Data Controller is the natural or legal person that, alone or jointly with others, determines the purposes and means of personal data processing under GDPR.
The Data Controller is the central accountability anchor of the GDPR, defined in Article 4(7). Whoever decides why personal data is processed and how it is processed (the purposes and means) is the controller, and the controller carries the obligations: lawful basis, transparency, data subject rights, security, breach notification, records of processing, and DPIA where required.
The role is determined by factual control, not by contract. Calling a counterparty a processor in a contract does not make them one if they actually decide purposes and means. Two or more parties determining purposes and means together are joint controllers under Article 26 and must publish the essence of their arrangement and the contact point for data subjects.
The controller selects processors and signs Article 28 data processing agreements with them, and remains responsible for the processor's acts. Controllers established outside the EU/EEA but in scope under Article 3(2) generally must designate a Representative in the EU under Article 27 to act as a local point of contact for supervisory authorities and data subjects.
You will act as a controller any time your business decides to collect personal data: customer accounts, employee records, marketing lists, CCTV, analytics. Vendors that merely execute your instructions, such as cloud hosting, payroll providers, or email-sending services, are typically processors, with you remaining the controller and bearing primary accountability.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.