Examples
Worked examples
- Is an instance
A university is the controller for processing personal data of cohort participants it has recruited and consented under its own ethics approval.
- Is an instance
Two universities running a joint clinical study sign a joint-controller agreement under Article 26 specifying their respective responsibilities for transparency and data-subject requests.
Counter-examples
Looks similar, but isn't
- Not an instance
A cloud-storage provider hosting research data on infrastructure-as-a-service terms and acting only on documented instructions is a processor, not a controller.
- Not an instance
A statistical analyst engaged purely to run queries on a controller's behalf under instructions is not a controller.
Editorial commentary
The controller is the entity accountable for compliance with the GDPR's principles in Article 5(2) and bears primary obligations including providing transparency information, securing a lawful basis, ensuring data-subject rights, maintaining records of processing, conducting DPIAs where required, notifying breaches, and appointing a Data Protection Officer where applicable. The controller relationship is determined by the factual circumstances of who decides the why and how of the processing, not by what the parties choose to label themselves in a contract. In multi-institutional research, parties may be separate controllers (each determining their own purposes) or joint controllers under Article 26 (where they jointly determine purposes and means).
Determining who is a controller turns on who decides the purposes (why) and essential means (how) of the processing — not on funding source, physical custody of the data, or who is named as principal investigator in a grant agreement. A frequent research error runs the other way: a lead institution assumes it is automatically the sole controller for a multi-site study, when in practice each participating site that makes its own recruitment, retention, or local-analysis decisions may be a separate or joint controller in its own right. Under Article 26, joint controllers must set out, in a transparent arrangement, their respective responsibilities for the GDPR’s obligations — particularly for handling data-subject requests and providing transparency information — and the essence of that arrangement must be made available to data subjects. Being a joint controller does not divide legal liability: each joint controller remains fully, and independently, responsible for compliance with its own obligations.
References
- GDPR Regulation (EU) 2016/679 Article 4(7) and Article 26 joint controllers
- European Data Protection Board Guidelines 07/2020 on the concepts of controller and processor
- UK Information Commissioner's Office Guidance on Controllers and Processors
Also known as
controller · GDPR controller · data-protection controller
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Data controller"
vocab-term-identifier="https://casrai.org/dictionary/term/data-controller" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/data-controller",
"name": "Data controller",
"identifier": "https://casrai.org/dictionary/term/data-controller",
"description": "The natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data, as defined in Article 4(7) of the GDPR.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/data-controller",
"sameAs": [
"controller",
"GDPR controller",
"data-protection controller"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-05-21T02:22:53",
"dateModified": "2026-08-23T05:31:19",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







