Skip to main content
Category: Controller & Processor Roles

Controller

Simply put

In data privacy law, a controller is the organization or person that decides why and how people's personal data is collected and used. It is the party that holds primary responsibility for making sure the data is handled lawfully. This is a specific legal role and should not be confused with the everyday meanings of the word, such as a financial officer or a device used to operate a machine.

Formal definition

Under EU and UK data protection law, a controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The controller bears primary accountability for compliance, including establishing a valid legal basis for processing and giving effect to data subject rights. The role is distinct from that of a processor, which acts on the controller's behalf, and the classification is determined by the factual reality of who exercises decision-making control rather than by contractual labels alone. Note: the evidence packet supplied does not contain data protection or GDPR source material defining this term; the specialist legal definition above is provided for context, and practitioners should verify the precise wording and applicable article against the current official text of the applicable Regulation and any national implementing law.

Why it matters

The controller is the party that carries primary accountability under EU and UK data protection law. Because the controller determines why and how personal data is processed, it is generally the organization that must establish a valid legal basis, respond to data subject rights requests, and demonstrate compliance to regulators. Misidentifying who the controller is can undermine an entire compliance program, since obligations and liability attach to this role rather than to whichever party merely handles the data on someone else's instructions.

The distinction matters in practice because classification depends on the factual reality of who exercises decision-making control, not on the labels the parties choose in a contract. Two organizations may agree in writing that one is a processor, but if that party in fact decides the purposes and means of processing, it may be treated as a controller and bear the corresponding responsibilities. Getting this analysis right is a prerequisite for structuring arrangements such as processing agreements and for allocating responsibility where parties act as joint controllers.

A note of caution on terminology: the word controller has several unrelated everyday meanings, including a senior financial or accounting officer of an organization and a device used to operate a machine or play video games. These meanings are entirely distinct from the data protection role and should not be conflated in a privacy or compliance context. Practitioners should also verify the precise legal wording and applicable article against the current official text of the applicable Regulation and any national implementing law, as the source material supplied here did not include data protection statutory text.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads need to correctly identify when their organization acts as a controller, because that classification determines which accountability obligations apply, including establishing a legal basis and giving effect to data subject rights. Mapping controller status across processing activities is typically a foundational step in a compliance program.
Privacy and technology lawyers
Lawyers advising on data arrangements must assess controller status based on the factual reality of who determines purposes and means, rather than relying on contractual labels alone. This analysis informs how responsibilities and liability are allocated between parties, including in joint controller and controller-to-processor relationships.
Engineers and product teams
Engineers and product teams influence the means of processing through the systems they design and the data flows they build. Understanding that decisions about how personal data is processed can bear on controller responsibilities helps teams surface those decisions to legal and compliance colleagues early.
Business and operational stakeholders
Operational stakeholders who decide why personal data is collected and used may be exercising controller-level decision-making, even if that is not their intent. Recognizing this helps organizations avoid assuming that outsourcing an activity automatically shifts controller responsibility to a third party.

Inside Controller

Determination of purposes
A controller is the entity that decides the 'why' of processing, i.e. the objectives for which personal data is processed. This decision-making role is central to the definition under Article 4(7) GDPR.
Determination of means
A controller also decides the 'how' of processing, at least the essential means (such as what data, whose data, and for how long). Non-essential or technical means may be left to a processor without changing the controller status, per European Data Protection Board guidance.
Natural or legal person, authority, agency, or other body
The controller may be an individual, a company, a public authority, or another type of organization. The determination is functional rather than formal, so it turns on actual influence over the processing rather than on a contractual label alone.
Alone or jointly
Where two or more parties jointly determine purposes and means, they may be joint controllers, who under Article 26 GDPR are generally required to arrange their respective responsibilities transparently between them. Joint control is distinct from a controller-processor relationship.
Accountability obligations
The controller generally bears primary responsibility for compliance and must be able to demonstrate it, reflecting the accountability principle. Typical obligations include identifying a lawful basis under Article 6 (and an additional condition under Article 9 for special category data), providing information to data subjects, and responding to data subject rights requests.
Distinction from the processor
A processor processes personal data on behalf of, and under the documented instructions of, the controller and does not determine the purposes. A controller-processor arrangement typically requires a contract meeting the requirements of Article 28 GDPR.

Common questions

Answers to the questions practitioners most commonly ask about Controller.

