Skip to content
Topic Contested in court

Controllers

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Entities that determine purposes and means of processing

2,849 linked items 83 Laws269 Case Law384 Guidance2017 Enforcement43 News

Overview

28 sources · Aug 27, 2026

Legal Framework

The controller concept is defined in Article 4(7) GDPR, which establishes that a controller is the entity that—alone or jointly with others—determines the purposes and means of processing personal data. This definition is foundational: it triggers the full suite of controller obligations under the GDPR, including accountability under Article 24, transparency duties under Article 12, and the information requirements in Articles 13 and 14.

The Court of Justice confirmed the definitional scope in Schrems II, quoting the GDPR's own language:

"een natuurlijke persoon of rechtspersoon, een overheidsinstantie, een dienst of een ander orgaan die/dat, alleen of samen met anderen, het doel van en de middelen voor de verwerking van persoonsgegevens vaststelt"
— Schrems II ¶10

The definition expressly accommodates joint controllership—where multiple entities together determine purposes and means. Once controller status is established, the entity must comply with transparency obligations: Article 13(1) requires providing identity and contact details at the time data are collected from the subject, while Article 14(1) imposes equivalent duties when data are obtained indirectly. Article 12 frames the manner of delivery:

"The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14"
— GDPR Art. 12(1)

Key Developments

Enforcement authorities have applied controller obligations with increasing rigour, particularly around documentation and information duties. The Danish DPA's action against IDdesign illustrates that controllers face sanctions not only for substantive violations but also for failure to maintain internal accountability records:

"the controller had not adequately documented its personal data deletion procedures"
— IDdesign, Danish DPA

The Polish DPA (UODO) pursued a company processing publicly sourced data for failing to meet Article 14 information obligations, finding that publishing a privacy notice solely on a website was insufficient when data subjects had no direct relationship with the controller. Although a court subsequently annulled the fine on procedural grounds—specifically, the authority's failure to substantiate the number of records affected—the substantive principle survived: controllers obtaining data indirectly must actively reach data subjects, not passively post information online.

The Deutsche Wohnen case further demonstrates that controller liability requires culpability under national law, a question the CJEU addressed in December 2023. The ruling confirmed that while culpability is necessary for fines against legal persons, the GDPR does not preclude member states from establishing attribution mechanisms.

Status of the Debate

The core definition of "controller" under Article 4(7) is settled, but its application to complex data-sharing ecosystems remains actively contested. Courts and DPAs continue to grapple with distinguishing controllers from processors in multi-party arrangements, and with identifying joint controllership in collaborative relationships. The Deutsche Wohnen referral to the CJEU on culpability requirements signals that the intersection of GDPR controller liability and national procedural law is still being defined. What would resolve the open questions is further CJEU guidance on the functional test for controller status—particularly whether influence over purposes and means must be substantive or merely formal—and clearer doctrinal boundaries for joint controllership under Article 26.

Practical Guidance

  • Map your role functionally, not contractually. Controller status turns on who determines purposes and means, not on labels in a contract. Conduct a factual assessment of decision-making authority over each processing activity, referencing Article 4(7).
  • Document accountability measures proactively. As the IDdesign enforcement shows, failure to maintain deletion policies and internal documentation is itself a violation. Establish written procedures for retention, deletion, and data subject rights handling.
  • Fulfill information obligations actively. When processing data obtained indirectly, do not rely on website-only notices. Article 14(1) requires proactive communication to data subjects; the UODO enforcement confirms passive disclosure is insufficient.
  • Clarify joint controllership arrangements. Where multiple entities jointly determine purposes and means, execute an Article 26 agreement allocating responsibilities transparently, and ensure data subjects can identify and contact each controller.
  • Prepare for breach response as a controller duty. EDPB guidance emphasises that controllers must have incident response plans enabling prompt detection, risk assessment, and notification to supervisory authorities where required.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 29 Processing under the authority of the controller or processor Laws GDPR Apr 2016 controller's instruction authority
why this is here
shall not process those data except on instructions from the controller

This provision directly defines the binding nature of controller instructions on processors and their subordinates, a core element of controller control.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 24 Responsibility of the controller Laws GDPR Apr 2016 defines controller obligations
why this is here
the controller shall implement appropriate technical and organisational measures

The provision directly imposes responsibilities on controllers, making it a primary source for the topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Definition and role of controller
why this is here
A controller is a body that decides certain key elements of the processing. Controllership may be defined by law or may stem from an analysis of the factual elements or circumstances of the case.

The document is entirely focused on defining controllers, their determination of purposes and means, and their responsibilities.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Guidance EDPB Apr 2023 main establishment determination
why this is here
In order to establish where the main establishment is, it is firstly necessary to identify the central administration of the controller in the EEA

The document provides detailed guidance on determining the main establishment of a controller for LSA purposes.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 26 Joint controllers Laws GDPR Apr 2016 joint determination of purposes
why this is here
Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.

This provision defines joint controllers as a specific category of controllers, and paragraph 3 allocates rights against each, which is central to the concept of controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 31 Cooperation with the supervisory authority Laws GDPR Apr 2016 Obligation to cooperate
why this is here
The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority

Imposes a direct duty on controllers to assist supervisory authorities in their tasks.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 28 Processor Laws GDPR Apr 2016 controller obligations regarding processors
why this is here
the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures

The provision primarily regulates processors, but it also sets out the controller's duty to select adequate processors, which is directly relevant to controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing Laws GDPR Apr 2016 Imposes obligation on controller
why this is here
The controller shall communicate any rectification or erasure of personal data or restriction of processing

The provision explicitly addresses the controller's role in executing the notification obligation, which is relevant but not the full scope of the topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 79 Right to an effective judicial remedy against a controller or processor Laws GDPR Apr 2016 Court jurisdiction over controllers
why this is here
Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment.

The provision mentions controllers only to specify where proceedings against them must be brought, not to define or regulate their obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 44 General principle for transfers Laws GDPR Apr 2016 Mentions controllers but no substantive rules
why this is here
the conditions laid down in this Chapter are complied with by the controller and processor

The provision mentions controllers only in the context of who must comply, but its core is about transfers, not the definition or obligations of controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 16 Right to rectification Laws GDPR Apr 2016 Controller's obligation to rectify
why this is here
obtain from the controller without undue delay the rectification

Mentions the controller as the party obligated to rectify, but the focus is on the data subject's right, not on defining controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 02/2022 application of Article 60 GDPR Guidelines ·EDPB Guidance EDPB Mar 2022 Controller's role in cross-border processing
why this is here
the controller or processor must have a main or single establishment in the EU

Defines controller but not about controller obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

What Happened to the Risk-Based Approach to Data Transfers? The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute… News Future of Privacy Forum Sep 2022 controller obligations under Art 24
why this is here
the general obligation of the controller of Article 24 would not also apply to obligations of controllers under Chapter V

The document discusses the controller's role in ensuring compliance and the risk-based approach to its obligations, relevant to controller responsibilities.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Dirkzwager: The Council of State provides clarification on the GDPR concept of “the initiation, pursuit, or substantiation of a legal claim” ⇄ > Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele… News Dirkzwager Oct 2022 Controller's obligation to erase
why this is here
Anders had de minister de persoonsgegevens van [appellante] moeten wissen uit stukken die onderdeel zijn van een procesdossier.

The document discusses the controller (minister) and its duty to erase, but the main focus is the exception to that duty.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

CJEU clarifies GDPR principles of purpose limitation and storage limitation ⇄ The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data… News NL EU Court Expert Oct 2022 controller obligations
why this is here
de verwerkingsverantwoordelijke (Digi) in een nieuw opgezette databank persoonsgegevens vastlegt en opslaat

The document refers to Digi as the controller, but the judgment does not focus on the definition or obligations of controllers beyond the principles.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 83 Laws · all 384 Guidance · all 269 Case Law · all 2017 Enforcement · all 51 Literature · all 43 News