2026 Edition · Sources checked August 20, 2026 · Independent educational resource · Not legal advice
LGPD Compliance & Implementation

Controller vs Operator Under LGPD: A Practical Business Guide

“Controller” and “operator” are not permanent labels attached to a company. Under ANPD guidance, the role must be assessed for each processing operation. A SaaS provider can be an operator for customer-hosted account data and a controller for its own billing records. A marketing agency can act on instructions for one campaign and become a controller for a separate purpose it decides itself. This guide shows how to classify roles using actual decision-making power—not contract titles—and how that classification affects DPAs, subprocessors, ROPA, rights, incidents and liability.

Published: August 20, 2026 Last reviewed: August 20, 2026 Reading time: ~24 minutes By LGPD Brazil Editorial Team

Quick Answer: What is the difference between a controller and an operator under the LGPD?

Under Article 5 of Brazil's LGPD, the controller is the natural person or legal entity that has decision-making authority over personal-data processing, while the operator processes personal data on behalf of the controller. ANPD's current guidance makes the practical distinction clearer: the controller determines the purpose and other essential elements of the processing, whereas the operator follows the controller's lawful instructions and may decide non-essential technical or operational details. The role is assessed per processing operation, so the same company can be a controller in one context and an operator in another. The contract label is evidence, but the actual facts and decision-making power determine the role.

Key Takeaways

  • Controller = essential decision-maker. Purpose is always a central controller decision.
  • Operator = acts on behalf of the controller. It can make non-essential technical decisions without becoming a controller automatically.
  • Roles are processing-specific. The same vendor can be an operator for one purpose and a controller for another.
  • Employees are not normally separate operators of their employer. The legal entity is generally the processing agent when staff act under its authority.
  • Joint controllership can exist under LGPD. ANPD recognizes it where two or more controllers jointly, commonly or convergently determine purposes and essential elements.
  • Suboperator is an ANPD guidance concept, not an express LGPD definition. Formal controller authorization is recommended.
  • A DPA does not create the role by itself. It should document and govern the role that actually exists.

The Legal Definitions

Article 5(VI) Controller

A natural person or legal entity, public or private, with decision-making authority regarding the processing of personal data.

Article 5(VII) Operator

A natural person or legal entity, public or private, that processes personal data on behalf of the controller.

Article 5(IX) Processing agents

The collective statutory category that includes controllers and operators.

Article 39 adds the central operator rule: the operator must process personal data according to the controller's instructions, while the controller verifies compliance with its instructions and applicable rules.

The practical test

Ask who determines why the processing happens and who controls the essential elements needed to achieve that purpose. That party is usually acting as controller for the operation. A party that carries out the processing for that purpose under another party's instructions is usually acting as operator.

Roles Are Defined Per Processing Operation

This is probably the most important point in ANPD's guidance. The Agency says processing-agent status should be assessed for each personal-data processing operation.

The same organization can therefore be:

One company, different roles

Customer account data hosted for a client → Operator · Vendor's own billing records → Controller · Employee payroll → Controller · Customer-directed analytics service → Potential Operator · Vendor's independent product analytics → Potential Controller

This is why a global statement such as: “Vendor X is our processor” can be incomplete.

A better record says:

“Vendor X acts as operator for Activity A and as controller for Activity B.”

Contract labels are not conclusive

A contract can help demonstrate the intended relationship and establish instructions, but calling a company “processor,” “service provider” or “operator” does not override what the company actually does.

If a party independently decides to use the data for a new purpose, it may become a controller for that separate processing even if the contract still calls it an operator.

Role classification follows facts, not branding. “We wrote processor in the DPA” is not a defense if the vendor independently determines an incompatible new purpose.

Which Decisions Belong to the Controller?

ANPD distinguishes between essential and non-essential processing decisions. The controller does not need to make every technical choice. It must, however, retain influence over the essential elements.

