Controller

Data protection glossary · 1 minute read

The controller is the natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Obligations of the controller

The controller is the addressee of almost all obligations under the GDPR. It must ensure and be able to demonstrate compliance with the principles (accountability), fulfil data subject rights, take appropriate security measures and notify data breaches.

In companies, the controller is the company itself, not individual employees or departments.

Joint controllership

Where several bodies jointly determine the purposes and means, they are joint controllers and must conclude an arrangement under Art. 26 GDPR. The CJEU took this view, for example, for the operator of a Facebook fan page (judgment of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein).

Art. 4(7) GDPR
Definition of the controller.
Art. 5(2) and Art. 24 GDPR
Accountability and responsibility.
Art. 26 GDPR
Joint controllers.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.