Labels in a contract do not decide the real role. Actual decisions do: who selected the audience, defined the purpose, chose the data, set retention, handled objections, and decided what happens next.
A role map matters because it determines notices, agreements, rights handling, security duties, records, and incident coordination.
Governance position
The organization that decides why and how personal data is used is generally the controller; a provider acting only on documented instructions is generally a processor. In Telegram acquisition, the answer must be mapped per processing activity. An agency or software provider can be a processor for one activity and an independent or joint controller for another.
Decisions to document
- A decision test for each processing activity.
- A worked responsibility map.
- Contract and operating questions.
- Warning signs that the paper model is false.
Map activities, not companies
| Activity | Key decision | Likely responsibility question |
|---|---|---|
| Community research | Why these people and fields? | Who defined the research purpose? |
| Audience approval | Who is eligible for contact? | Who owns the prospecting criteria? |
| Message delivery | On whose instructions? | Can the operator reuse data for itself? |
| CRM storage | Which records and how long? | Who controls retention and deletion? |
| AI analysis | Which data enters which model? | Does the provider train or act independently? |
Use the decision test
Document the answer with evidence. If two parties jointly determine essential purposes and means, assess joint controllership rather than forcing a processor label.
The same discipline applies to lawful basis. The EDPB's legitimate-interest guidance uses a three-part analysis: identify a legitimate interest, show that the processing is necessary for it, and balance that interest against the person's rights and reasonable expectations. Writing 'legitimate interest' in a spreadsheet is not the analysis.
- Who defines the purpose?
- Who selects categories of people and data?
- Who chooses essential means and retention?
- Who can authorize a new use?
- Who answers the individual and regulator?
Translate the map into operations
- Documented instructions and prohibited uses.
- Confidentiality, security, subprocessors, and transfer terms.
- Rights-request routing and response deadlines.
- Incident notification contacts and evidence preservation.
- Return, deletion, and audit obligations at termination.
Test common scenarios
| Scenario | Risk to examine |
|---|---|
| Agency builds list to client's exact brief | Whether the agency stays within instructions |
| Agency reuses list for other clients | Independent purpose and likely controller role |
| CRM stores client data only as configured | Processor obligations and access controls |
| Vendor uses conversations to train its own model | New independent purpose and transparency |
| Client and agency jointly design the campaign | Possible joint decisions and allocation |
Watch for paper-only compliance
- The contract says processor but the provider chooses audiences independently.
- No one owns deletion across exports and subprocessors.
- The privacy notice omits Telegram acquisition sources.
- Suppression applies in one tool but not the connected CRM.
- A client can request any campaign without an acceptable-use review.
Research note
This article explains operational concepts from GDPR Article 4 and related principles. Role determination is fact-specific and requires qualified legal advice.
Turn policy into an operating control
A useful role map names the real decision-maker for every stage. Once responsibility is visible, contracts, system permissions, retention, and incident workflows can reflect reality.
Build clearer boundaries into Telegram operations
TeleBoost supports isolated team workspaces, owned records, suppression controls, encrypted sessions, tickets, and scoped integrations. Legal roles remain yours to determine.
Continue the operating system
Related TeleBoost guides
Evidence base