A first step to take in analysing requirements under the General Data Protection Regulation, Regulation (EU) 2016/679 (the GDPR) in relation to any data sharing is to establish the capacity in which the relevant parties are acting. In a similar manner to preceding EU data protection laws, the GDPR distinguishes between controllers and processors. In summary, Article 4 of the GDPR, Regulation (EU) 2016/679 generally defines a controller as: ‘the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data...’ In contrast, Article 4 of the GDPR, Regulation