Controller (Article 4(7) GDPR)
Whoever determines the purposes and means of processing is a controller and the central party bound by the obligations of the GDPR: definition, distinction from processor and joint controllership, case groups.
A controller is the party that, alone or jointly with others, determines the purposes and means of the processing of personal data (Article 4(7) GDPR). The GDPR attaches its obligations to this party: the controller is the central addressee of the norms, to whom the obligations under Chapter IV (from Article 24 GDPR onward) are addressed.
Key takeaways
- A controller is the party that determines the whether (purposes) and the how (means) of a processing operation, whether a natural person, legal person, public authority, or other body (Article 4(7) GDPR).
- The term is to be interpreted broadly so that the protection of data subjects remains effective and comprehensive.
- The controller is the central party bound by the obligations of the GDPR; responsibility can be delegated only to a limited extent and is not extinguished by the appointment of a data protection officer.
- Where several parties jointly determine the purposes and means, they are joint controllers (Article 26 GDPR); a party that processes solely on instructions on behalf of another is a processor.
- There is no corporate-group data protection: the corporate group as such is not a controller; each undertaking is considered individually.
1. Overview
1.1 Legal definition and function
Under Article 4(7) GDPR, the controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, that law may itself designate the controller or the specific criteria for its nomination.
What matters is decision-making power over two dimensions: over the purposes of the processing (the "why") and over the means (the "how," in particular the essential decisions on the nature and scope of the procedures used). Whoever actually makes these decisions is the controller, regardless of whether that party physically holds the data itself.
1.2 Broad interpretation
The term is to be understood broadly in order to ensure effective and comprehensive protection of data subjects. The classification follows actual decision-making power, not a formal designation in contracts. This broad interpretation is the reason why the case law has also classified as controllers actors who themselves have no access to the collected data (see Section 4 below).
1.3 Central party bound by the obligations, no corporate-group privilege
The central obligations of the GDPR attach to the controller, such as accountability (Article 5(2) GDPR), the general obligations under Article 24 GDPR, and the record of processing activities under Article 30 GDPR. The GDPR does not recognize any corporate-group data protection: the corporate group as such is not a controller. What is always decisive is the individual undertaking that determines the purposes and means. Even economically affiliated undertakings that process data in a shared database cannot invoke a corporate-group privilege.
2. Who can be a controller
2.1 Bodies and acting natural persons
Any natural or legal person, public authority, agency, or other body can be a controller. In the case of legal persons and public authorities, the body itself is the controller; in addition, however, the organs acting on its behalf are also controllers in their function. At a public authority, the head of the authority acts; at a GmbH (German limited liability company), the management; at an Aktiengesellschaft (German stock corporation), the management board.
2.2 Limited delegability
Responsibility can be delegated only to a limited extent. In particular, it is not waived by the controller's appointment of a data protection officer. The data protection officer advises and monitors, but does not assume the position of the controller and does not step into the controller's obligations in its place.
2.3 Insolvency administrator
Upon the opening of insolvency proceedings, the right to administer and dispose of the assets belonging to the insolvency estate passes to the insolvency administrator (Section 80(1) of the German Insolvency Code (InsO)). The insolvency administrator thereby becomes the controller for the processing of the personal data belonging to the estate. In the case of preliminary insolvency administration, a distinction must be drawn according to whether a strong or a weak preliminary administrator has been appointed, because the power of disposal, and thus controllership, follows from this.
A professional legal guardian (Betreuer) is likewise a controller for the processing of personal data in the course of the guardianship. It is disputed whether a university or an individual university lecturer is a controller within the scope of the constitutionally protected freedom of research; here the circumstances of the individual case must be assessed.
3. Distinction from other roles
The most important question in practice is not whether someone handles data, but in what role. Whoever determines the purposes and means is a controller. A party that processes solely on instructions on behalf of another is a processor. Where several parties decide jointly, joint controllership exists (see Section 4).
| Criterion | Controller | Joint controllers | Processor |
|---|---|---|---|
| Decision on purposes and means | alone | jointly with others | no, bound by instructions |
| Legal basis of the role | Article 4(7) GDPR | Article 26 GDPR | Article 4(8), Article 28 GDPR |
| Relationship to one another | independent | coordinated allocation of obligations | data processing agreement |
| Access to the data required | no | no | as a rule yes |
The following diagram shows the key decision point in the allocation of roles.
A party that is a recipient of the data without determining its processing falls under recipient; a body outside the controller's sphere of responsibility may at the same time be a third party.
