Data controller
Also known as: controller
The organisation that decides why and how personal data is used, and so carries the main legal duty under GDPR.
Draft - this entry has not been reviewed yet.
Formal
Under GDPR Article 4(7), the person or body that, alone or jointly with others, decides the purposes and means of processing personal data; under Article 24 it must be able to show that the processing complies with the regulation.
In plain English
Like someone who hires a moving firm - the movers carry the boxes, but you chose what to move and where, so it is on you if the wrong things end up in the wrong place.
In practice
A Danish municipality picks a learning platform for its schools; the municipality, not the platform supplier, is the controller, so it must tell parents what is collected and answer their requests for access.
Why it matters
Data often passes through many hands; fixing one party as answerable means people know whom to ask, and the authority knows whom to hold liable when data is misused or lost.
Technical deep dive
Controllership under GDPR Art. 4(7) is a functional concept: it follows from who actually determines the purposes and means of processing, not from what a contract calls the parties. The EDPB Guidelines 07/2020 on the concepts of controller and processor distinguish essential means (which data are processed, for how long, who has access, which recipients) from non-essential means (choice of hardware, software, security architecture). Deciding purposes and essential means makes an entity a controller; a service provider may choose non-essential means and still be a processor. Art. 4(7) also allows Union or member-state law to designate the controller directly, which is common for public authorities whose tasks are set by statute.
Joint controllership (Art. 26) arises when two or more parties jointly determine purposes and means, and the CJEU has read it broadly. In Wirtschaftsakademie (C-210/16, 2018) a Facebook fan-page administrator was a joint controller with Facebook for visitor statistics; in Jehovan todistajat (C-25/17, 2018) a religious community was joint controller for data collected by its members door to door; in Fashion ID (C-40/17, 2019) a website embedding a Like button was joint controller for the collection and transmission of visitor data, but not for Facebook's subsequent processing. Joint control does not require equal responsibility or access to the data, but it does require an arrangement allocating duties, whose essence must be made available to data subjects, and data subjects may exercise their rights against each controller (Art. 26(3)).
The controller carries the accountability duty in Art. 5(2) and Art. 24: it must implement and be able to demonstrate appropriate technical and organisational measures, which in practice means records of processing (Art. 30(1)), information notices (Arts. 13-14), handling of data subject requests within one month extendable by two further months (Art. 12(3)), DPIAs, breach notification to the supervisory authority (Art. 33) and to data subjects (Art. 34), and choosing only processors providing sufficient guarantees (Art. 28(1)). Under Art. 82 the controller is liable for damage caused by non-compliant processing; a processor is liable only for breaching its own obligations or the controller's lawful instructions.
Common failure modes are role confusion in supplier relationships and in groups of companies. A SaaS vendor that reuses customer data to train its own models or for analytics is a controller for that purpose, regardless of the data processing agreement. Each legal entity in a corporate group is a separate controller, so intra-group sharing needs a legal basis and often a processing agreement. Assigning roles per processing activity, not per organisation, is the reliable method: the same company can be controller for its HR data and processor for its customers' data.
What to learn first
Everything this builds on, foundations first.
- Confidentiality
- →Personal data
- →GDPR
- →Data controller
Relationships
- Requires
- GDPR
- Unlocks
- Supervisory authority
- Don't confuse with
- Data processor
- Used with
- Data processing agreement (DPA)
Sources & further reading
Standards & official texts
- Regulation (EU) 2016/679 (GDPR), Article 4(7) and Article 24 · European Union
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…