Controllers
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Entities that determine purposes and means of processing
Overview
21 sources · Jul 15, 2026Legal Framework
The concept of "controller" is defined in Article 4(7) GDPR as the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. This definition is deliberately broad, capturing any entity that exercises decision-making authority over why and how personal data are processed.
Article 24 GDPR places primary responsibility for compliance squarely on the controller—not the processor. The controller must implement appropriate technical and organisational measures to ensure and demonstrate that processing is carried out in accordance with the Regulation. This accountability obligation means the controller must adopt internal policies, impose contractual obligations on processors under Article 28, and maintain documentation sufficient to prove compliance. Article 24(3) further provides that adherence to approved codes of conduct under Article 40 or certification mechanisms under Article 42 serves as an element by which the controller can demonstrate compliance.
Article 29 GDPR reinforces the controller's authority: any person acting under the controller's authority with access to personal data may process those data only on the controller's instructions, unless required to do so by Union or Member State law. Article 26 GDPR expressly contemplates joint controllership—situations where multiple parties together determine purposes and means, as commonly arises in collaborative arrangements.
Key Developments
The CJEU's ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW eV clarified that a controller's transparency obligations extend only to the operations for which that controller actually determines the purposes and means. A party that plays a limited role in processing is not responsible for the entire processing operation but only for the segment it controls. This narrows the scope of accountability for embedded third-party tools and similar arrangements.
In Jehovah's Witnesses, the CJEU held that controllers cannot systematically refuse data subject access requests by invoking the privacy of third parties without examining the specific circumstances. Each request requires individualized assessment.
The Schrems II judgment underscored that controllers transferring data outside the EU must document their transfer impact assessments and suitable safeguards in their Article 30 records, reinforcing the documentation burden on controllers.
Enforcement actions illustrate the consequences of failing to meet controller obligations. The Spanish DPA fined a landlord €1,800 for deploying video surveillance in rental apartments without a sufficient legal basis. The Romanian DPA imposed a €20,000 fine on Tensa Art Design S.A. after the controller obstructed the investigation into its processing activities—demonstrating that failure to cooperate with supervisory authorities compounds liability.
Practical Guidance
Document your role determination: For each processing activity, record whether you act as controller, joint controller, or processor. The Fashion ID ruling confirms that accountability is proportionate to actual decision-making authority over purposes and means.
Establish internal accountability policies: Article 24(1)–(2) requires controllers to implement and be able to demonstrate compliance through documented policies, not ad hoc practices. Certification mechanisms and approved codes of conduct under Articles 42 and 40 can serve as evidence.
Bind processors contractually: Under Article 28, controllers must impose data protection terms on all processors. Liability for compliance failures extends to the controller if processor oversight is inadequate.
Restrict internal access on a need-to-know basis: Article 29 mandates that personnel acting under the controller's authority process data only on instructions. Implement access controls and documented authorization hierarchies.
Prepare individualized responses to data subject requests: Following Jehovah's Witnesses, controllers must assess each access request on its merits rather than applying blanket refusals based on third-party privacy concerns.