What is a controller?

Who is a controller under the GDPR? This article explains the functional concept of controller, why titles and contracts are not determinative, how controllers are identified in practice, and why determining the purposes and means of processing is the key test.

What is a controller?
Key Point: Controllers are individuals or entities that, alone or in jointly with others, determine the purposes and the means of the processing of personal data. controller status is determined by what an individual or entity actually does—not by what it calls itself or what its contracts or privacy policy may say. If it looks like a controller and acts like a controller, it is a controller.

The first and foremost role of the concept of controller is to determine who shall be responsible for compliance with data protection rules, and how data subjects can exercise the rights in practice. Controllers are primarily responsible for overall compliance with GDPR and for demonstrating that compliance. If this isn’t achieved, they may be liable to pay damages in legal proceedings or be subject to fines or other penalties or corrective measures. Since the controller determines the “means and purposes” of the processing, in effect all provisions setting conditions for lawful processing are essentially addressed to the controller, even if this is not always clearly expressed. The provisions on the rights of the data subject (e.g. to information, access, rectification, erasure and blocking, etc.) under data protection law are framed in such a way as to create obligations for the controller. The controller is also central in the provisions on notifications to data subjects (e.g. privacy notices) and supervisory authorities (e.g. in data breach situations). Finally, it should be no surprise that the controller is also held liable, in principle, for any damage resulting from unlawful processing.

  • The concept of controller under GDPR is autonomousAlthough in some cases the capacity to determine the means and purposes stems from legal provisions that normally imply a certain responsibility (e.g. the employer in relation to data on his employees, the publisher in relation to data on subscribers, the association in relation to data on its members or contributors) the concept of controller is autonomous and should be interpreted mainly according to data protection law. Other — sometimes colliding or overlapping — concepts in other fields of law are not determinative. For example, being a right holder for intellectual property does not exclude the possibility of qualifying as “controller” as well and thus be subject to the obligations stemming from data protection law.
  • The concept of controller under GDPR is functional in the sense that it is intended to allocate responsibilities where the factual influence is, and thus based on a factual rather than a formal analysis.

The definition is composed of closely interrelated building blocks:

“Individuals or entities” refers to a broad series of subjects, which can play the role of controller, ranging from natural to legal persons and including any other entity or individual. For companies and organizations, preference is given to consider as controller the organization itself to ensure the entity is ultimately held responsible for the processing and the obligations stemming from data protection legislation.

“Alone or joint with others” refers to situations where a single processing operation involves a number of parties that jointly determine the purposes and means of processing.In such cases each of the entities acting as co- controllers is subject to the obligations imposed by data protection law on controllers. Contractual arrangements can be useful in assessing joint control, but should always be checked against the factual circumstances of the relationship between the parties.

  • A broad variety of typologies for joint control exists and their legal consequences vary. Where a joint controller is not able to directly fulfill all controller’s obligations it will remain ultimately responsible for them.

“Determine the means and purposes” refers to the activities that, if performed, will render an individual or organization a controller. Determination of controller-ship is based on factual circumstances. It is irrelevant whether the decision to process was “lawful” or whether a formal appointment as controller took place. This approach ensures that, even in those cases where data is processed unlawfully, a controller can be easily found and held responsible for the processing.

ICO “Cheat-Sheet” (Link provided in resources below)

Dictionaries define “purpose” as “an anticipated outcome that is intended or that guides your planned actions” and “means” as “how a result is obtained or an end is achieved”“Means” does not only refer to the technical ways of processing personal data, but also to questions like “which data shall be processed”“which third parties shall have access to this data”, “when data shall data be deleted”, etc. In other words, determining the purposes and the means amounts to determining respectively the “why” and the “how” of certain processing activities. The crucial question is therefore to which level of details somebody should determine purposes and means in order to be considered as a controller (and in correlation to this, which is the margin of maneuver allowed for a data processor). This can be a difficult line to draw in practice (for a post GDPR EU perspective on this see Every vendor wants to be … a data controller!?).

Concept of ‘controller’ across different jurisdictions

The concept of controller has a remarkable track record of being defined in a consistent manner across most jurisdictions that have enacted data protection laws.’

Although the definition and the interpretation tends to be consistent, in practice, where the line between acting as controller and acting as processor is blurry, different data protection authorities can come to different conclusions for identical factual patterns.

