The UK General Data Protection Regulation (UK GDPR) distinguishes between ‘data controllers’ and ‘data processors’. The UK GDPR definition of a data controller is: ‘The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data…’ A data processor is: ‘A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.’ Most methods of handling personal data constitute ‘processing’, including collecting, using, organising and storing it. Where a solicitor instructs a barrister to appear at a hearing and to advise generally, the distinction between controllers and processors may not be obvious. The Information Commissioner’s Office (ICO)’s detailed guidance on Controllers and processors and the European Data Protection Board (EDPB)’s Guidelines on the concepts