Controller (Article 4(7), Article 24 GDPR)
The controller as the central figure of the GDPR: the concept and its broad interpretation under Article 4(7), who can be a controller, the obligations under Article 24, and persons acting under the controller's authority pursuant to Article 29 GDPR.
The controller is the central figure of the GDPR. It determines the processing and is made subject to obligations by the Regulation for precisely that reason. All other roles are defined by way of distinction from the controller.
Key takeaways
- A controller is the party that alone determines the purposes and means of a processing operation (Article 4(7) GDPR).
- What is decisive is legal or factual influence over whether processing takes place and over its nature and scope, not a formal designation.
- The role is held by the legal person or body (for example a GmbH (German limited liability company) or a public authority), not by a department or an individual employee.
- The controller bears, in principle, all obligations under the GDPR and must be able to demonstrate compliance with them (Article 24, Article 5(2) GDPR).
- Employees are not controllers in their own right but persons acting under the authority of the controller, who may process data only on instructions (Article 29 GDPR).
1 Concept and scope
1.1 Definition
Under Article 4(7) GDPR, a controller is any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. What is decisive is who, in the exercise of its own decision-making and organizational power, has legal or factual influence over whether processing takes place and over its nature and scope.
The term is interpreted broadly and functionally. What matters is the actual scope for influence, not the designation chosen in the contract. Whoever determines the purpose of a processing operation is a controller, even where that party has no direct access to the data. The concept is explained in full in the reference entry (1.2.7 Controller).
1.2 Who can be a controller
The point of reference is always the organizational unit as a whole, not its internal structure:
- Non-public (private) sector. The controller is the legal person under civil law as such (for example an AG (German stock corporation) or a GmbH). Associations of persons without legal personality, such as the OHG (German general partnership), the KG (German limited partnership), the GbR (German civil-law partnership), registered associations and political parties, also come into consideration. Branches are part of the controlling body and are not controllers in their own right.
- Public sector. The controller is the individual public authority or the independent body governed by public law. The German Federation and the Länder (federal states) as such are not bodies; the relevant unit is the particular authority, institute, school or hospital.
- Not bodies in the legal sense are non-autonomous parts of an organization, that is, sections, divisions or departments. They act for the controlling body but are not themselves controllers.
Within a corporate group there is no group privilege: each group company is a controlling body in its own right, and passing data between them constitutes a disclosure that requires justification, unless, exceptionally, there is processing on behalf of a controller or joint controllership (on the distinction, see 1.2.10 Third party).
2 Obligations of the controller (Article 24 GDPR)
The controller is the principal addressee of the GDPR. Under Article 24(1) GDPR, it must implement appropriate technical and organizational measures, taking the risks into account, in order to carry out the processing in accordance with the Regulation, and it must be able to demonstrate that it has done so. This obligation to demonstrate compliance is the flip side of the accountability principle under Article 5(2) GDPR.
These obligations include, in particular, the choice of a legal basis and compliance with the principles (Articles 5 and 6 GDPR), the provision of information to data subjects and the handling of their requests (Articles 12 to 22 GDPR), the security of processing (Article 32 GDPR), the records of processing activities (Article 30(1) GDPR), the notification of personal data breaches (Articles 33 and 34 GDPR) and, where a high risk is likely, the data protection impact assessment (Article 35 GDPR). These obligations apply to the controller irrespective of whether it carries out the processing itself or has it carried out by a processor.
3 Persons acting under the authority of the controller (Article 29 GDPR)
A person who handles personal data within a company or a public authority and on its behalf is not a controller. The individual employee or civil servant acts for the body and is subject to its authority.
Under Article 29 GDPR, any person acting under the authority of the controller or of the processor who has access to personal data may process those data only on instructions from the controller. Mirroring this, Article 32(4) GDPR obliges the controller to ensure precisely that. Processing by persons acting under its authority is attributed to the body; their deployment requires no separate justification, just as the processing by the body itself does not.
The distinguishing criterion is the right to issue directions: a person acts under the authority of the controller or processor if that person is subject to its instructions, which is typically the case for employees. Anyone standing outside this relationship of instruction is a third party within the meaning of Article 4(10) GDPR. This internal binding to instructions must be distinguished from the external processor: a processor likewise acts on instructions, but it is a separate body with its own obligations and requires a data processing agreement.
Attribution to the body ends where the person acting under its authority exceeds their powers. If an employee processes the data outside the instructions and for their own purposes, for example by using customer data for a private side business or by copying data holdings for themselves without permission, that person no longer acts for the body in that respect but becomes a controller for that processing, with responsibility of their own. However, this relieves the body only to the extent that it has fulfilled its duties of selection, instruction and supervision and has taken appropriate measures under Article 32(4) GDPR; where its organization is inadequate, it remains co-responsible for the incident.
The GDPR prescribes an express commitment to data secrecy only for the processor (confidentiality of the persons deployed, Article 28(3)(b) GDPR). For a controller's own employees, confidentiality follows from the principle of integrity and confidentiality (Article 5(1)(f) GDPR) and from their being bound by instructions; a documented confidentiality commitment from employees is nevertheless good practice.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Controllers and Processors
Overview of the data protection roles under the GDPR: controller, joint controllers, processors, and persons acting under the authority of the controller, the distinction according to purposes and means, the allocation of obligations, and liability.
Joint Controllers (Article 26 GDPR)
When two or more bodies are joint controllers: criteria, categories of cases and CJEU case law, as well as the arrangement on the allocation of obligations under Article 26 GDPR, making its essence available to data subjects and joint and several liability.