Back to Glossary
Privacy Glossary

Data Controller

An entity that determines the purposes and means of processing personal data.

GDPRLGPDPIPEDA

Full Definition

Under GDPR and similar frameworks, a Data Controller is a natural or legal person who determines why (the purpose) and how (the means) personal data is processed. Controllers bear primary accountability for compliance — they must establish a lawful basis, respond to data subject rights, conduct DPIAs, maintain processing records, and ensure any processors they appoint offer sufficient guarantees. In India's DPDP Act, the equivalent concept is the 'Data Fiduciary'. Controllers can be distinguished from processors, who only process data on behalf of and under instructions from a controller.

Automate your privacy program

TruePrivacy handles DSRs, consent management, data mapping, and breach response — all in one platform.