Examples

NOTE: All examples below are based on A29WP and EDPB guidelines

Example: Telecom operators - Where a message containing personal data is transmitted by means of a telecommunications or electronic mail service, the sole purpose of which is the transmission of such messages, the controller in respect of the personal data contained in the message will normally be considered to be the person from whom the message originates, rather than the person offering the transmission services; (…) nevertheless, those offering such services will normally be considered controllers in respect of the processing of the additional personal data necessary for the operation of the service. The provider of telecommunications services should therefore, in principle, be considered controller only for traffic and billing data, and not for any data being transmitted.

Example: Email transmission by internet service provider - An entity providing a client with access to a communication network cannot be considered as data controller where it neither initiates the data transmission nor selects the addressees or modifies the information contained in the transmission.

Example: Mail marketing- Company ABC enters into contracts with different organisations to carry out its mail marketing campaigns and to run its payroll. It gives clear instructions (what marketing material to send out and to whom, and who to pay, what amounts, by what date etc). Even though the organisations have some discretion (including what software to use) their tasks are pretty clearly and tightly defined and though the mailing house may offer advice (e.g. advising against sending mailings in August) they are clearly bound to act as ABC instructs. Moreover, only one entity, the Company ABC, is entitled to use the data which are processed — all the other entities have to rely on the legal basis of Company ABC if their legal ability to process the data is questioned. In this case it is clear that the company ABC is the data controller and each of the separate organisations can be considered as a processor regarding the specific processing of data carried out on its behalf.

Example: Company referred to as data processor but acting as controller - Company MarketinZ provides services of promotional advertisement and direct marketing to various companies. Company GoodProductZ concludes a contract with MarketinZ, according to which the latter company provides commercial advertising for GoodProductZ customers and is referred to as data processor. However, MarketinZ decides to use GoodProducts customer database also for the purpose of promoting products of other customers. This decision to add an additional purpose to the one for which the personal data were transferred converts MarketinZ into a data controller for this processing operation.

Example: Secret monitoring of employees - A member of the board of a company decides to secretly monitor the employees of the company, even though this decision is not formally endorsed by the board. The company should be considered as controller and face the possible claims and liability with regard to the employees whose personal data have been misused. The liability of the company is notably due to the fact that as a controller, it has the obligation to ensure compliance with security and confidentiality rules. Misuse by a functionary of the company or an employee could be considered as the result of inappropriate security measures. This is irrespective of whether at a later stage also the member of the board or other natural persons within the company may be considered liable, both from a civil law perspective — also towards the company — as well as from a criminal law perspective. This could be the case e.g. if the board member made use of collected data for extorting personal favours from employees: he would have to be considered as ‘controller’ and be liable concerning this specific use of data.

Example: Installing video-surveillance cameras - The owner of a building concludes a contract with a security company, so that the latter installs some cameras in various parts of the building on behalf of the controller. The purposes of the video-surveillance and the way the images are collected and stored are determined exclusively by the owner of the building, which therefore has to be considered as the sole controller for this processing operation.

Example: Headhunters - Company Headhunterz Ltd helps Enterprize Inc in recruiting new staff. The contract clearly states that “Headhunterz Ltd will act on behalf of Enterprize and in processing personal data acts as a data processor. Enterprize is the sole data controller”. However, Headhunterz Ltd is in an ambiguous position: on the one hand it plays the role of a controller towards the job seekers, on the other hand it assumes to be processor acting on behalf of the controllers, such as Enterprize Inc and other companies seeking staff trough it. Furthermore, Headhunterz — with its famous value-added service “global matchz” — looks for suitable candidates both among the CVs received directly by Enterprize and those it already has in its extensive database. This ensures that Headhunterz, which according to the contract is paid only for contracts actually signed, enhances the matching between job offers and job seekers, thus increasing its revenues. From the elements above, it can be said that, in spite of the contractual qualification, Headhunterz Ltd shall be considered as a controller, and as controlling jointly with Enterprize Inc at least those sets of operations relating to Enterprize recruitment.

Resources:

EDPS Guidelines on the concepts of controller, processor and joint controllership under Regulation (EU) 2018/1725. November 7, 2019

Article 29WP Opinion on the concept of Controller and Processor 169/2010

ICO Report: Data controllers and data processors: what the difference is and what the governance implications are

EDPB Guidelines on the concept of controller and processor (2020)

Controller-processor and clinical research projects

UKRI (Medical research council) guidance

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe