Controllers
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Entities that determine purposes and means of processing
Overview
28 sources · Aug 27, 2026Legal Framework
The controller concept is defined in Article 4(7) GDPR, which establishes that a controller is the entity that—alone or jointly with others—determines the purposes and means of processing personal data. This definition is foundational: it triggers the full suite of controller obligations under the GDPR, including accountability under Article 24, transparency duties under Article 12, and the information requirements in Articles 13 and 14.
The Court of Justice confirmed the definitional scope in Schrems II, quoting the GDPR's own language:
"een natuurlijke persoon of rechtspersoon, een overheidsinstantie, een dienst of een ander orgaan die/dat, alleen of samen met anderen, het doel van en de middelen voor de verwerking van persoonsgegevens vaststelt"
— Schrems II ¶10
The definition expressly accommodates joint controllership—where multiple entities together determine purposes and means. Once controller status is established, the entity must comply with transparency obligations: Article 13(1) requires providing identity and contact details at the time data are collected from the subject, while Article 14(1) imposes equivalent duties when data are obtained indirectly. Article 12 frames the manner of delivery:
"The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14"
— GDPR Art. 12(1)
Key Developments
Enforcement authorities have applied controller obligations with increasing rigour, particularly around documentation and information duties. The Danish DPA's action against IDdesign illustrates that controllers face sanctions not only for substantive violations but also for failure to maintain internal accountability records:
"the controller had not adequately documented its personal data deletion procedures"
— IDdesign, Danish DPA
The Polish DPA (UODO) pursued a company processing publicly sourced data for failing to meet Article 14 information obligations, finding that publishing a privacy notice solely on a website was insufficient when data subjects had no direct relationship with the controller. Although a court subsequently annulled the fine on procedural grounds—specifically, the authority's failure to substantiate the number of records affected—the substantive principle survived: controllers obtaining data indirectly must actively reach data subjects, not passively post information online.
The Deutsche Wohnen case further demonstrates that controller liability requires culpability under national law, a question the CJEU addressed in December 2023. The ruling confirmed that while culpability is necessary for fines against legal persons, the GDPR does not preclude member states from establishing attribution mechanisms.
Status of the Debate
The core definition of "controller" under Article 4(7) is settled, but its application to complex data-sharing ecosystems remains actively contested. Courts and DPAs continue to grapple with distinguishing controllers from processors in multi-party arrangements, and with identifying joint controllership in collaborative relationships. The Deutsche Wohnen referral to the CJEU on culpability requirements signals that the intersection of GDPR controller liability and national procedural law is still being defined. What would resolve the open questions is further CJEU guidance on the functional test for controller status—particularly whether influence over purposes and means must be substantive or merely formal—and clearer doctrinal boundaries for joint controllership under Article 26.
Practical Guidance
- Map your role functionally, not contractually. Controller status turns on who determines purposes and means, not on labels in a contract. Conduct a factual assessment of decision-making authority over each processing activity, referencing Article 4(7).
- Document accountability measures proactively. As the IDdesign enforcement shows, failure to maintain deletion policies and internal documentation is itself a violation. Establish written procedures for retention, deletion, and data subject rights handling.
- Fulfill information obligations actively. When processing data obtained indirectly, do not rely on website-only notices. Article 14(1) requires proactive communication to data subjects; the UODO enforcement confirms passive disclosure is insufficient.
- Clarify joint controllership arrangements. Where multiple entities jointly determine purposes and means, execute an Article 26 agreement allocating responsibilities transparently, and ensure data subjects can identify and contact each controller.
- Prepare for breach response as a controller duty. EDPB guidance emphasises that controllers must have incident response plans enabling prompt detection, risk assessment, and notification to supervisory authorities where required.
why this is here
shall not process those data except on instructions from the controller
This provision directly defines the binding nature of controller instructions on processors and their subordinates, a core element of controller control.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the controller shall implement appropriate technical and organisational measures
The provision directly imposes responsibilities on controllers, making it a primary source for the topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
A controller is a body that decides certain key elements of the processing. Controllership may be defined by law or may stem from an analysis of the factual elements or circumstances of the case.
The document is entirely focused on defining controllers, their determination of purposes and means, and their responsibilities.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
In order to establish where the main establishment is, it is firstly necessary to identify the central administration of the controller in the EEA
The document provides detailed guidance on determining the main establishment of a controller for LSA purposes.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.
This provision defines joint controllers as a specific category of controllers, and paragraph 3 allocates rights against each, which is central to the concept of controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority
Imposes a direct duty on controllers to assist supervisory authorities in their tasks.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures
The provision primarily regulates processors, but it also sets out the controller's duty to select adequate processors, which is directly relevant to controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The controller shall communicate any rectification or erasure of personal data or restriction of processing
The provision explicitly addresses the controller's role in executing the notification obligation, which is relevant but not the full scope of the topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment.
The provision mentions controllers only to specify where proceedings against them must be brought, not to define or regulate their obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the conditions laid down in this Chapter are complied with by the controller and processor
The provision mentions controllers only in the context of who must comply, but its core is about transfers, not the definition or obligations of controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
obtain from the controller without undue delay the rectification
Mentions the controller as the party obligated to rectify, but the focus is on the data subject's right, not on defining controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the controller or processor must have a main or single establishment in the EU
Defines controller but not about controller obligations.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the general obligation of the controller of Article 24 would not also apply to obligations of controllers under Chapter V
The document discusses the controller's role in ensuring compliance and the risk-based approach to its obligations, relevant to controller responsibilities.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Anders had de minister de persoonsgegevens van [appellante] moeten wissen uit stukken die onderdeel zijn van een procesdossier.
The document discusses the controller (minister) and its duty to erase, but the main focus is the exception to that duty.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
de verwerkingsverantwoordelijke (Digi) in een nieuw opgezette databank persoonsgegevens vastlegt en opslaat
The document refers to Digi as the controller, but the judgment does not focus on the definition or obligations of controllers beyond the principles.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 83 Laws · all 384 Guidance · all 269 Case Law · all 2017 Enforcement · all 51 Literature · all 43 News