What is a data controller?
A data controller is the organisation, public authority or other party that determines why personal data is processed and the essential means by which the processing takes place. The role is based on actual decision-making power rather than the label used in a contract. A party that decides the purpose, categories of data, affected people and key use of the information is likely to be acting as a controller.
An organisation can be a controller for one activity and a processor for another. For example, a software provider may process customer records on instructions while acting as a controller for its own employee administration, security logs or direct marketing.
What responsibilities does a controller have?
The controller is generally responsible for ensuring that processing has a valid legal basis, is transparent, limited to defined purposes and protected by appropriate security. It must support individual rights, maintain records, apply retention rules and assess high-risk processing. It also needs to choose suitable processors and oversee their performance.
Accountability means the controller should be able to demonstrate these decisions through notices, records of processing, contracts, assessments, approvals and monitoring evidence.
How is a controller identified?
The analysis should examine who initiated the processing, defined the objective, selected the data and decided the essential rules. Funding a service or receiving a result does not automatically determine the role, and contractual wording cannot override the factual relationship.
Where two parties jointly shape the purpose and essential means, they may be joint controllers. Where one party acts only on documented instructions, it may be a processor. Complex platforms and data-sharing arrangements may require a detailed activity-by-activity assessment.
How should controllers manage processors?
Controllers should conduct proportionate due diligence, enter into an appropriate data-processing agreement and maintain visibility over sub-processors, locations, security and deletion. Instructions should be clear and aligned with the real service. Material changes should trigger review.
Using a processor does not transfer all responsibility. The controller remains accountable for selecting the provider, defining permitted processing and responding to individuals and regulators.
Frequently asked questions
Can an individual be a data controller?
Potentially, although purely personal or household activities may be exempt under some laws. Professional or commercial processing can create controller responsibilities.
Is the customer always the controller in a software service?
Often, but not automatically. The provider may be a separate controller for some purposes or may jointly determine certain processing.
Can a controller instruct a processor to do anything?
No. Instructions must be lawful, within the contract and consistent with the stated purpose and applicable obligations.
Does a controller need a data-protection officer?
Only when the relevant legal conditions are met or the organisation chooses to appoint one. The need depends on activities, scale and risk.
Who handles data-subject requests?
The controller remains responsible for the response, although processors may be contractually required to assist with searches, deletion and evidence.



