Provision record
Writer · Writer Privacy Policy · View original document ↗

Controller/Processor Distinction for Enterprise Customers

High severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Writer and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

When enterprise customers submit data through Writer, Writer is acting as a data processor following the customer's instructions, while the customer remains legally responsible for that data under privacy law.

This analysis describes what Writer's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This allocation of legal roles has significant implications for enterprise compliance teams: it means the enterprise customer bears primary obligations under GDPR for lawful basis, data subject rights, and privacy notices related to the data they submit to Writer.

Interpretive note: The precise scope of what constitutes 'Customer Data' versus other data categories processed by Writer may vary by contract and use case, affecting the boundaries of the controller/processor allocation.

Recent Activity

This document changed recently

Medium Jun 2, 2026

The updated policy removes detailed disclosures that previously explained five cookie categories (strictly necessary, functional, performance, targeting), their purposes, and user controls. The revised policy retains only a brief statement that Writer uses cookies to enhance navigation, analyze usage, personalize experience, and assist in advertising, but no longer provides the granular categories, opt-out procedures, or explanation of what data each type collects. Users can no longer reference specific cookie management options, targeting cookie opt-out procedures, or detailed functional descriptions within the policy itself.

View change record →

Consumer impact (what this means for users)

Enterprise customers are responsible for ensuring their use of Writer complies with applicable privacy laws, including obtaining any necessary consents from employees or end users whose data is submitted to the platform.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Enterprise customers should contact privacy@writer.com to obtain or confirm execution of Writer's Data Processing Agreement (DPA) and to request sub-processor disclosures.

How other platforms handle this

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

Skillshare Medium

When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.

Square Medium

to object to profiling activities based on our own legitimate interests

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
With respect to Customer Data that enterprise customers submit to Writer's Services, Writer acts as a data processor on behalf of the customer, who acts as the data controller. The customer is responsible for ensuring they have the appropriate rights and permissions to submit such data to Writer.

Excerpt from Writer's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision directly engages GDPR Article 28, which governs processor agreements and requires a written contract specifying the subject matter, duration, nature, and purpose of processing, as well as obligations and rights of …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Writer Privacy Policy
Entity
Writer
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009056
Document ID
CA-D-00519
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7608f98ec864962e460fb54081cd71df8204c9cd672cbda9a45d0e7e87410493
Analysis generated
May 8, 2026 01:46 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Writer
Document: Writer Privacy Policy
Record ID: CA-P-009056
Captured: 2026-05-08 01:46:56 UTC
SHA-256: 7608f98ec864962e…
URL: https://conductatlas.com/platform/writer/writer-privacy-policy/provision/CA-P-009056/controllerprocessor-distinction-for-enterprise-customers/
Accessed: Sept. 12, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Writer's Controller/Processor Distinction for Enterprise Customers clause do?

This allocation of legal roles has significant implications for enterprise compliance teams: it means the enterprise customer bears primary obligations under GDPR for lawful basis, data subject rights, and privacy notices related to the data they submit to Writer.

How does this clause affect you?

Enterprise customers are responsible for ensuring their use of Writer complies with applicable privacy laws, including obtaining any necessary consents from employees or end users whose data is submitted to the platform.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Writer?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Writer.