Quick Answer: What is the difference between a controller and an operator under the LGPD?
Under Article 5 of Brazil's LGPD, the controller is the natural person or legal entity that has decision-making authority over personal-data processing, while the operator processes personal data on behalf of the controller. ANPD's current guidance makes the practical distinction clearer: the controller determines the purpose and other essential elements of the processing, whereas the operator follows the controller's lawful instructions and may decide non-essential technical or operational details. The role is assessed per processing operation, so the same company can be a controller in one context and an operator in another. The contract label is evidence, but the actual facts and decision-making power determine the role.
Key Takeaways
- Controller = essential decision-maker. Purpose is always a central controller decision.
- Operator = acts on behalf of the controller. It can make non-essential technical decisions without becoming a controller automatically.
- Roles are processing-specific. The same vendor can be an operator for one purpose and a controller for another.
- Employees are not normally separate operators of their employer. The legal entity is generally the processing agent when staff act under its authority.
- Joint controllership can exist under LGPD. ANPD recognizes it where two or more controllers jointly, commonly or convergently determine purposes and essential elements.
- Suboperator is an ANPD guidance concept, not an express LGPD definition. Formal controller authorization is recommended.
- A DPA does not create the role by itself. It should document and govern the role that actually exists.
The Legal Definitions
A natural person or legal entity, public or private, with decision-making authority regarding the processing of personal data.
A natural person or legal entity, public or private, that processes personal data on behalf of the controller.
The collective statutory category that includes controllers and operators.
Article 39 adds the central operator rule: the operator must process personal data according to the controller's instructions, while the controller verifies compliance with its instructions and applicable rules.
Ask who determines why the processing happens and who controls the essential elements needed to achieve that purpose. That party is usually acting as controller for the operation. A party that carries out the processing for that purpose under another party's instructions is usually acting as operator.
Roles Are Defined Per Processing Operation
This is probably the most important point in ANPD's guidance. The Agency says processing-agent status should be assessed for each personal-data processing operation.
The same organization can therefore be:
One company, different roles
Customer account data hosted for a client → Operator · Vendor's own billing records → Controller · Employee payroll → Controller · Customer-directed analytics service → Potential Operator · Vendor's independent product analytics → Potential Controller
This is why a global statement such as: “Vendor X is our processor” can be incomplete.
A better record says:
“Vendor X acts as operator for Activity A and as controller for Activity B.”
Contract labels are not conclusive
A contract can help demonstrate the intended relationship and establish instructions, but calling a company “processor,” “service provider” or “operator” does not override what the company actually does.
If a party independently decides to use the data for a new purpose, it may become a controller for that separate processing even if the contract still calls it an operator.
Which Decisions Belong to the Controller?
ANPD distinguishes between essential and non-essential processing decisions. The controller does not need to make every technical choice. It must, however, retain influence over the essential elements.
| Decision | Usually controller or operator? | Why |
|---|---|---|
| Purpose of processing | Controller | The controller determines the objective that justifies processing. |
| Legal basis for the controller's purpose | Controller | ANPD treats purpose and legal basis as essential controller decisions. |
| Nature/categories of personal data | Controller / essential | Choosing which type of personal data is necessary materially shapes the processing. |
| Duration / deletion period | Controller / essential | ANPD identifies processing duration as an essential element. |
| Choice of software or equipment | Can be operator | ANPD gives these as examples of non-essential technical decisions. |
| Detailed security implementation | Can be operator | The operator can choose technical prevention/security details while still following the controller's required outcome. |
| Independent new purpose | Controller for that purpose | A vendor that determines a new essential purpose is no longer acting only on behalf of the original controller for that use. |
Who determines the legal basis?
For controller-directed processing, the controller should determine and document the legal basis for its purpose. The operator should understand the instructions and avoid using the data outside that framework.
If the operator separately processes data for its own independent purpose, it needs its own controller analysis, including purpose, legal basis, transparency, retention and rights obligations for that separate processing.
Are Employees Operators?
Usually not when they act as part of the legal entity and under its authority. ANPD explains that, in the context of a legal entity, the organization itself is generally the processing agent because it establishes the processing rules that representatives, employees or agents execute.
Employees, administrators, partners, public servants and other people whose actions express the organization's activity should not normally be classified as separate operators merely because they touch personal data.
What Is Joint Controllership Under the LGPD?
The LGPD does not expressly define “joint controller.” ANPD nevertheless considers joint controllership implicitly recognized in the Brazilian framework, including through Article 42's liability structure.
ANPD defines joint controllership as the joint, common or convergent determination by two or more controllers of the purposes and essential elements of personal-data processing, through an arrangement that establishes their respective LGPD responsibilities.
ANPD's three practical criteria
Joint controller vs independent controllers
Two companies sharing personal data are not automatically joint controllers. They may be independent controllers where each separately determines its own purpose and essential means.
Example: a retailer sends shipping information to an independent carrier. Depending on the actual facts, the carrier may process some information for its own regulatory and transport purposes rather than merely following the retailer's instructions. That can produce separate-controller analysis instead of a classic controller-operator relationship.
Role classification should therefore be based on the real decisions made by each party, not a generic rule that every supplier is an operator.
What Is a Suboperator?
The LGPD itself does not expressly define the term suboperator. ANPD uses it as a practical concept for complex processing chains.
A suboperator is a party hired by the operator to assist it in processing personal data on behalf of the controller. Its direct contractual relationship is normally with the operator rather than the controller.
Typical chain
Controller → Operator → Suboperator
ANPD recommends that the operator obtain formal authorization from the controller before engaging a suboperator. The authorization may be specific or general and can be included in the controller-operator contract.
What should a subprocessor clause address?
A practical clause should address:
- whether authorization is specific or general;
- how new subprocessors are notified;
- which processing they perform;
- security requirements;
- confidentiality;
- data-subject-rights support;
- incident escalation;
- retention/deletion;
- international-transfer requirements; and
- how downstream obligations are imposed contractually.
For international transfers, Resolution 19/2024 also contains its own “subcontracted party” concept within the Brazilian SCC framework. That transfer-specific term should not be casually treated as identical to every domestic suboperator scenario without examining the applicable instrument.
Practical Business Examples
1. SaaS platform
A Brazilian retailer uses a U.S. CRM SaaS to store customer names, email addresses and support history. The retailer determines why those customer records exist and how they will be used for its customer relationship. The SaaS follows those instructions.
Likely starting point: retailer = controller; SaaS = operator for the hosted customer data.
If the SaaS separately uses account-admin contact details to manage its own billing, fraud controls or legal compliance, it may act as controller for those separate activities.
2. Cloud infrastructure provider
A software company hosts its database with a cloud provider. The software company defines the product purpose, customer data and retention. The cloud provider chooses technical infrastructure, redundancy and security implementation.
Likely starting point: software company = controller or operator depending on its customer relationship; cloud provider = operator/suboperator for the hosted processing.
The cloud provider does not become controller merely because it chooses technical equipment or security mechanisms.
3. Payroll provider
An employer sends employee payroll data to an outsourced payroll company that calculates payroll according to the employer's instructions.
Likely starting point: employer = controller; payroll vendor = operator for payroll execution.
If the payroll provider has separate legal obligations involving records it must independently maintain, those separate activities may require a different role analysis.
4. Marketing agency
A company gives an agency a customer list and detailed campaign instructions. The agency configures ad platforms and creative execution for the company's campaign.
Possible structure: company = controller; agency = operator for the directed campaign.
But if the agency takes that list and independently builds its own cross-client audience product, that independent reuse can move the agency into a controller role for that new purpose.
5. Analytics platform
A website sends user events to an analytics vendor. Whether the vendor is only an operator depends on what it does with the events.
If it processes solely to provide customer-directed analytics, operator status can fit. If it independently combines data across customers for its own advertising or profiling purposes, controller analysis becomes relevant for that separate use.
6. Payment provider
A merchant transmits payment information to a payment service. It is unsafe to assume every payment provider is simply an operator.
Payment companies may have independent anti-fraud, regulatory, anti-money-laundering, accounting or network obligations. The actual role can differ by processing purpose.
7. Recruiting agency
If an employer instructs a recruiter to source candidates under tightly defined criteria and process applications for the employer's hiring purpose, an operator relationship may exist for some activities.
If the recruiter independently maintains a candidate database for its own future placements across clients, it may be controller for that separate database.
8. AI service provider
A company sends customer-support tickets to an AI provider only to generate summaries. If the AI provider processes strictly under instructions and does not reuse the data for its own model development, operator analysis can fit.
If the provider independently uses prompts or outputs for model training, benchmarking or other product-development purposes, that separate purpose must be classified independently.
Does the LGPD Require a DPA?
The LGPD does not contain a GDPR Article 28-style provision saying that every controller-operator relationship must have a contract with a fixed statutory field list.
ANPD nevertheless treats a written contract as a good practice. Its guidance explains that contractual clauses can limit the operator's actions, objectively allocate responsibilities and reduce uncertainty.
ANPD identifies useful contract topics including:
- object of processing;
- duration;
- nature of processing;
- purpose;
- types of personal data;
- rights and obligations; and
- responsibilities related to LGPD compliance.
A practical LGPD DPA should usually go further
| DPA topic | Why it matters |
|---|---|
| Role and processing scope | Documents the purpose and activities for which the vendor acts as operator. |
| Lawful instructions | Connects Article 39 to an operational instruction mechanism. |
| Confidentiality | Controls personnel and authorized access. |
| Security measures | Connects vendor obligations to Article 46. |
| Suboperators | Documents authorization, notification and downstream obligations. |
| Rights support | Ensures the operator can help locate, export, correct, block or delete data as needed. |
| Incident escalation | Operator notification must be fast enough for the controller's regulatory deadline. |
| International transfers | Identifies countries and Article 33 mechanisms where relevant. |
| Retention/deletion | Defines what happens during service, at termination and in backups. |
| Audit/evidence | Provides a practical way to verify compliance with instructions and agreed safeguards. |
How the Role Changes Operational Obligations
| Compliance area | Controller | Operator |
|---|---|---|
| Purpose & legal basis | Determines essential purpose and basis for controller-directed processing. | Follows lawful instructions; separately analyzes any independent controller purpose. |
| Article 37 records / ROPA | Must maintain processing records. | Also expressly subject to Article 37 recordkeeping. |
| Data-subject rights | Primary responsibility for handling controller obligations and responses. | Should assist the controller and avoid acting outside instructions. |
| Security | Article 46 applies. | Article 46 also applies to processing agents, including operators. |
| Incident communication | Assesses reportability and makes required ANPD/data-subject communication. | Must inform controller without unjustified delay under Resolution 15/2024. |
| Encarregado / DPO | Controller generally must appoint, subject to applicable exemptions. | Appointment is optional under the current encarregado regulation and is treated as a good-practice measure. |
| Suboperators | Should govern authorization and expectations. | Should obtain formal controller authorization as recommended by ANPD. |
| International transfers | Must ensure applicable transfer architecture where responsible. | Must support information and comply with transfer instructions/mechanisms. |
ROPA applies to both
Article 37 expressly requires both controllers and operators to maintain records of processing operations, especially where legitimate interest is used.
An operator's ROPA should not be a copy of the controller's register. It should reflect the systems, suboperators, locations, access, retention and processing the operator actually performs.
See LGPD ROPA: How to Build a Record of Processing Activities.
Incident responsibilities are different
Under Resolution 15/2024, the controller is responsible for external communication to ANPD and affected data subjects when the reportability threshold is met. The operator must notify the controller without unjustified delay and provide the information needed for assessment.
This is why incident clauses should require vendor escalation well before the controller's external three-business-day deadline.
See LGPD Data Breach Notification.
DPO / encarregado treatment also differs
Current ANPD guidance under the encarregado regulation says controller appointment is generally mandatory, while operator appointment is optional and can be treated as a good practice, subject to applicable small-agent exemptions and other specific rules.
See Does Your Company Need an LGPD DPO?.
Controller and Operator Liability
Role classification matters because liability is not identical.
Article 42 provides that an operator can be jointly liable for damage caused by processing when it fails to comply with data-protection legislation or fails to follow the controller's lawful instructions, subject to the statutory exclusions in Article 43.
Article 42 also provides joint liability among controllers directly involved in processing that causes damage, again subject to Article 43.
What if the operator acts outside instructions?
If a vendor takes customer data and uses it for an independently chosen purpose, that conduct can change the role analysis for that processing. ANPD guidance treats a party that exercises essential decision-making power as controller for the relevant activity.
The compliance response should therefore do more than say: “the processor breached the DPA.” It should assess whether the vendor has become a controller for the unauthorized purpose and what separate transparency, legal-basis, rights, retention and liability consequences follow.
A Five-Question Role Classification Test
Who decided why the data is processed?
The party that defines the purpose is usually acting as controller for that purpose.
Who decides the essential elements?
Look at data categories, duration, key purposes, legal basis and other material processing decisions.
Is the other party acting on documented instructions?
Instruction-following supports operator status; independent incompatible purposes point away from it.
Are its decisions merely technical/non-essential?
Choosing software, infrastructure or detailed security controls can remain compatible with operator status.
