Data Controller
A data controller is the person, company, or public authority that decides why and how personal data is collected and used. It makes the key decisions about the processing, such as what data to gather, for what purpose, and how long to keep it. The controller is distinct from a data processor, which acts on the controller's behalf rather than setting the purposes itself.
Under EU and UK data protection law, a data controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The defining characteristic is decision-making authority over the 'why' and 'how' of processing; the controller exercises overall control and generally bears ultimate responsibility for compliance obligations attaching to that processing. This role is legally separate from that of a data processor, which processes personal data on the controller's behalf and under its instructions and does not itself determine the purposes of processing. Determining controller status is fact-specific and turns on who actually exercises decisive influence over processing, rather than on contractual labels alone. This entry addresses the concept as framed under the EU GDPR and UK GDPR; other jurisdictions may use different terminology or role definitions, and readers should verify against the applicable authoritative text.
Why it matters
The controller concept is the anchor for allocating accountability under the EU GDPR and UK GDPR. Because the controller determines the purposes and means of processing, it generally bears the primary compliance obligations attaching to that processing, including establishing a lawful basis, honoring data subject rights, and demonstrating accountability. Misidentifying who the controller is can therefore lead to obligations being unassigned or misassigned, which undermines both compliance and the ability to respond correctly when regulators or data subjects raise questions.
Controllership is determined by who actually exercises decisive influence over the 'why' and 'how' of processing, not by contractual labels alone. A party cannot avoid controller responsibilities simply by describing itself as a processor in an agreement, nor assume it is a mere processor when it is in fact making the key decisions about the data. This fact-specific character means organizations should assess their real-world decision-making role for each processing activity rather than relying on a single blanket designation across all their operations.
The analysis is also arrangement-specific: parties may act as controllers alone or jointly with others, and a single organization can be a controller for some processing and a processor for other processing. Because determining status turns on the facts and because terminology and role definitions differ across jurisdictions, readers should verify their assessment against the applicable authoritative text and apply professional judgment to their particular circumstances.
Who it's relevant to
Inside Data Controller
Common questions
Answers to the questions practitioners most commonly ask about Data Controller.

