Laws · GDPR ·art-4-par-7 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
How it connects
Cited by
- Guidelines 01/2022 on data subject rights - Right of access
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 8/2020 on the targeting of social media users
All 109
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- VB v Natsionalna agentsia za prihodite
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Rb. Den Haag - C/09/689833
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Can the GPC standard eliminate consent banners in the EU?
- AKI (Estonia) - No. 2.1-1/24/397-890-38
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- Generative AI and data protection
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Belgian DPA: Roularta Media Group violated cookie consent rules
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- CNIL (France) - SAN-2022-026
- LG Köln - 28 O 168/22
- HDPA (Greece) - 54/2024
- Personvernnemnda (Norway) - 2018-14 (15/01355)
- CNIL (France) - SAN-2021-023
- Guidelines on processing of personal data through blockchain technologies
- Opinion 27/2024 on the Brand Compliance criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 19/2024 on the EuroPrise criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- Opinion 04/2024 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR
- Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria
- Report of the work undertaken by the supervisory authorities within the 101 Taskforce
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
- EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- EDPB Annual Report 2018
- X v Russmedia Digital SRL and Inform Media Press SRL
- Philippe Latombe v European Commission
- Amt der Tiroler Landesregierung v Datenschutzbehörde
- MK v K GmbH
- Agentsia po vpisvaniyata v OL
- ND v DR
- MK v WB
- SO
- IAB Europe v Gegevensbeschermingsautoriteit
- Österreichische Datenschutzbehörde v WK
- État belge v Autorité de protection des données
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- Gesamtverband Autoteile-Handel e.V. v Scania CV AB
- Proceedings brought by J.M
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- TU and RE v Google LLC
- Proximus NV v Gegevensbeschermingsautoriteit
- OT v Vyriausioji tarnybinės etikos komisija
- VQ v Land Hessen
- DSB (Austria) - 2026-0.043.390
- NAIH (Hungary) - NAIH-11443-3/2026
- AEPD (Spain) - PS-00140-2025
- HDPA (Greece) - 33/2020
- HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate
- CJEU - C‑313/23, C‑316/23 and C‑332/23 - Inspektorat kam Visshia sadeben savet
- DSB (Austria) - 2025-0.950.759
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- BGH - VI ZR 97/22
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- DSB (Austria) - D123.768/0004-DSB/2019
- DSB (Austria) - 2025-1.049.138
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- BAG - 8 AZR 169/25
- NAIH (Hungary) - NAIH-4462-5-2026
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB: No processor access violation under Art. 15 GDPR when controller deleted data
- DSB (Austria) - DSB-D124.5337
- Federal Administrative Court: retention of job applicant data for potential legal claims
- HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR
- AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- BVwG - W137 2334047-1
- VG Munich: university may be GDPR controller for professors' editorial work emails
- AEPD (Spain) - ps-00256-2025
- Persónuvernd (Iceland) - 2025010364
- BVwG - W292 2292202-1
- BVwG - W292 2298015-1
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Den Haag District Court: 51 gamblers sue Unibet operator Risepoint over unanswered GDPR
- BVwG - W298 2314952-1
- Cyprus court upholds €5,000 DPA fine on Pancyprian Judo Federation for Article 31 GDPR
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- European Commission v Hungary
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- CNIL fines EXTIA for failing to properly handle job applicant erasure requests
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
- AEPD (Spain) - ps-00287-2025
Related across sources
C-231/22 État belge v Autorité de protection des données In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court… Third Chamber Jan 11, 2024 Controllers Personal Data Public Authority
C-638/23 Amt der Tiroler Landesregierung v Datenschutzbehörde In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt… Eighth Chamber Feb 27, 2025 Public Authority Controllers Personal Data
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-683/21 Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija The CJEU Grand Chamber issued a preliminary ruling in Case C-683/21, arising from a dispute between Lithuania's National Public Health Centre (NVSC) and the State Data Protection… Grand Chamber Dec 5, 2023 Controllers Personal Data Public Authority
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction