Two roles: controller and processor
The GDPR (Regulation 2016/679) defines two main roles, and understanding them decides who answers to the supervisory authority:
🎯 Controller
The party that determines why and in broad terms how data is processed. Your client is typically the controller for their website's data: they decide the purposes (marketing, sales) and the means (CMS, newsletter tools).
🔧 Processor
The party that processes data on the controller's instructions. An agency maintaining a client site with access to user data via admin logins, backups or staging environments is typically a processor.
⚖️ Both at once
Many agencies are both: processor for client website data — but an independent controller for their own data (employees, own leads, analytics on their own domain).
Why it matters: as a processor you cannot simply "follow the client's instructions" if those instructions breach the GDPR — you are jointly exposed. And without a written data processing agreement (DPA), the processing is unlawful from day one (Art. 28).