controller
CIPP/E glossary · Last reviewed: · By Victor Humenhuk (CIPP/E certified)
controller - The natural/legal person, authority, agency or body that, alone or jointly with others, determines the purposes and means of processing personal data (Article 4(7)).
In the CIPP/E body of knowledge, controller comes up under Ch 11.2 - Controller responsibility; Ch 17.2.2 - Controller vs processor; Ch 18.2.1-18.2.2 - Who is who.
controller in context
- Two flashpoints: whether [[IP address|IP addresses]] and [[cookie|cookies]] are [[personal data]] (now clarified - the definition expressly includes ==online identifiers==), and where the boundary between [[controller]] and [[processor]] sits (left unchanged despite the debate). (Introduction to Data Protection Concepts)
- A [[controller]] is the person or body that ==alone or jointly determines the purposes and means== of processing - the ==key decision-maker==, who carries ==most GDPR responsibilities and liability== (information notices, lawful basis, rights, DPIAs, security, breach notification). (Controller vs Processor - Roles and Liability)
- EDPB Guidelines 07/2020 break 'controller' into ==five building blocks==: the ==person/body==; =='determines'==; =='alone or jointly with others'==; =='the purposes and means'==; and =='of the processing of personal data'==. (The Five Building Blocks of 'Controller')
Where controller is covered in the CIPP/E study notes
- Controller vs Processor - Roles and Liability
- Background & the role of consent
- Responsibility of the controller
- Cloud: controllership issues
- Roles of the parties: controller and processor
- Module 3 · Controller vs processor
Related terms
Test yourself on controller
Recognising a definition is not the same as applying it in an exam scenario. Work through the free CIPP/E practice questions, or read the full CIPP/E study guide - every study note is free.