Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Data Governance

Data Controller

Also known as: Controller
Simply put

A data controller is the person, company, or public authority that decides why and how personal data is collected and used. It makes the key decisions about the processing, such as what data to gather, for what purpose, and how long to keep it. The controller is distinct from a data processor, which acts on the controller's behalf rather than setting the purposes itself.

Formal definition

Under EU and UK data protection law, a data controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The defining characteristic is decision-making authority over the 'why' and 'how' of processing; the controller exercises overall control and generally bears ultimate responsibility for compliance obligations attaching to that processing. This role is legally separate from that of a data processor, which processes personal data on the controller's behalf and under its instructions and does not itself determine the purposes of processing. Determining controller status is fact-specific and turns on who actually exercises decisive influence over processing, rather than on contractual labels alone. This entry addresses the concept as framed under the EU GDPR and UK GDPR; other jurisdictions may use different terminology or role definitions, and readers should verify against the applicable authoritative text.

Why it matters

The controller concept is the anchor for allocating accountability under the EU GDPR and UK GDPR. Because the controller determines the purposes and means of processing, it generally bears the primary compliance obligations attaching to that processing, including establishing a lawful basis, honoring data subject rights, and demonstrating accountability. Misidentifying who the controller is can therefore lead to obligations being unassigned or misassigned, which undermines both compliance and the ability to respond correctly when regulators or data subjects raise questions.

Controllership is determined by who actually exercises decisive influence over the 'why' and 'how' of processing, not by contractual labels alone. A party cannot avoid controller responsibilities simply by describing itself as a processor in an agreement, nor assume it is a mere processor when it is in fact making the key decisions about the data. This fact-specific character means organizations should assess their real-world decision-making role for each processing activity rather than relying on a single blanket designation across all their operations.

The analysis is also arrangement-specific: parties may act as controllers alone or jointly with others, and a single organization can be a controller for some processing and a processor for other processing. Because determining status turns on the facts and because terminology and role definitions differ across jurisdictions, readers should verify their assessment against the applicable authoritative text and apply professional judgment to their particular circumstances.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for privacy compliance need to identify, for each processing activity, whether their organization is acting as a controller, a processor, or a joint controller, because controller status generally drives the primary compliance obligations. This determination should be made on the facts of who decides the purposes and means, not on contractual labels alone.
Legal counsel and contract managers
Counsel drafting or reviewing data processing arrangements need to reflect the parties' actual roles accurately. Because controller status turns on who exercises decisive influence over processing rather than on how a contract describes a party, contractual designations should be tested against the operational reality and against the applicable authoritative text.
Organizations engaging service providers
Businesses that outsource processing to third parties need to understand where controller responsibility sits. A controller that engages a processor generally retains overall control and ultimate responsibility for the processing, so understanding the boundary between setting the purposes and means and merely acting on instructions is important when allocating obligations.
Compliance auditors and assessors
Those evaluating an organization's data protection posture need to confirm that role designations align with actual decision-making authority. Because the analysis is fact-specific and can differ per processing activity, assessments should examine who genuinely determines the why and how of processing rather than relying on a single organization-wide label.

Inside Data Controller

Determination of purposes
A controller is the entity that decides why personal data is processed. Determining the objectives or reasons for processing is a defining characteristic of the controller role under EU and UK data protection law.
Determination of means
The controller also decides how personal data is processed. While detailed technical decisions may be delegated to a processor, the essential means (such as which categories of data to collect and how long to retain them) generally remain with the controller.
Legal responsibility and accountability
The controller bears primary accountability for compliance with applicable data protection obligations, including demonstrating that processing meets the relevant principles. This is distinct from the more limited obligations imposed on a processor.
Distinction from the processor
A processor acts on behalf of, and under the instructions of, the controller. The controller sets the purposes and essential means; the processor executes processing without determining those purposes on its own account.
Joint controllership
Where two or more entities jointly determine the purposes and means of processing, they may be joint controllers and generally need to allocate their respective responsibilities, often through an arrangement between them.
Jurisdictional grounding
The concept is defined principally within EU data protection law and the UK equivalent following retained-law arrangements. Other jurisdictions may use different terminology or frameworks, and the analysis should be tied to the applicable regime.