4. Joint controllers
4.1 Requirements
Where two or more controllers jointly determine the purposes and means of the processing, they are joint controllers (Article 26(1) GDPR). The degree of each party's responsibility is to be assessed according to the circumstances of the individual case; the actors involved may be involved at different stages of the processing and to different extents. Joint controllership can also arise without a formal arrangement, solely on the basis of actual cooperation. In particular, no equal or equally strong contribution is required.
4.2 Obligation to allocate tasks
Joint controllers must determine which of them fulfills which obligations under the GDPR. This concerns above all the exercise of data subject rights and the fulfillment of the information obligations under Articles 13 and 14 GDPR. This allocation should be set out transparently in an arrangement; however, the absence of such an arrangement does not in itself render the processing unlawful (CJEU, judgment of 4 May 2023, C-60/22, Federal Republic of Germany).
5. Case groups from the case law
The broad interpretation of the concept of the controller is shown particularly clearly in the case law of the CJEU. It has decided a number of constellations in which controller status was not readily apparent.
5.1 Search engines and online platforms
The operator of a search engine processes personal data from third-party web pages and is the controller for this; it is also the correct addressee for delisting requests (CJEU, judgment of 13 May 2014, C-131/12, Google Spain).
The operator of a fan page on a social network is, jointly with the network, responsible for the processing of visitor data, because through the selection and parameters of the statistics functions it participates in determining the purposes and means; its own access to the data is irrelevant (CJEU, judgment of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein).
A party that embeds a social plugin into its own website and thereby enables the collection and transmission of visitor data to the plugin provider is jointly responsible for that collection and transmission (CJEU, judgment of 29 July 2019, C-40/17, Fashion ID).
5.2 Controllership without one's own data access
A religious community that organizes and coordinates a preaching activity of its members is responsible for the data collected in the process, even if it itself has no access to the collected data (CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses). This decision makes clear that controller status attaches to the decision on purposes and means, not to physical control over the data.
5.3 Parliaments, bodies, and municipal authorities
Parliaments are controllers; the GDPR is applicable to their activities, and a general exclusion under Article 2(2) GDPR does not apply. This also applies to petitions committees and parliamentary committees of inquiry. In this regard, a distinction must be drawn between purely administrative and parliamentary tasks. Municipal council groups are controllers and non-public (private) bodies. An expert appraisal committee under Section 192 of the German Building Code (BauGB) is a controller.
For works councils and staff councils, national law determines the controller: under Section 79a of the German Works Constitution Act (BetrVG), the employer, and under Section 69 of the German Federal Staff Representation Act (BPersVG), the agency (Dienststelle), is the controller for the processing carried out by the respective body. However, this does not relieve the body of its own duty to fulfill obligations. The staff council must, on its own responsibility, ensure the technical and organizational measures under Articles 24 and 32 GDPR.
The fact that national law designates the employer or the agency as the controller does not shift the entire operational responsibility. Works councils and staff councils remain themselves obligated for the security of the data they process (Articles 24 and 32 GDPR).
5.4 Registers and provision online by public authorities
Bodies that make data available online can be joint controllers. Thus, register courts, together with the joint judicial portal of the Länder (German federal states) and the Company Register (Unternehmensregister), can be joint controllers in the online provision of register data.
6. Joint processing operations
Beyond the classic constellations, there are large-scale joint processing operations in which several bodies or Member States participate in one system. At the Union level, these include, for example, the Schengen Information System and the Visa Information System; comparable at the national level is the police information system.
For these systems, attention must be paid to the applicable legal framework in each case. The Central Register of Foreign Nationals (Ausländerzentralregister) falls under the GDPR, whereas purely police systems for criminal law enforcement are subject to Directive (EU) 2016/680 and therefore fall outside the direct scope of the GDPR.
7. Cross-references
Processor (Article 4(8) GDPR)
Processing on instructions on behalf of another and its distinction from the controller.
Recipient (Article 4(9) GDPR)
A body to which data are disclosed without necessarily determining the processing.
Third party (Article 4(10) GDPR)
Persons and bodies outside the controller's sphere of responsibility.
Record of processing activities
Article 30 GDPR: the controller's central documentation obligation.
CJEU Fashion ID (C-40/17)
Joint controllership when embedding social plugins.
CJEU Jehovah's Witnesses (C-25/17)
Controllership without one's own access to the collected data.
CJEU C-60/22 (BAMF)
Consequences of a missing Article 26 arrangement and an incomplete record.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Filing System (Article 4(6) GDPR)
Article 4(6) GDPR defines the filing system as any structured set of personal data which are accessible according to specific criteria. In the case of manual processing, this concept is the decisive threshold for the material scope of the GDPR.
Processor (Article 4(8) GDPR)
A processor is any body that processes personal data on behalf of the controller. The GDPR establishes the processor's own obligations and independent liability.