Glossary | GDPR & Data Privacy
Data Controller
What is a Data Controller?
A Data Controller is a natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data. Under Regulation (EU) 2016/679 (GDPR), the Data Controller is the primary party responsible for ensuring that personal data is processed lawfully, fairly, and in accordance with the rights of data subjects.
Why It Matters
Being a Data Controller carries the highest level of accountability under the GDPR. Controllers are responsible for determining why and how personal data is collected and used, and must be able to demonstrate compliance with the regulation’s principles at all times.
Most businesses that collect personal data from customers, users, or employees will be acting as a Data Controller for at least some of that processing. Understanding this role is essential — controllers are the primary target of enforcement action by supervisory authorities and can face significant fines where obligations are not met.
For ecommerce sellers, app developers, and businesses of all sizes, correctly identifying yourself as a Data Controller is the first step in building a compliant data protection framework.

Key Requirements
Who Is Considered a Data Controller?
An organisation or individual is considered a Data Controller when they:
- Decide why personal data is being collected or used, and
- Determine how that personal data is processed.
This role is defined under:
- Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR)
A single processing activity may involve more than one controller — known as joint controllers — where two or more parties jointly determine the purposes and means of processing.
Responsibilities of a Data Controller
While specific obligations depend on the nature and scale of processing, responsibilities commonly include:
- Establishing and documenting a lawful basis for each processing activity
- Providing clear and transparent privacy information to data subjects
- Honouring data subject rights, including access, rectification, erasure, and portability
- Maintaining records of processing activities
- Implementing appropriate technical and organisational security measures
- Appointing a Data Protection Officer (DPO) where required
- Ensuring any Data Processors acting on their behalf are bound by appropriate contractual obligations
- Reporting personal data breaches to the supervisory authority within 72 hours where required
Data Controller vs. Data Processor
These roles are distinct under the GDPR. A Data Controller decides the purpose and means of processing. A Data Processor processes personal data solely on behalf of and under the instruction of a controller. For example, a cloud hosting provider or email marketing platform.
Both roles carry obligations under the GDPR, but the controller bears primary accountability. Where a processor acts outside the controller’s instructions, they may assume controller-level liability for that processing.
Frequently Asked Questions
Yes. An organisation may act as a controller for some processing activities and as a processor for others, depending on the context. For example, a business may control its own customer data while processing employee data on behalf of a third-party payroll provider.
Supervisory authorities can issue warnings, reprimands, and fines of up to €20 million or 4% of total global annual turnover, whichever is higher, depending on the nature and severity of the breach.
Yes, in most cases. Non-EU organisations acting as Data Controllers in relation to EU residents are subject to the GDPR and are generally required to appoint a GDPR Article 27 Representative unless a specific exemption applies.
Need GDPR Representative Services?
Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.
Related Terms
Further Reading