A conditional privacy-role decision schedule is a bid record for a service whose final processing design is still open. It divides the offer into processing activities and design branches. For each branch, it records the purpose, the facts about who decides the purpose and essential means, the proposed role of every party, contractual and operational consequences, evidence, the decision still required, its owner and the exact wording permitted in the response. The schedule does not decide the legal role. It gives the authorized privacy or legal reviewer enough facts to decide it before the relevant commitment takes effect.
The fictional Northborough Skills Agency is procuring a service for apprenticeship applications and placements. The buyer has not decided whether it will define every matching rule, let the supplier tune a recommendation feature, commission cross-programme outcome analysis or permit product improvement with identifiable applicant data. The questionnaire still asks for one answer: “Will the supplier act solely as our processor?” A flat yes could become false under one design branch. A flat no could misdescribe the core case-management service. Repeating “to be agreed” gives the evaluator no design, safeguard or accountable next step to assess.
Answer at processing-activity level and make the unresolved design visible. Start with why each activity occurs and who decides the essential features of that processing. Treat controller, joint-controller and processor descriptions as reasoned hypotheses until an authorized reviewer confirms them under the applicable law. Then show what each branch changes: instructions, transparency, contract terms, rights handling, records, risk assessment, subprocessor oversight and evidence. Commit only to a branch the offer can deliver or to a controlled decision gate that the procurement permits.
Scope
Freeze the question before classifying the parties
A privacy role is not an attribute of a company in the abstract. It belongs to identified processing. Begin with the current invitation, questionnaire, draft contract, definitions, clarifications and evaluation method. Record whether the buyer wants a legal characterization, a proposed operating model, an Article 28 schedule, a description of safeguards or all four. Fix the jurisdiction and the date at which the answer must be true. A statement due at bid submission can differ from a configuration that must exist before live data enters the service.
Define the offer next. Northborough is a fictional authority, and its facts are illustrative. Its proposed service has applicant intake, eligibility review, placement matching, messaging, user administration, support and optional outcome reporting. The bidder has several service editions and cannot answer from a group privacy policy. The record must name the contracting entity, operating entities, selected functions, buyer-controlled settings, integrations, providers and material data flows.
The procurement rule still matters. Current UK guidance says award criteria and the assessment method must be sufficiently clear, measurable, specific and tied to the contract. Mirror the requested answer form and expose the evidence the evaluator can assess. Do not turn a legal caveat into an empty response. State what is known, which design branch changes the answer and who closes it.
| Field | Recorded position | Why it controls the answer |
|---|---|---|
| Buyer proposition | Supplier acts solely as processor for all service processing | A compound absolute statement must be tested activity by activity |
| Truth event | Proposed position at final tender, confirmed before configuration approval | Prevents a proposal from being read as current operation |
| Open options | Matching control, cross-programme analysis and improvement-data use | Each option can alter purpose or decisive means |
| Legal frame | UK data-protection law, with current regulator guidance checked at approval | The ICO marks its detailed role guidance as under review after statutory change |
| Authority | Buyer and supplier privacy counsel approve their positions; product owners confirm facts | The proposal writer does not make the legal determination |
Activity model
A product boundary is too coarse for a role decision
Split the service when the reason for using personal data changes. Northborough processes applications to administer a public programme. The supplier may process those applications on documented instructions. Supplier account administration protects access to the service. Support diagnosis may use a bounded copy to resolve a ticket. Cross-programme analysis may serve the buyer, several commissioning bodies or the supplier. These are not one purpose merely because the same platform touches them.
For each activity, describe the affected people, data categories, source, operations, recipients, duration and disposal. Then record who decides why it happens. Capture the decisions about essential means: which people and data are in scope, what material operations occur, who receives data and how long identifiable records are needed. Record practical implementation choices separately. The EDPB explains that a processor can decide non-essential means, such as specific technical implementation, while purposes and essential means remain decisive for the controller analysis.
One party can hold different roles for different activities. A supplier could be proposed as processor for buyer-directed case handling while acting in another capacity for its own account-security records. That possibility is neither an admission nor a conclusion. It is a reason to avoid the word “solely” until each material activity has been assessed.
| Field | Question to answer | Boundary test |
|---|---|---|
| Purpose | Why does this processing occur? | Create another row when the objective changes |
| People and data | Whose data and which categories are necessary? | Separate optional populations or materially different data |
| Operations and recipients | What happens, and who receives the result? | Split a new disclosure or materially different operation |
| Decision authority | Who determines the purpose and essential means? | Record facts, not the title in the draft contract |
| Implementation discretion | Which practical choices can the supplier make inside instructions? | Do not mistake engineering discretion for a new purpose |
| Lifecycle | When does processing start, change and end? | Include support copies, exports and restored data where applicable |
Role branches
Write a role hypothesis that another reviewer can disprove
A useful role row contains a proposed classification and the facts on which it depends. “Supplier is processor” is incomplete. A reviewable position says that the buyer determines the apprenticeship-case purpose, applicant categories, mandatory fields, eligibility logic, authorized recipients and retention; the supplier performs named operations under documented instructions and chooses bounded implementation details. It also states which fact would defeat the position, such as a supplier-determined secondary purpose for identifiable applications.
Joint control needs its own analysis. Cooperation, a shared database or a contract does not settle it. The EDPB asks whether parties make common decisions or separate decisions that converge so the processing would not occur in the same way without both. If that hypothesis is confirmed, the schedule must lead to an allocation of responsibilities, an accessible account of the arrangement and working rights routes. It must not imply that every responsibility is equal or that one arrangement covers separate activities automatically.
Do not negotiate the label before understanding the function. Article 28 contracts matter when one party processes on behalf of another, but the contract must describe the real processing. Under the GDPR, a processor that determines purposes and means contrary to the regulation is treated as controller for that processing. The schedule therefore precedes the contract schedule and feeds it; a heading in the contract cannot repair contradictory product behavior.
| Activity and branch | Decisive facts | Working position | Consequence before release |
|---|---|---|---|
| Placement matching A: buyer fixes rules | Buyer selects objective, inputs, exclusions, recipients and retention; supplier applies the configured rules | Buyer controller and supplier processor hypothesis | Put instructions and assistance in the processing schedule; verify configuration evidence |
| Placement matching B: supplier defines a reusable objective | Supplier selects outcome target and material inputs for use beyond the buyer instruction | Supplier controller or joint-controller review required for that activity | Do not offer blanket processor wording; assess basis, transparency, rights and arrangement |
| Outcome report A: buyer-only statistics | Buyer defines questions and recipients; supplier calculates within instructions | Processor hypothesis while identifiable data remain involved | Define fields, aggregation threshold, access, retention and deletion |
| Outcome report B: supplier product comparison | Supplier chooses a separate improvement purpose and wants to reuse customer data | Separate controller analysis; processor instructions are not enough | Require written decision, compatibility and lawful-basis review, notice, minimisation and opt-out or exclusion design as applicable |
| Account security | Supplier determines security-monitoring purpose and bounded telemetry for its service accounts | Separate supplier-role review | Document purpose, data, duration, access and rights route; do not merge with applicant processing |
Consequences
A changed role changes more than the contract noun
Follow the branch into each affected duty. A processor branch needs documented instructions, a contract or legal act with the required processing detail, confidentiality, security, assistance, return or deletion, audit support and controlled appointment of subprocessors. A joint-controller hypothesis raises an Article 26 arrangement and a transparent account of responsibilities. A separate controller activity needs its own purpose, legal basis, transparency, rights route, retention and accountability analysis. Qualified counsel must decide the exact consequence under the applicable regime.
Privacy by design belongs at the branch decision, not after award. The EDPB’s Article 25 guidance links safeguards to the choice of means and to processing itself. Record data that can be excluded, defaults, access, retention, separation and evidence for each branch. If an option is likely to create high risk, route it to the controller that must decide whether and how to complete an impact assessment before the processing begins. The bid should not promise that another party’s statutory judgment has already been made.
Trace provider chains too. EDPB Opinion 22/2024 says controllers should have the identity of processors and subprocessors readily available and must verify sufficient guarantees, with the depth of verification varying according to risk. For the offer, identify which branch invokes which provider, processing, data and location. This article does not answer the separate residency and transfer question, but the chosen role and chain must link to that analysis.
- Identify the party that issues and changes instructions for each processor activity.
- Describe who gives privacy information and who receives each type of rights request.
- Update the processing records and contract annex with the selected purpose, data and duration.
- Name the owner of any impact-assessment decision and the event before which it must close.
- Link each provider to the activity and branch that makes it necessary.
- Keep data-location and international-transfer conclusions in their dedicated assessment.
Evidence
Evidence the facts that drive the role, not the label itself
Role evidence is distributed. The tender and service description show intended outcomes. Configuration records show who can select fields, rules and recipients. Product decisions explain why optional telemetry or improvement uses exist. Data-flow records show operations and parties. Processing records, privacy information and contract drafts show the documented position. None is decisive alone. Index the facts and contradictions that counsel needs, with service version, date, owner and disclosure class.
Use separate states. A verified fact has current evidence for the offered configuration. A proposal is a deliverable commitment that still needs implementation. An assumption is a condition supplied by the buyer or bid team. A legal hypothesis is pending authorized review. An unknown lacks a defensible value. These states keep the bid useful without letting “proposed” or “expected” disappear during editing.
The evidence pack should be proportionate to the evaluated claim. Provide the answer, branch schedule and safe references in the response. Keep personal data, internal legal advice, sensitive configurations, security findings and customer-confidential material out of public or broadly shared annexes. A controlled diligence route can expose further evidence only when the procurement permits it and the owner approves access.
| State | Minimum support | Permitted language | Release control |
|---|---|---|---|
| Verified current fact | Current product or operating record for named scope | State the bounded fact and cite the record | Factual owner confirms currency |
| Proposed design | Approved offer design, delivery owner and acceptance gate | Will be configured subject to named dependency | Commercial and delivery approval |
| Role hypothesis | Purpose and essential-means facts with contrary indicators | We propose this role for this activity, subject to review | Authorized privacy or legal approval |
| Assumption | Named source, owner, impact and confirmation date | If the buyer selects A, the following position applies | Buyer confirmation or approved clarification |
| Unknown | Owner, question, deadline and safe fallback | No positive claim; state the unresolved decision | Release authority accepts qualification or stops answer |
Response form
Give the evaluator a direct answer and a controlled condition
Do not open with a lecture on data-protection law. Answer the stated proposition, identify the exception and point to the schedule. For Northborough, an approved response might say: “For buyer-directed application, case-management and configured matching activities, we propose that Northborough acts as controller and the supplier as processor. That position depends on Northborough determining the purposes, applicant data, material rules, recipients and retention described in Schedule PR-02. Optional supplier-defined comparative analysis is excluded from the offer. Account-security processing is assessed separately and is not covered by the blanket processor statement.” Counsel must approve the wording for the real facts and jurisdiction.
If the buyer requires a yes or no field, use the permitted qualification route rather than forcing a misleading absolute. A response can select “No” and explain the activity-level exception, or select the value specified by an official clarification. Do not alter a mandatory form silently. If the instructions prohibit qualification and the absolute statement remains inaccurate, escalate the commercial and legal decision before submission.
Keep the short answer consistent with the data-processing schedule, service description, subprocessor disclosure, security response, implementation plan, privacy information and price. A product option excluded to preserve the stated model cannot reappear in a demo script or implementation work package. The role schedule is the control record; the evaluator receives the portion needed to understand the offered design.
Decision gate
Make the last responsible decision date explicit
Every conditional row needs a trigger and a final safe state. Northborough may choose its matching configuration after a dialogue stage but before final tender. The schedule records who may choose, the latest date, evidence required and what the bidder offers if no choice arrives. The fallback might exclude the option, use a buyer-defined rule set or stop the affected processing. Silence must not activate the branch with the largest privacy consequence.
Some decisions can close after award but before live processing if the tender and contract allow it. Mark them as delivery conditions rather than current facts. Tie them to design approval, test evidence, contract schedules, privacy information, impact-assessment status and operational readiness. The commercial owner confirms that the condition is deliverable; the relevant controller retains its statutory decisions.
A branch is not ready because every cell is filled. It is ready when the controlling source is current, the facts cover the exact offer, contradictory evidence is resolved or visible, the correct authority has approved the role position and the response wording matches the decision. Record dissent and limitations. A neat table should never suppress a material disagreement.
Change control
Reopen the affected activity when the design moves
Link every released privacy statement to activity and branch identifiers. Reopen them if a purpose, material input, affected population, recipient, duration, instruction, provider, feature default or decision authority changes. Also reopen when legislation, regulator guidance or a binding procurement clarification alters the review frame. Give the new position a version and effective date; do not overwrite the record that supported the submitted bid.
The detailed ICO controller and processor guidance currently says it is under review because of changes made by the Data (Use and Access) Act. That notice is part of the source state. A UK bid approved later must check the current statute and regulator material again. It should not repeat this article as legal authority or assume a 2026 web page will remain unchanged.
After award, reconcile the selected branch with the signed terms and implemented service before personal data enters the system. During operation, product change, provider change and new uses of data return to the same purpose-and-means analysis. This preserves the bid commitment without pretending that a role characterization can never change.
What good looks like
Useful outcomes from answer RFP privacy question before final design
- Every privacy statement is tied to the current procurement question, jurisdiction, bidder, service option and date at which it must be true.
- Different purposes and material decisions are separated into processing activities instead of inheriting one relationship-wide label.
- Each open product or operating choice has named branches, a deadline, an owner and a stated effect on the proposed roles.
- Role hypotheses identify the facts that support them and the facts that would overturn them.
- Contract, notice, rights, record, impact-assessment and subprocessor consequences are visible before a branch is selected.
- The buyer can distinguish current capability, proposed configuration, buyer dependency, legal review and unresolved fact.
- The released answer remains useful to an evaluator without claiming that a commercial label determines the law.
- Any later design change reopens only the affected activities, decisions and bid statements through traceable links.
Operating model
How to run the work
- 01
Fix the legal and procurement frame
Record the question, definitions, scoring method, governing documents, relevant jurisdictions, bidder entities, required answer form and event at which each statement must hold.
- 02
Draw the offered service boundary
Name the edition, options, integrations, users, data classes, support path and third parties. Mark buyer choices that have not yet been made.
- 03
Separate processing activities
Create a row whenever purpose, affected people, data, recipient, retention, instruction or decision authority differs.
- 04
Define credible design branches
Describe only options the offer could deliver. Give each branch a trigger, assumptions, unavailable choices and last responsible decision date.
- 05
Record the decisive facts
For each activity and branch, state who decides why processing occurs, the essential means, practical implementation choices and permitted instructions.
- 06
Trace downstream consequences
Connect each role hypothesis to contracts, notices, rights routes, records, impact assessment, providers, evidence and delivery work.
- 07
Approve the response wording
Have product owners verify facts and privacy or legal reviewers approve the role analysis, qualifications, jurisdiction and allowed commitment.
- 08
Release and reopen by trigger
Publish the approved branch or conditional answer, then reopen linked rows when the buyer selects an option or the service design changes.
Evaluation
Questions that change the decision
- Which document, definition, clarification and scoring rule control the privacy question?
- Which legal regimes and public-sector duties need qualified advice for the stated processing?
- What exact service and configuration is the bidder offering, and when must it be fixed?
- What is the purpose of each processing activity, and whose objective does it serve?
- Who decides which people and data are involved, the material operations, recipients and duration?
- Which implementation choices can the supplier make while still following documented instructions?
- Do any parties make common or converging decisions for one activity?
- Does the supplier propose any separate use for service, account, support, security or product-improvement purposes?
- What contract, transparency, rights, record, impact-assessment and provider duties follow under each branch?
- Who has authority to select the branch, approve the legal position and bind the offer?
- Which facts remain unknown, how will they be obtained and what happens if they remain unresolved?
- What event expires the answer or requires a fresh assessment?
Failure modes
Where teams lose control
The master agreement calls the supplier a processor, so the bid team applies that label to unrelated supplier purposes.
One row combines application handling, user administration, support diagnostics, security monitoring and outcome analysis.
The answer treats a future buyer configuration as if it were the implemented default.
A recommendation feature is described as neutral tooling even though a party still decides its objective and essential inputs.
Joint control is assumed merely because two parties cooperate, or missed because their decisive contributions occur at different times.
Operational freedom over hosting or software is confused with authority to choose a new processing purpose.
A proposed processor reuse of customer data appears in product language but not in the role, transparency or compatibility analysis.
The contract schedule is drafted before the processing activities and cannot describe their subject, duration, nature and purpose accurately.
A high-risk option is promised before the responsible controller has assessed whether an impact assessment is required.
An unknown is hidden inside reassuring prose, leaving no owner or date for resolution.
A later design decision changes a role but the questionnaire, contract, privacy notice and delivery plan stay on the old branch.
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- privacy propositions linked to their controlling source, jurisdiction, response field and truth date
- material processing purposes represented by separate activity rows
- open design choices with exhaustive offered branches, owners and decision dates
- role hypotheses supported by recorded facts about purpose and essential means
- branches with contract, transparency, rights, record, assessment and provider consequences traced
- positive bid statements approved for the selected branch and current evidence state
- role-dependent statements that lack an authorized reviewer or decision trigger; target zero
- changes that reopen every linked statement before release
- activities left under a relationship-wide role label without separate analysis; target zero
Questions
Common questions
Can the contract simply state that the supplier is a processor?
The contract can record the agreed position and required terms, but it does not override the factual processing. Analyze each material activity first, then make the contract describe that result.
Can one supplier be both controller and processor?
It can hold different roles for different processing activities. Keep the purposes and records separate, and have qualified reviewers confirm the characterization under the applicable law.
Does choosing the hosting technology make a supplier a controller?
Not by itself. Practical implementation can be a non-essential means. The assessment must examine who determines the purpose and the means that are essential to the processing.
When should joint control be considered?
Consider it when parties make common decisions or separate but converging decisions about a processing activity. Cooperation alone is insufficient, and the conclusion needs legal review.
What if the buyer has not selected an optional feature?
Show the offered branches, the facts and consequences of each, the decision owner and date, and the safe fallback. Do not describe an unselected option as implemented.
Should a product-improvement use stay inside processor wording?
Not automatically. A supplier-defined reuse for its own purpose needs separate analysis of role, instructions, compatibility, lawful basis, transparency and safeguards.
Can a bid promise that no impact assessment is needed?
Only the responsible controller can make the required assessment on the final facts. The bidder should provide accurate design and risk information and state any decision still required.
Who approves the final privacy-role answer?
Product and delivery owners verify service facts. Authorized privacy or legal reviewers determine the role position and qualifications. Commercial authority approves the resulting commitment.
Sources
Primary references
- UK General Data Protection Regulation The National Archives
- Data Protection Act 2018 The National Archives
- Data (Use and Access) Act 2025 The National Archives
- Controllers and processors guidance Information Commissioner's Office
- How to determine whether you are a controller or processor Information Commissioner's Office
- What joint controllership means Information Commissioner's Office
- Contracts and liabilities between controllers and processors Information Commissioner's Office
- Documentation under the UK GDPR Information Commissioner's Office
- Data protection by design and by default Information Commissioner's Office
- Data protection impact assessments Information Commissioner's Office
- Purpose limitation Information Commissioner's Office
- Data minimisation Information Commissioner's Office
- Privacy in the product design lifecycle Information Commissioner's Office
- Guidelines 07/2020 on controller and processor concepts European Data Protection Board
- Opinion 22/2024 on processors and subprocessors European Data Protection Board
- Guidelines 4/2019 on data protection by design and by default European Data Protection Board
- Standard contractual clauses between controllers and processors EUR-Lex
- General Data Protection Regulation EUR-Lex
- Procurement Act 2023 The National Archives
- Guidance on assessing competitive tenders UK Cabinet Office
Ziva
Proposal software for source-grounded RFP, RFI, DDQ and questionnaire response work.
Bid, proposal, presales, security and compliance teams. Start with the workflow, constraints and evidence you already have.