Glossary/Compliance/Data Controller
Compliance

Data Controller

Data Controller is the natural or legal person that, alone or jointly with others, determines the purposes and means of personal data processing under GDPR.

What Data Controller is

The Data Controller is the central accountability anchor of the GDPR, defined in Article 4(7). Whoever decides why personal data is processed and how it is processed (the purposes and means) is the controller, and the controller carries the obligations: lawful basis, transparency, data subject rights, security, breach notification, records of processing, and DPIA where required.

The role is determined by factual control, not by contract. Calling a counterparty a processor in a contract does not make them one if they actually decide purposes and means. Two or more parties determining purposes and means together are joint controllers under Article 26 and must publish the essence of their arrangement and the contact point for data subjects.

The controller selects processors and signs Article 28 data processing agreements with them, and remains responsible for the processor's acts. Controllers established outside the EU/EEA but in scope under Article 3(2) generally must designate a Representative in the EU under Article 27 to act as a local point of contact for supervisory authorities and data subjects.

When you will meet Data Controller

You will act as a controller any time your business decides to collect personal data: customer accounts, employee records, marketing lists, CCTV, analytics. Vendors that merely execute your instructions, such as cloud hosting, payroll providers, or email-sending services, are typically processors, with you remaining the controller and bearing primary accountability.

Where this comes up in our guides

Data Controller FAQ

The controller decides why and how personal data is processed. The processor processes data on behalf of the controller, only on documented instructions. The same entity can be a controller for some processing activities and a processor for others; the analysis is per-processing-activity, not entity-wide.
At a glance
Category
Compliance
Confirm current figures with the official registry or a qualified adviser before relying on them.
Related terms
← All 120 glossary terms
Sources
  1. 1GDPR Article 4(7), Article 24, Article 26, Regulation (EU) 2016/679
  2. 2EDPB Guidelines 07/2020 on the concepts of controller and processor
  3. 3ICO controllers and processors guide
Definition reviewed March 2026.
Put it to use

Eight jurisdictions, costed out in full.

See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.

Tax calculatorEffective rates on your revenue and margin.Country comparisonEleven criteria, side by side.Cost estimatorWhat the first year actually costs.Document checklistWhat each registry will ask for.

New terms as the rules change

Thresholds move, regimes close, new ones open. One email, no pitches.