Two vendors use the same customer data for different purposes
Describe them by what each actually does, not by a shared label like vendor or processor. ICO guidance on controller and processor roles makes the role depend on who determines the purposes and means of each processing activity, not on the organization's marketing category. Two services receiving the same email address can differ completely: one may act only on your documented instructions while the other determines its own use. Build a vendor-purpose map from the contracts and observed behavior before writing or updating any public description.
For: A research-only merchant whose email platform, analytics service, payment provider and other vendors each receive overlapping customer information for different reasons.
A customer email address sent to a mailing service to deliver your order updates and the same address received by an advertising platform to build audiences are the same data doing different work. Treating both as a single line in a vendor list erases the distinction a reader or a regulator would care about. The data element is shared; the processing activity is not.
ICO guidance on determining controller and processor status directs attention to who decides the purposes and means of each processing activity. An organization can act as a processor for one activity and determine its own purposes for another. That means you cannot read the role off the vendor's logo, its market category or the label in your plugin directory.
Start the map from the transfers, not the vendors. List each actual flow of customer information out of your store: what is sent, to which legal entity, triggered by what event. Two flows to the same company can still be separate activities with separate terms.
Read the contract for the activity, not the brand
For each flow, locate the agreement that governs it: the service terms, data processing terms or addendum that actually applies to your account. Record what the vendor is contracted to do, what it is permitted to do with the information for its own purposes, and what instructions it accepts from you. A vendor whose terms reserve independent uses is a different arrangement from one that acts only on documented instructions, even if both are marketed as simple tools.
Do not assign a legal role from the worksheet itself. The map records the facts: the contracted service, the permitted uses stated in the agreement, and any purposes the vendor determines itself. Whether those facts make the vendor a controller, processor, joint controller or service provider under a given law is a classification for qualified review against the rules that apply to your business and your customers' locations.
Where no agreement can be found for an active flow, that is a finding. An undocumented transfer is not a transfer without rules; it is a gap the business owner must close before the arrangement can be described accurately anywhere.
Assign access and request-handling ownership per vendor
For each vendor, record who inside the business owns the relationship: who holds the account, who can change the integration, and who answers a customer request that touches that vendor's data. If a customer asks what you share or asks for deletion, the answer may require action in several vendor accounts, each with its own process and its own responsible person.
Distinguish what the vendor does automatically from what your staff can invoke. A vendor may hold data you cannot see or export through your account, and may offer request-handling tools you have never configured. The map should record the actual mechanism available to you, not the mechanism a sales page implies.
Keep the distinction between vendors whose handling you direct and vendors whose handling you can only request. That difference changes both your customer-facing answers and your realistic timelines, and it belongs in internal records even when the public description stays brief.
Describe the arrangement publicly at the level you verified
Public policy text should reflect the verified map: categories of recipients, what each receives and why, at the level of detail your records support. Where two vendors receive the same data for different purposes, the description should not flatten them into one generic entry, and it should not invent precision you have not verified.
When a vendor's role, terms or integration changes, update the map first and the public text second, recording both dates. A policy edit made from memory rather than from the current agreement recreates the original problem with fresher formatting.
If you want a scoped Prism website review of the recipient descriptions in your store policies, bring the policy URLs and a non-sensitive summary of the vendor arrangement; scope, responsibilities, fees and terms are confirmed before work. Keep contracts, account credentials and customer data out of the public inquiry.
Vendor-purpose map
Complete one row set per vendor that receives customer information, using the actual agreement and observed configuration. Where a fact cannot be verified, record it as unresolved rather than borrowing a description from the vendor's marketing. This map records facts; legal role classification needs qualified review.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Vendor-purpose map. The last column is for temporary notes.
Mapping item
Record or check that establishes it
Why it matters
Your finding
Data transferred
Record or check that establishes itThe actual fields sent, the trigger event and the technical route, from configuration or integration records.
Why it mattersDefines the flow being mapped; assumptions from the vendor's name do not count.
Vendor legal entity
Record or check that establishes itThe entity named in the agreement or account, distinct from the brand or plugin name.
Why it mattersIdentifies who actually receives the data and holds the obligations.
Contracted service
Record or check that establishes itWhat the vendor is engaged to do for you under the applicable terms.
Why it mattersAnchors the purpose of the transfer in a document, not in a product description.
Vendor's permitted own uses
Record or check that establishes itAny purposes the agreement reserves for the vendor itself, including service improvement or independent features.
Why it mattersSeparates a vendor acting on instructions from one determining its own purposes.
Access and control available to you
Record or check that establishes itWhat your account can view, export, restrict or delete, as actually configured.
Why it mattersDetermines what your staff can do directly versus what requires a vendor request.
Request-handling owner
Record or check that establishes itThe internal role responsible for this vendor when a customer request touches its data, and the vendor's mechanism.
Why it mattersAssigns action before a request arrives rather than during it.
Public description match
Record or check that establishes itThe policy sentence describing this vendor compared with the verified rows above.
Why it mattersFlags flattened, stale or invented descriptions for the policy owner.
Unresolved gaps
Record or check that establishes itAny flow without a located agreement or verified configuration.
Why it mattersBlocks a confident public description until the business owner closes the gap.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
ICO controller and processor guidance is UK guidance; role classification under any law requires assessment of your actual activities and contracts by qualified review, not a label from this map.
A vendor's marketing category, plugin listing or brand familiarity does not establish its legal role or its actual permitted uses.
Keep contracts, account credentials, customer records and exports out of the worksheet and the public consultation form.
An accurate vendor description does not establish legal compliance, consent sufficiency or payment-provider approval.
ICO: Controller or processor roles — checked 2026-10-01. Controller and processor roles depend on who determines the purposes and means of each processing activity, not on the organization's label. Actual activities and contracts require assessment.
Prism features — checked 2026-09-21. An agreed website review can cover store policies and business disclosures together with other surfaces, producing informational findings rather than legal opinions or certification.