Data controller
Also known as: controller, data owner, information controller, joint controller, organisation responsible for data
A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.
Term explanation
At a glance
The controller is the decision-maker behind an activity involving personal data. It decides the purpose—the reason the information is being used—and the essential means, such as which people and data are involved, how long the activity should continue and who should receive the results.
“Controller” is a legal role, not necessarily a job title. An organisation is often the controller, even though employees make day-to-day decisions on its behalf. Calling a supplier the “data owner” or writing “processor” into a contract does not settle the question. The real arrangement matters more than the label.
In plain language
Ask who decided that the activity should happen. Who selected the objective? Who determines which information is necessary, whose information is used and how the output affects people? Who can stop or materially change the activity? The organisation holding those decisions is likely to be a controller.
A retailer is normally the controller of its customer account records because it decides why the accounts exist and how they operate. A payroll provider may process employee data for the retailer under instructions. The provider can still be a controller for its own independent purposes, such as managing its workforce or meeting obligations that apply directly to it.
Why it matters
Privacy laws place many core responsibilities on controllers. These commonly include using data fairly and for defined purposes, giving people understandable information, choosing and overseeing processors, keeping information secure, responding to rights requests, managing incidents and demonstrating compliance. Jurisdictions may add notification, registration, licensing, representative or officer requirements.
A practical example
A clinic chooses to collect patient contact and health information so it can provide care. It is the controller. It hires a cloud provider to host the records. If the provider stores the information only under the clinic’s documented instructions, it is acting as a processor for that service. The clinic does not transfer its overall accountability simply by outsourcing the technology.
General principles
Controllers, processors and shared decisions
A processor acts for a controller rather than deciding its own purpose for the entrusted data. If a supposed processor begins using the data for an unrelated purpose of its own, its legal role may change for that use.
Sometimes two organisations jointly determine an activity. That does not mean every collaboration creates joint control. The question is whether the parties genuinely share or converge in the important decisions. Clear written arrangements help people understand who handles requests and responsibilities, but the documents should reflect reality.
Practical next steps
For each processing activity, record the controller, purpose, principal decisions, processors, recipients and any joint-controller arrangement. Check contracts against actual practice. If your organisation decides purposes or essential means, do not assume it is merely a processor because another party supplied the data.
Related terms: processor; joint controller; processing; data subject; privacy notice; accountability
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Data processor — processor
- Data subject — data subject
- Privacy notice — privacy notice
- Processing personal data — processing
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 1 of 2025 — Licensing of Data Controllers (CDPG-1-2025-LDC)
CDPG-1-2025-LDC · cites · Read in the Legal Library
- CDPG 5 of 2025 — Licensing of MDAS (CDPG-5-2025)
CDPG-5-2025 · cites · Read in the Legal Library
- SI 155 of 2024 — Licensing of Data Controllers & Appointment of DPOs (SI155)
SI155 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.