Privacy
Glossary

Controller

The natural or legal person, public authority or other body that alone or jointly decides the purposes and means of processing personal data.

In brief

Under Article 4(7) GDPR, a controller is the natural or legal person, public authority, agency or other body that alone or jointly with others determines the purposes and means of processing personal data. Where Union or Member State law determines those purposes and means, that law may also designate the controller or set the criteria for its designation.

The role follows the actual design of the processing, not merely the heading of a contract. In a business, the organisation itself will usually be the controller rather than an individual managing director, employee or external provider. The party that decides why personal data are processed and determines the essential elements of how the processing operates carries the data protection responsibility. The controller does not need direct access to every item of data being processed.

A processor must be distinguished from the controller. A processor handles personal data on the controller’s behalf and under documented instructions. Where two or more entities jointly decide the purposes and essential means, they may be joint controllers under Article 26 GDPR. That assessment depends on the parties’ actual decisions and processes. An agreement may allocate tasks between them, but it cannot turn an incorrectly classified role into the right one.

In practice, a business should record for each processing activity its purpose, the party deciding the essential means and the decisions on legal basis, recipients, access, erasure and security. Article 24 GDPR requires appropriate measures and the ability to demonstrate compliance. The privacy compliance and governance section places these responsibilities in context; the role check offers an initial orientation when distinguishing a controller from a processor or joint controllers.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich