Data Controller
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The entity that determines purposes and means of processing personal data
Overview
21 sources · Jul 15, 2026Legal Framework
The data controller is defined under Article 4(7) GDPR as the entity that, alone or jointly with others, determines the purposes and means of processing personal data. This functional definition turns on decision-making authority over why and how data is processed, not on formal labels or contractual designations. Article 24 GDPR places primary responsibility on the controller for compliance with the data protection principles set out in Article 5, and requires the controller to implement appropriate technical and organisational measures to demonstrate that compliance — the accountability principle.
Article 24(2) clarifies that the controller, not the processor, bears responsibility for adherence to these principles. The controller must be able to evidence compliance, which implies implementing internal policies and, where processors are engaged, imposing binding obligations on them through Article 28 contracts. Article 24(3) recognises that adherence to approved codes of conduct under Article 40 or certification mechanisms under Article 42 can serve as legitimate means to demonstrate compliance.
Article 26 GDPR addresses joint controllership — situations where two or more entities jointly determine purposes and means. The definition expressly accommodates this scenario, which arises particularly in collaborative arrangements. Joint controllers must arrange their respective responsibilities in a transparent manner, though each remains individually accountable.
Article 29 GDPR reinforces the hierarchical structure: anyone acting under the authority of the controller or processor — including employees — may only process data on the controller's instructions, unless legally compelled otherwise. A processor that begins determining its own purposes and means for a given processing operation reclassifies as a controller for that operation, as confirmed in the doctrinal analysis and prior WP29 guidance.
Key Developments
The CJEU's ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW eV established that a controller's information obligations under Articles 13–14 GDPR extend only to the operations for which it actually determines purposes and means — not to the entire processing ecosystem. This narrows the scope of responsibility for entities with partial or limited control over processing, but requires precise delineation of each party's role.
In Jehovah's Witnesses, the CJEU held that access rights cannot be systematically denied on privacy grounds without examining the specific circumstances, reinforcing that controllers must assess requests individually rather than applying blanket refusals.
The Schrems II decision underscored that controllers transferring data outside the EU remain responsible for assessing whether third-country legal frameworks provide adequate protection, even where the Commission has adopted an adequacy decision. This places an active monitoring burden on controllers.
Enforcement actions illustrate practical failures. The Spanish AEPD fined a landlord €1,800 for deploying video surveillance in rental apartments without a sufficient legal basis — a reminder that controllership can arise in low-complexity contexts. The Romanian DPA fined Tensa Art Design S.A. €20,000 after the controller obstructed investigation into its processing activities, highlighting that controllers must cooperate with supervisory authorities and maintain demonstrable compliance records.
Practical Guidance
Map your role per processing operation: Controller status is determined functionally. Document, for each processing activity, who determines purposes and means — do not rely on contractual labels. Where a processor begins making autonomous decisions about processing, reclassify it as a controller for that operation.
Implement accountability infrastructure under Article 24: Maintain internal policies, data protection measures, and records that evidence compliance with Article 5 principles. Approved codes of conduct or certification mechanisms can serve as demonstrable compliance tools.
Delineate joint controllership arrangements under Article 26: Where collaboration involves shared determination of purposes and means, execute a transparent arrangement allocating responsibilities, and ensure data subjects can identify each controller's role.
Scope information obligations precisely: Following Fashion ID, limit Article 13–14 disclosures to the operations you actually control, but ensure those disclosures are provided at the point of data collection.
Assess transfer risks actively: Post-Schrems II, controllers must independently evaluate third-country safeguards and cannot rely solely on Commission adequacy decisions.