Decision Usually controller or operator? Why
Purpose of processingControllerThe controller determines the objective that justifies processing.
Legal basis for the controller's purposeControllerANPD treats purpose and legal basis as essential controller decisions.
Nature/categories of personal dataController / essentialChoosing which type of personal data is necessary materially shapes the processing.
Duration / deletion periodController / essentialANPD identifies processing duration as an essential element.
Choice of software or equipmentCan be operatorANPD gives these as examples of non-essential technical decisions.
Detailed security implementationCan be operatorThe operator can choose technical prevention/security details while still following the controller's required outcome.
Independent new purposeController for that purposeA vendor that determines a new essential purpose is no longer acting only on behalf of the original controller for that use.
Technical autonomy does not automatically make a vendor a controller. A cloud provider can choose server architecture, software, security tooling and operational methods while remaining an operator if those choices are non-essential and it continues processing on behalf of the controller's defined purpose.

Who determines the legal basis?

For controller-directed processing, the controller should determine and document the legal basis for its purpose. The operator should understand the instructions and avoid using the data outside that framework.

If the operator separately processes data for its own independent purpose, it needs its own controller analysis, including purpose, legal basis, transparency, retention and rights obligations for that separate processing.

Are Employees Operators?

Usually not when they act as part of the legal entity and under its authority. ANPD explains that, in the context of a legal entity, the organization itself is generally the processing agent because it establishes the processing rules that representatives, employees or agents execute.

Employees, administrators, partners, public servants and other people whose actions express the organization's activity should not normally be classified as separate operators merely because they touch personal data.

This does not mean a natural person can never be a controller or operator. ANPD recognizes that natural persons can be processing agents when they act independently in the relevant capacity rather than simply as a subordinate member of an organization.

What Is Joint Controllership Under the LGPD?

The LGPD does not expressly define “joint controller.” ANPD nevertheless considers joint controllership implicitly recognized in the Brazilian framework, including through Article 42's liability structure.

ANPD defines joint controllership as the joint, common or convergent determination by two or more controllers of the purposes and essential elements of personal-data processing, through an arrangement that establishes their respective LGPD responsibilities.

ANPD's three practical criteria

More than one party has decision-making powerThe essential processing decisions are not controlled by only one organization.
The parties have mutual interests based on their own purposesThey are not merely serving one party's purpose under instructions.
They make common or convergent decisionsThose decisions concern the purposes and essential elements of the same processing operation.

Joint controller vs independent controllers

Two companies sharing personal data are not automatically joint controllers. They may be independent controllers where each separately determines its own purpose and essential means.

Example: a retailer sends shipping information to an independent carrier. Depending on the actual facts, the carrier may process some information for its own regulatory and transport purposes rather than merely following the retailer's instructions. That can produce separate-controller analysis instead of a classic controller-operator relationship.

Role classification should therefore be based on the real decisions made by each party, not a generic rule that every supplier is an operator.

What Is a Suboperator?

The LGPD itself does not expressly define the term suboperator. ANPD uses it as a practical concept for complex processing chains.

A suboperator is a party hired by the operator to assist it in processing personal data on behalf of the controller. Its direct contractual relationship is normally with the operator rather than the controller.

Typical chain

Controller → Operator → Suboperator

ANPD recommends that the operator obtain formal authorization from the controller before engaging a suboperator. The authorization may be specific or general and can be included in the controller-operator contract.

What should a subprocessor clause address?

A practical clause should address:

  • whether authorization is specific or general;
  • how new subprocessors are notified;
  • which processing they perform;
  • security requirements;
  • confidentiality;
  • data-subject-rights support;
  • incident escalation;
  • retention/deletion;
  • international-transfer requirements; and
  • how downstream obligations are imposed contractually.

For international transfers, Resolution 19/2024 also contains its own “subcontracted party” concept within the Brazilian SCC framework. That transfer-specific term should not be casually treated as identical to every domestic suboperator scenario without examining the applicable instrument.

Practical Business Examples

1. SaaS platform

A Brazilian retailer uses a U.S. CRM SaaS to store customer names, email addresses and support history. The retailer determines why those customer records exist and how they will be used for its customer relationship. The SaaS follows those instructions.

Likely starting point: retailer = controller; SaaS = operator for the hosted customer data.

If the SaaS separately uses account-admin contact details to manage its own billing, fraud controls or legal compliance, it may act as controller for those separate activities.

2. Cloud infrastructure provider

A software company hosts its database with a cloud provider. The software company defines the product purpose, customer data and retention. The cloud provider chooses technical infrastructure, redundancy and security implementation.

Likely starting point: software company = controller or operator depending on its customer relationship; cloud provider = operator/suboperator for the hosted processing.

The cloud provider does not become controller merely because it chooses technical equipment or security mechanisms.

3. Payroll provider

An employer sends employee payroll data to an outsourced payroll company that calculates payroll according to the employer's instructions.

Likely starting point: employer = controller; payroll vendor = operator for payroll execution.

If the payroll provider has separate legal obligations involving records it must independently maintain, those separate activities may require a different role analysis.

4. Marketing agency

A company gives an agency a customer list and detailed campaign instructions. The agency configures ad platforms and creative execution for the company's campaign.

Possible structure: company = controller; agency = operator for the directed campaign.

But if the agency takes that list and independently builds its own cross-client audience product, that independent reuse can move the agency into a controller role for that new purpose.

5. Analytics platform

A website sends user events to an analytics vendor. Whether the vendor is only an operator depends on what it does with the events.

If it processes solely to provide customer-directed analytics, operator status can fit. If it independently combines data across customers for its own advertising or profiling purposes, controller analysis becomes relevant for that separate use.

6. Payment provider

A merchant transmits payment information to a payment service. It is unsafe to assume every payment provider is simply an operator.

Payment companies may have independent anti-fraud, regulatory, anti-money-laundering, accounting or network obligations. The actual role can differ by processing purpose.

7. Recruiting agency

If an employer instructs a recruiter to source candidates under tightly defined criteria and process applications for the employer's hiring purpose, an operator relationship may exist for some activities.

If the recruiter independently maintains a candidate database for its own future placements across clients, it may be controller for that separate database.

8. AI service provider

A company sends customer-support tickets to an AI provider only to generate summaries. If the AI provider processes strictly under instructions and does not reuse the data for its own model development, operator analysis can fit.

If the provider independently uses prompts or outputs for model training, benchmarking or other product-development purposes, that separate purpose must be classified independently.

For AI vendors, “no training on customer data” is not just a security question. It can be central to whether the provider stays within a controller-directed operator role for the relevant processing.

Does the LGPD Require a DPA?

The LGPD does not contain a GDPR Article 28-style provision saying that every controller-operator relationship must have a contract with a fixed statutory field list.

ANPD nevertheless treats a written contract as a good practice. Its guidance explains that contractual clauses can limit the operator's actions, objectively allocate responsibilities and reduce uncertainty.

ANPD identifies useful contract topics including:

  • object of processing;
  • duration;
  • nature of processing;
  • purpose;
  • types of personal data;
  • rights and obligations; and
  • responsibilities related to LGPD compliance.

A practical LGPD DPA should usually go further

DPA topic Why it matters
Role and processing scopeDocuments the purpose and activities for which the vendor acts as operator.
Lawful instructionsConnects Article 39 to an operational instruction mechanism.
ConfidentialityControls personnel and authorized access.
Security measuresConnects vendor obligations to Article 46.
SuboperatorsDocuments authorization, notification and downstream obligations.
Rights supportEnsures the operator can help locate, export, correct, block or delete data as needed.
Incident escalationOperator notification must be fast enough for the controller's regulatory deadline.
International transfersIdentifies countries and Article 33 mechanisms where relevant.
Retention/deletionDefines what happens during service, at termination and in backups.
Audit/evidenceProvides a practical way to verify compliance with instructions and agreed safeguards.
A DPA cannot lawfully rewrite reality. If a vendor is an independent controller for a particular purpose, forcing the word “operator” into the contract does not make its independent purpose disappear.

How the Role Changes Operational Obligations

Compliance area Controller Operator
Purpose & legal basisDetermines essential purpose and basis for controller-directed processing.Follows lawful instructions; separately analyzes any independent controller purpose.
Article 37 records / ROPAMust maintain processing records.Also expressly subject to Article 37 recordkeeping.
Data-subject rightsPrimary responsibility for handling controller obligations and responses.Should assist the controller and avoid acting outside instructions.
SecurityArticle 46 applies.Article 46 also applies to processing agents, including operators.
Incident communicationAssesses reportability and makes required ANPD/data-subject communication.Must inform controller without unjustified delay under Resolution 15/2024.
Encarregado / DPOController generally must appoint, subject to applicable exemptions.Appointment is optional under the current encarregado regulation and is treated as a good-practice measure.
SuboperatorsShould govern authorization and expectations.Should obtain formal controller authorization as recommended by ANPD.
International transfersMust ensure applicable transfer architecture where responsible.Must support information and comply with transfer instructions/mechanisms.

