EDPB coordinated a pan-European enforcement sweep targeting cloud providers and their customers. The sweep revealed that:

  • 68% of providers claimed processor status in contracts but exercised controller-like discretion in practice (e.g., setting default data retention periods).
  • 42% of customers failed to document instructions to processors, leaving them exposed to joint liability for provider misconduct.
  • 23% of joint control scenarios lacked formal agreements, violating GDPR Article 26.

The sweep resulted in 12 enforcement actions, including fines for both providers and customers. In one case, a German cloud provider was fined €3.2 million for acting as a controller (by using customer data for internal analytics) while contractually limiting its liability as a processor. The customer, a financial institution, was also fined €1.8 million for failing to audit the provider’s processing activities.

The IQVIA Sanction: A Warning for Data Warehouse Governance

The 2024 IQVIA sanction by the Irish Data Protection Commission (DPC) offers a cautionary tale for organizations using cloud-based data warehouses. IQVIA, a healthcare data analytics provider, acted as a joint controller with its pharmaceutical clients for processing patient data in a shared cloud environment. However, IQVIA’s contracts misclassified itself as a processor, and the DPC found that:

  • IQVIA determined the purposes of processing (e.g., "enhancing drug development insights") without customer input.
  • The lack of a joint controller agreement left data subjects unaware of their rights or how to exercise them.
  • IQVIA’s failure to conduct a DPIA for high-risk processing violated GDPR Article 35.

The DPC imposed a €12 million fine on IQVIA and required the company to rewrite all cloud contracts to reflect its controller status. The case underscores that regulators will not accept contractual misclassification as a defense—substance over form prevails.

---

Practical Steps to Audit Your Cloud Vendor's GDPR Status

CNIL’s guidance provides a roadmap for organizations to audit their cloud vendors and clarify roles. Below are actionable steps to implement the framework.

1. Map Processing Activities to Roles

  • Inventory all cloud services used by your organization, including SaaS, PaaS, and IaaS.
  • For each service, document: - The purposes of processing (e.g., "store customer records," "analyze sales data"). - The means of processing (e.g., "provider’s encryption algorithm," "customer-defined retention policy").
  • Use CNIL’s three-step test to classify the provider’s role for each activity.

2. Review Contracts for Role Alignment

  • Compare the contractual role (e.g., "processor") with the actual role determined in Step 1.
  • Look for discrepancies where the contract limits the provider’s liability but the provider exercises controller-like discretion.
  • Ensure processor contracts include: - Documented instructions for processing (GDPR Article 28(3)(a)). - Security obligations (e.g., encryption, access controls) (GDPR Article 32). - Sub-processor approval requirements (GDPR Article 28(2)).

3. Assess Joint Control Scenarios

  • Identify shared tools or features (e.g., logging, monitoring, compliance modules) that may create joint control.
  • Draft a joint controller agreement (GDPR Article 26) that: - Allocates responsibility for data subject rights (e.g., DSARs, erasure requests). - Defines breach notification procedures. - Specifies DPIA responsibilities.
  • Ensure the agreement is publicly accessible (e.g., via a privacy notice or dedicated webpage).

4. Conduct a Data Protection Impact Assessment (DPIA)

  • For high-risk processing (e.g., large-scale data