Skip to content
← All terms

Glossary · Privacy & regulation

Data controller

A data controller is the natural or legal person that determines the purposes and means of processing personal data — under GDPR, the controller bears primary responsibility for lawful processing and for honoring data subjects’ rights.

The controller/processor split is the organizing structure of GDPR accountability: whoever decides why data is being processed and how — what fields to collect, what the data will be used for, how long to keep it — is the controller, regardless of whether that organization does the technical processing itself or outsources it. A retailer deciding to run an email marketing campaign and collecting addresses for it is the controller even if it uses a third-party service to actually send the emails.

Controller status carries the heaviest compliance burden: establishing a lawful basis for processing, providing privacy notices, honoring access/erasure/portability requests, conducting data protection impact assessments where required, and — if using a processor — putting a compliant DPA in place. Two organizations can also be joint controllers when they jointly determine the purposes and means of the same processing, which requires its own arrangement clarifying respective responsibilities.

For most of Ciphera’s products, the customer organization using Ciphera ID or Pulse to manage its own end users is typically the controller for that end-user data, with Ciphera acting as processor — the relationship a DPA is meant to formalize.

See also

Related terms