Common questions

Answers to the questions practitioners most commonly ask about Data Controller.

Is the data controller simply whichever organization physically holds or stores the personal data?
No. Controller status turns on who determines the purposes and means of processing, not on who holds the data. An organization can be a controller for data it never physically stores if it decides why and how that data is processed, while a party that stores data on another's behalf and processes it only per instructions is generally a processor, not a controller. Possession and control of processing are distinct concepts and should not be conflated.
Does outsourcing processing to a vendor transfer the controller's compliance responsibility to that vendor?
Generally not. Engaging a processor does not discharge the controller's own obligations; the controller typically remains accountable for the lawfulness of the processing and for the choices it directs. Processors carry their own distinct duties, but the controller's accountability for purposes and means does not shift to a vendor merely because the work is outsourced. Roles should be assessed on the facts of each arrangement rather than assumed from the contract label.
How should an organization determine whether it is acting as a controller or a processor for a given activity?
The assessment is fact-specific and should focus on who decides the purposes and the essential means of the processing for that particular activity. An organization may be a controller for some processing and a processor for other processing, sometimes within the same relationship. Contractual labels are not decisive; the actual decision-making role governs. Where two or more parties jointly determine purposes and means, a joint controller analysis may apply. Application to particular circumstances requires professional judgment and verification against the current authoritative text of the applicable law.
What documentation is typically expected to reflect controller status and responsibilities?
Practices vary by jurisdiction and by the nature and scale of the processing, but controllers commonly maintain records describing their processing activities, the purposes pursued, and the legal or contractual basis relied upon, along with arrangements governing any processors they engage. The precise scope, format, and any exemptions depend on the applicable rules and the organization's size and risk profile. Readers should confirm specific record-keeping requirements against the relevant official text.
When a vendor is engaged, how is the controller-processor relationship usually formalized?
In most cases the relationship is set out in a written agreement that reflects each party's role and the terms under which the processor may act, including that the processor acts on the controller's documented instructions. The specific mandatory contents of such agreements are prescribed by the applicable law and can differ across jurisdictions. Because a label in a contract does not by itself establish the actual role, the arrangement should be reviewed against how purposes and means are in fact determined, and against the current legal requirements.
How does controller status interact with obligations toward individuals whose data is processed?
The controller is generally the party responsible for responding to the exercise of individuals' rights and for the transparency and lawfulness of the processing, because it is the entity that determines purposes and means. A processor typically supports the controller in meeting these obligations but does not ordinarily bear them independently for processing carried out on the controller's behalf. The precise allocation of duties, available exemptions, and enforcement practice differ by jurisdiction and should be verified against the applicable authoritative source.

Common misconceptions

Whoever physically holds or stores the data is automatically the controller.
Controller status turns on who determines the purposes and means of processing, not on who possesses or hosts the data. A hosting or storage provider acting on instructions is typically a processor, while the entity deciding why the data is processed remains the controller.
Controller and processor are interchangeable labels, so it does not matter which applies.
The roles carry distinct obligations. Controllers bear primary accountability for the purposes and lawfulness of processing, while processors have narrower duties tied to acting on the controller's instructions. Misclassifying the role can lead to obligations being missed.
An organization can only ever be a controller or only ever a processor.
The same organization may be a controller for some processing activities and a processor for others, and in certain arrangements may act as a joint controller. The classification is assessed per processing activity rather than assigned once to the entity as a whole.

Best practices

Assess controller versus processor status separately for each distinct processing activity rather than applying a single label across the whole organization.
Base the classification on who actually determines the purposes and essential means of processing, not on who stores or physically handles the data.
Where more than one entity jointly determines purposes and means, document the allocation of responsibilities between the parties in a clear written arrangement.
Maintain documentation that supports the accountability expected of a controller, and be prepared to demonstrate how processing meets applicable obligations.
Confirm which jurisdiction's regime applies before relying on the controller concept, as terminology and obligations differ across the EU, the UK, the United States, and elsewhere.
Verify role definitions and their specific obligations against the current authoritative text of the applicable law, and seek professional judgment for fact-specific situations.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.