The controller is the natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Obligations of the controller
The controller is the addressee of almost all obligations under the GDPR. It must ensure and be able to demonstrate compliance with the principles (accountability), fulfil data subject rights, take appropriate security measures and notify data breaches.
In companies, the controller is the company itself, not individual employees or departments.
Joint controllership
Where several bodies jointly determine the purposes and means, they are joint controllers and must conclude an arrangement under Art. 26 GDPR. The CJEU took this view, for example, for the operator of a Facebook fan page (judgment of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein).
Legal provisions
- Art. 4(7) GDPR
- Definition of the controller.
- Art. 5(2) and Art. 24 GDPR
- Accountability and responsibility.
- Art. 26 GDPR
- Joint controllers.