Governance & Operations

What is Data Controller?

A data controller is the organization that determines the purposes and means of processing personal data — the 'why' and 'how' — and therefore bears primary legal responsibility for compliance under GDPR and equivalent laws.

The controller/processor distinction, defined in GDPR Article 4, allocates responsibility across the data supply chain. The controller decides why personal data is processed and, in its essential elements, how; everyone processing on the controller's documented instructions is a processor. An eCommerce brand deciding to collect customer emails for marketing is the controller; the email platform sending campaigns on its behalf is a processor.

Controllership follows decisions, not contracts or labels. A vendor agreement calling a party a 'processor' does not survive facts showing it used the data for its own purposes — at that point it became a controller (and possibly an unlawful one). Two organizations that jointly determine purposes and means are joint controllers under Article 26, a status courts have applied expansively: the CJEU has found website operators jointly responsible with Facebook for data collected by an embedded Like button.

The controller's duty list is the long one: establishing a legal basis for each purpose, delivering privacy notices, honoring data subject rights, implementing privacy by design, executing Article 28 contracts with every processor, maintaining records of processing, notifying breaches, and conducting DPIAs for high-risk processing. Controllers answer for their processors' handling of the data, which is why processor due diligence is a controller obligation rather than a courtesy.

US state laws adopted the same architecture — Virginia, Colorado, and most other state statutes use 'controller' and 'processor' explicitly, while California's 'business' and 'service provider' play the equivalent roles. Whatever the vocabulary, the entity deciding why data is used carries the primary duties.

Why it matters for eCommerce

Your brand is the controller for customer and visitor data, even though nearly all processing happens inside third-party SaaS — Shopify, Klaviyo, analytics, ad platforms. That means their handling of your customers' data is your responsibility: DPAs signed, purposes constrained, and special attention to tools whose terms let them use your data for 'their own purposes,' because that clause converts them from processor to independent controller of your customers' data.

Frequently asked questions

How do I know if my company is a controller or a processor?
Ask who decides why the data is processed. If you determine the purposes — building customer profiles, sending marketing, tracking visitors — you are the controller, even if vendors execute everything. If you only process client data under instructions, you are a processor for that data (and controller of your own employee and marketing data).
Can there be more than one controller for the same data?
Yes — joint controllers jointly determine purposes and means, and must allocate responsibilities transparently under GDPR Article 26. Embedded social plugins and co-marketing arrangements are classic joint-controller fact patterns.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms