Data Controller
Under the GDPR, a data controller is the person, company, public authority, agency, or other body that determines the purposes and means of processing personal data.
In practical terms, the controller decides why personal data is processed and the essential elements of how that processing takes place.
For example, an employer that collects employee information for payroll, benefits, and HR administration will generally act as the controller for that processing.
Controllers have significant obligations, including establishing a lawful basis, providing transparency, respecting data subject rights, applying appropriate safeguards, and ensuring that processors handle personal data according to applicable requirements.