ROPA applies to both

Article 37 expressly requires both controllers and operators to maintain records of processing operations, especially where legitimate interest is used.

An operator's ROPA should not be a copy of the controller's register. It should reflect the systems, suboperators, locations, access, retention and processing the operator actually performs.

See LGPD ROPA: How to Build a Record of Processing Activities.

Incident responsibilities are different

Under Resolution 15/2024, the controller is responsible for external communication to ANPD and affected data subjects when the reportability threshold is met. The operator must notify the controller without unjustified delay and provide the information needed for assessment.

This is why incident clauses should require vendor escalation well before the controller's external three-business-day deadline.

See LGPD Data Breach Notification.

DPO / encarregado treatment also differs

Current ANPD guidance under the encarregado regulation says controller appointment is generally mandatory, while operator appointment is optional and can be treated as a good practice, subject to applicable small-agent exemptions and other specific rules.

See Does Your Company Need an LGPD DPO?.

Controller and Operator Liability

Role classification matters because liability is not identical.

Article 42 provides that an operator can be jointly liable for damage caused by processing when it fails to comply with data-protection legislation or fails to follow the controller's lawful instructions, subject to the statutory exclusions in Article 43.

Article 42 also provides joint liability among controllers directly involved in processing that causes damage, again subject to Article 43.

Operator does not mean “no responsibility.” Operators have direct LGPD duties, including Article 37 records, Article 39 instruction compliance and Article 46 security, and can face liability when statutory conditions are met.

What if the operator acts outside instructions?

If a vendor takes customer data and uses it for an independently chosen purpose, that conduct can change the role analysis for that processing. ANPD guidance treats a party that exercises essential decision-making power as controller for the relevant activity.

The compliance response should therefore do more than say: “the processor breached the DPA.” It should assess whether the vendor has become a controller for the unauthorized purpose and what separate transparency, legal-basis, rights, retention and liability consequences follow.

A Five-Question Role Classification Test

1

Who decided why the data is processed?

The party that defines the purpose is usually acting as controller for that purpose.

2

Who decides the essential elements?

Look at data categories, duration, key purposes, legal basis and other material processing decisions.

3

Is the other party acting on documented instructions?

Instruction-following supports operator status; independent incompatible purposes point away from it.

4

Are its decisions merely technical/non-essential?

Choosing software, infrastructure or detailed security controls can remain compatible with operator status.

5

Do two parties jointly determine purpose and essential elements?

If yes, assess joint controllership rather than trying to force one party into an operator label.

Common Controller / Operator Mistakes

“Every vendor is an operator.”

Incorrect. Some vendors independently determine their own purposes and can be separate controllers for those activities.

“If the vendor chooses technology, it is a controller.”

Incorrect. ANPD allows operators to make non-essential technical decisions such as software/equipment selection and detailed security implementation.

“Our employee is our operator.”

Usually incorrect where the employee acts as part of and under the authority of the legal entity.

“The DPA decides the role.”

No. The DPA documents and governs the relationship, but factual decision-making power determines classification.

“Joint controller means two companies touched the same data.”

Too broad. ANPD looks for joint/common/convergent determination of purpose and essential elements plus mutual interests and decision-making power.

“Operator means no liability.”

Incorrect. Operators have direct duties and can face joint liability in the situations described by Article 42.

“Subprocessors are the vendor's problem.”

Too simplistic. ANPD recommends formal controller authorization for suboperator engagement, and downstream processing should be contractually and operationally governed.

20-Point Controller vs Operator Review

1. Classify per processing activityNever assign one global role without testing each purpose.
2. Identify who defines the purposePurpose is a core controller decision.
3. Identify who selects the legal basisController-directed processing should have a controller basis record.
4. Identify essential data decisionsWhich categories and duration are materially controlled by whom?
5. Separate technical decisionsDo not misclassify a vendor solely because it chooses infrastructure.
6. Check for independent purposesBilling, fraud, analytics, AI training or advertising can create separate controller roles.
7. Check for joint controlCommon purpose + mutual interest + shared essential decisions.
8. Do not classify employees as vendorsInternal staff generally act through the legal entity.
9. Document the role in the ROPAController/operator status should be visible per activity.
10. Use a written DPA where operator processing existsANPD treats contractual allocation as good practice.
11. Document lawful instructionsPurpose, scope and permitted processing should be clear.
12. Govern suboperatorsAuthorization, notice, security, deletion and downstream obligations.
13. Review vendor securityArticle 46 applies to processing agents.
14. Set incident escalationOperator notification must occur without unjustified delay.
15. Map rights supportCan the operator search, export, correct or delete when instructed?
16. Map retentionOperator and suboperator copies must follow the lifecycle.
17. Map international transfersRole classification carries into transfer contracts and SCC options.
18. Review DPO / encarregado obligationsController and operator rules differ under the current regulation.
19. Review liability exposureUnderstand Article 42 and the effect of acting outside lawful instructions.
20. Reclassify when the product changesNew AI, analytics, advertising or data reuse can change the role.

Turn Role Classification Into a Documented Vendor Process

The Brazil LGPD Compliance Playbook — 2026 Edition includes a Vendor Privacy and Security Review, Data Processing Agreement Checklist, Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, International Transfer Review, Retention Schedule, Security Incident Assessment, 100-point compliance audit and 30-day implementation roadmap.

Vendor Review DPA Checklist Processing Inventory / ROPA International Transfer Review
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What is the difference between controller and operator under LGPD?

The controller has authority over the essential decisions of the processing, especially its purpose. The operator processes on behalf of the controller and follows its lawful instructions while it may decide non-essential technical details.

Can the same company be both controller and operator?

Yes. ANPD says classification is made for each processing operation. One organization can be controller for its own billing data and operator for customer data processed on a client's behalf.

Are employees operators?

Normally not when they act within and under the authority of the legal entity. In that context, ANPD generally treats the organization as the processing agent. A natural person can separately be a controller or operator when acting independently in the relevant capacity.

Can an operator choose the software and security controls?

Yes. ANPD recognizes that an operator can make non-essential technical decisions, including choosing software/equipment and detailing prevention/security measures, without automatically becoming controller.

Does the LGPD require a DPA?

The LGPD does not contain a GDPR Article 28-style universal contractual provision. ANPD nevertheless recommends a written controller-operator contract as good practice to define scope, duration, nature, purpose, data types, rights, obligations and responsibilities.

What is a joint controller under LGPD?

ANPD recognizes joint controllership where two or more controllers jointly, commonly or convergently determine purposes and essential processing elements through an arrangement allocating their LGPD responsibilities.

What is a suboperator?

It is an ANPD guidance concept for a party hired by the operator to assist with processing on behalf of the controller. ANPD recommends formal controller authorization, general or specific, for the operator to engage one.

Can an operator become a controller?

For a specific activity, yes. If it determines an independent purpose or other essential elements instead of acting on the controller's instructions, its role can change for that processing.

Do operators need an LGPD ROPA?

Yes. Article 37 expressly requires both controllers and operators to maintain records of processing operations, especially for legitimate-interest processing.

Who reports a data breach to ANPD?

Under Resolution 15/2024, the controller makes the required external communication when the reportability threshold is met. The operator must inform the controller without unjustified delay and provide the information needed for assessment.

Does an operator need an encarregado / DPO?

Under the current ANPD encarregado framework, appointment by the operator is optional and can be treated as a good-practice measure. Controller appointment is generally required, subject to applicable exemptions such as rules for qualifying small processing agents.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 20, 2026. ANPD's Guide to Processing Agents is non-binding guidance, but it is the Agency's primary interpretive resource for distinguishing controllers, operators, joint controllers and suboperators. Role classification is fact-specific and must be performed for each processing operation. Examples in this article are analytical starting points, not automatic legal classifications: actual contracts, purposes, legal obligations, technical architecture, independent uses and decision-making power can change the result.