Do two parties jointly determine purpose and essential elements?
If yes, assess joint controllership rather than trying to force one party into an operator label.
Common Controller / Operator Mistakes
“Every vendor is an operator.”
Incorrect. Some vendors independently determine their own purposes and can be separate controllers for those activities.
“If the vendor chooses technology, it is a controller.”
Incorrect. ANPD allows operators to make non-essential technical decisions such as software/equipment selection and detailed security implementation.
“Our employee is our operator.”
Usually incorrect where the employee acts as part of and under the authority of the legal entity.
“The DPA decides the role.”
No. The DPA documents and governs the relationship, but factual decision-making power determines classification.
“Joint controller means two companies touched the same data.”
Too broad. ANPD looks for joint/common/convergent determination of purpose and essential elements plus mutual interests and decision-making power.
“Operator means no liability.”
Incorrect. Operators have direct duties and can face joint liability in the situations described by Article 42.
“Subprocessors are the vendor's problem.”
Too simplistic. ANPD recommends formal controller authorization for suboperator engagement, and downstream processing should be contractually and operationally governed.
20-Point Controller vs Operator Review
Turn Role Classification Into a Documented Vendor Process
The Brazil LGPD Compliance Playbook — 2026 Edition includes a Vendor Privacy and Security Review, Data Processing Agreement Checklist, Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, International Transfer Review, Retention Schedule, Security Incident Assessment, 100-point compliance audit and 30-day implementation roadmap.
Frequently Asked Questions
What is the difference between controller and operator under LGPD?
The controller has authority over the essential decisions of the processing, especially its purpose. The operator processes on behalf of the controller and follows its lawful instructions while it may decide non-essential technical details.
Can the same company be both controller and operator?
Yes. ANPD says classification is made for each processing operation. One organization can be controller for its own billing data and operator for customer data processed on a client's behalf.
Are employees operators?
Normally not when they act within and under the authority of the legal entity. In that context, ANPD generally treats the organization as the processing agent. A natural person can separately be a controller or operator when acting independently in the relevant capacity.
Can an operator choose the software and security controls?
Yes. ANPD recognizes that an operator can make non-essential technical decisions, including choosing software/equipment and detailing prevention/security measures, without automatically becoming controller.
Does the LGPD require a DPA?
The LGPD does not contain a GDPR Article 28-style universal contractual provision. ANPD nevertheless recommends a written controller-operator contract as good practice to define scope, duration, nature, purpose, data types, rights, obligations and responsibilities.
What is a joint controller under LGPD?
ANPD recognizes joint controllership where two or more controllers jointly, commonly or convergently determine purposes and essential processing elements through an arrangement allocating their LGPD responsibilities.
What is a suboperator?
It is an ANPD guidance concept for a party hired by the operator to assist with processing on behalf of the controller. ANPD recommends formal controller authorization, general or specific, for the operator to engage one.
Can an operator become a controller?
For a specific activity, yes. If it determines an independent purpose or other essential elements instead of acting on the controller's instructions, its role can change for that processing.
Do operators need an LGPD ROPA?
Yes. Article 37 expressly requires both controllers and operators to maintain records of processing operations, especially for legitimate-interest processing.
Who reports a data breach to ANPD?
Under Resolution 15/2024, the controller makes the required external communication when the reportability threshold is met. The operator must inform the controller without unjustified delay and provide the information needed for assessment.
Does an operator need an encarregado / DPO?
Under the current ANPD encarregado framework, appointment by the operator is optional and can be treated as a good-practice measure. Controller appointment is generally required, subject to applicable exemptions such as rules for qualifying small processing agents.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary statutory source for controller/operator definitions, Articles 37, 39, 42–43, 46 and related duties.
- ANPD — Guide to Processing Agents and the Encarregado, Version 2.0 Primary ANPD guidance for role-per-operation analysis, essential vs non-essential decisions, employees, joint controllers, operator contracts and suboperators.
- ANPD — Data Protection and Privacy Glossary Current official definitions for controller, operator, joint controllership and suboperator terminology.
- ANPD — Security Incident Communication Current controller/operator incident responsibilities under Resolution 15/2024, including operator escalation without unjustified delay.
- ANPD — Guide on the Role of the Encarregado Current guidance confirming role-by-operation classification and the distinction between controller and operator encarregado appointment duties.
- ANPD Resolution No. 19/2024 — International Transfers Current transfer framework and Brazilian SCC architecture, including controller/operator selections and downstream processing concepts.