Is a controller the same as a processor?
No. A controller is the party that determines the purposes and means of processing personal data, whereas a processor acts on the controller's behalf and on its documented instructions. The roles carry different obligations under the GDPR, and the same organisation may be a controller for some processing and a processor for other processing. Determining the correct role is a factual assessment based on who exercises decision-making influence over the why and how of the processing, rather than on how a contract labels the parties.
Does being a controller mean you always need consent to process personal data?
No. Consent is only one of the legal bases available under Article 6, alongside contract, legal obligation, vital interests, public task, and legitimate interests. A controller must identify an appropriate lawful basis for each processing activity, and in many cases a basis other than consent will be the correct one. Where special category data is involved, an additional condition under Article 9 is generally required. Which basis applies is context-dependent and should be assessed for each purpose.
How does an organisation determine whether it is acting as a controller for a particular processing activity?
The assessment turns on who determines the purposes and means of the processing, which is a factual question rather than one settled by contractual labels alone. Relevant indicators typically include who decides why the data is processed, who decides the essential means, and who exercises overall decision-making influence. The same entity may be a controller for some activities and a processor or joint controller for others, so the analysis is generally carried out per processing activity. Regulatory guidance on this classification exists and readers should consult current guidance, as interpretation can evolve.
What documentation should a controller typically maintain to demonstrate accountability?
Controllers are generally expected to be able to demonstrate compliance, which in most cases includes maintaining records of processing activities, documenting the lawful basis for each purpose, and retaining evidence of measures taken. Depending on the processing, this may also involve documenting Data Protection Impact Assessments where high risk is indicated, and Article 28 arrangements with any processors engaged. The precise documentation obligations can vary with the nature, scope, and risk of the processing and with national implementing rules, so requirements should be verified against the current applicable text.
What must a controller put in place when engaging a processor?
Where a controller engages a processor, a written contract or other legal act meeting the requirements of Article 28 is generally required, setting out the subject matter, duration, nature and purpose of the processing, the types of personal data, categories of data subjects, and the obligations and rights of the controller. This instrument is distinct from a Data Protection Impact Assessment and from transfer tools such as Standard Contractual Clauses. Controllers should also assess whether the processor offers sufficient guarantees of appropriate technical and organisational measures.
How does controller status affect responsibility for responding to data subject rights requests?
The controller is generally the party responsible for facilitating and responding to data subject rights requests, such as access, rectification, and erasure, subject to the applicable conditions and exemptions. Where a processor receives such a request, it typically must assist the controller and refer or forward the request rather than respond independently. The scope and handling of specific rights can vary by legal basis, by processing context, and by national derogations, so procedures should be aligned with the current applicable requirements.

Common misconceptions

Whoever holds or physically stores the data is the controller.
Controller status turns on who determines the purposes and essential means of processing, not on who possesses or hosts the data. A party may store or handle large volumes of data purely on a controller's instructions and be a processor rather than a controller. The assessment is functional and fact-specific.
A party is a controller only if a contract or policy calls it one.
The role is assessed on the factual reality of who exercises decision-making influence over processing, not solely on how a contract labels the parties. A misdescribed label does not, by itself, change the underlying status, though documentation remains important evidence.
A controller must always obtain consent to process personal data.
Consent is only one of several lawful bases under Article 6 GDPR, alongside contract, legal obligation, vital interests, public task, and legitimate interests. The appropriate basis depends on the context, and special category data under Article 9 requires an additional condition beyond the Article 6 basis.

Best practices

Map each processing activity and assess, on the factual circumstances, whether your organization determines the purposes and essential means, so that you can classify yourself as controller, joint controller, or processor rather than relying on labels alone.
For each processing activity, identify and document an appropriate lawful basis under Article 6, and confirm an additional condition under Article 9 where special category data is involved, verifying the position against the current official text and any applicable national rules.
Where control is shared, evaluate whether a joint controller relationship exists and, if so, put in place a transparent arrangement allocating respective responsibilities as generally required under Article 26.
Where you engage another party to process on your behalf, put in place a written contract addressing the matters required under Article 28, and ensure documented instructions govern the processing.
Maintain records and internal documentation that demonstrate how compliance decisions were made, supporting the accountability principle and enabling you to evidence your role and lawful basis if challenged.
Review classifications and arrangements periodically, since roles can shift as processing activities change, and confirm whether UK GDPR, national implementing law, or member state derogations affect your specific position.