Controller
In data privacy law, a controller is the organization or person that decides why and how people's personal data is collected and used. It is the party that holds primary responsibility for making sure the data is handled lawfully. This is a specific legal role and should not be confused with the everyday meanings of the word, such as a financial officer or a device used to operate a machine.
Under EU and UK data protection law, a controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The controller bears primary accountability for compliance, including establishing a valid legal basis for processing and giving effect to data subject rights. The role is distinct from that of a processor, which acts on the controller's behalf, and the classification is determined by the factual reality of who exercises decision-making control rather than by contractual labels alone. Note: the evidence packet supplied does not contain data protection or GDPR source material defining this term; the specialist legal definition above is provided for context, and practitioners should verify the precise wording and applicable article against the current official text of the applicable Regulation and any national implementing law.
Why it matters
The controller is the party that carries primary accountability under EU and UK data protection law. Because the controller determines why and how personal data is processed, it is generally the organization that must establish a valid legal basis, respond to data subject rights requests, and demonstrate compliance to regulators. Misidentifying who the controller is can undermine an entire compliance program, since obligations and liability attach to this role rather than to whichever party merely handles the data on someone else's instructions.
The distinction matters in practice because classification depends on the factual reality of who exercises decision-making control, not on the labels the parties choose in a contract. Two organizations may agree in writing that one is a processor, but if that party in fact decides the purposes and means of processing, it may be treated as a controller and bear the corresponding responsibilities. Getting this analysis right is a prerequisite for structuring arrangements such as processing agreements and for allocating responsibility where parties act as joint controllers.
A note of caution on terminology: the word controller has several unrelated everyday meanings, including a senior financial or accounting officer of an organization and a device used to operate a machine or play video games. These meanings are entirely distinct from the data protection role and should not be conflated in a privacy or compliance context. Practitioners should also verify the precise legal wording and applicable article against the current official text of the applicable Regulation and any national implementing law, as the source material supplied here did not include data protection statutory text.
Who it's relevant to
Inside Controller
Common questions
Answers to the questions practitioners most commonly ask about Controller.