Data controller
The person or organisation that decides why and how personal data is processed, alone or jointly with others, and so carries primary accountability for that processing under the GDPR.
Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP
GDPR Article 4(7) defines the controller as the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The controller needs a lawful basis, must respect data subject rights, and under Article 5(2) must be able to demonstrate compliance. Where two organisations decide purposes and means together, Article 26 makes them joint controllers.
The controller is paired with the data processor, which Article 4(8) defines as the body processing personal data on the controller’s behalf. A payroll bureau running a client’s payroll is typically a processor, and the employer is the controller. Article 28 requires the relationship to be governed by a contract, the data processing agreement, and a processor that starts deciding purposes and means for itself is treated as a controller for that processing. The controller is also distinct from the data owner: the owner is an internal accountability role for any data set, while the controller is a legal role that applies to personal data.
Exam relevance: a scenario is likely to describe an outsourcing arrangement and ask which party carries accountability. Candidates are expected to keep accountability with the controller when processing is outsourced, and to recognise that a processor that starts deciding the purposes and means of processing is treated as a controller for that processing.