Data Controller
A data controller is the person or organisation that determines the purposes and means of processing personal data. Under UK GDPR, data controllers must register with the ICO (unless exempt), implement appropriate technical and organisational measures to protect data, and ensure individuals can exercise their data rights. Data processors (acting on a controller's instructions) have separate but related obligations.
A data controller determines the purposes and means of processing personal data and bears primary accountability under UK GDPR. Most organisations that collect personal data about customers, employees, or service users are data controllers. Controllers must register with (pay a fee to) the Information Commissioner's Office (ICO) unless exempt, implement appropriate technical and organisational security measures, and ensure individuals can exercise their data rights. A data processor acts only on the controller's documented instructions and must be governed by a written Data Processing Agreement (DPA). Processors have direct obligations under UK GDPR since 2018 (unlike the old Data Protection Act regime). Joint controllers must determine their respective responsibilities by agreement. A common pitfall for small businesses is assuming they are 'just a processor' when they in fact make decisions about data use — misclassification can expose them to fines for failing to meet controller obligations.
What it means in practice. Controller status turns on decision-making, not on who physically holds the data. Ask two questions: why is this data being processed, and how? Whoever answers those is the controller, even if the data sits entirely on someone else's servers. The consequences are substantial. Controllers must provide privacy information, identify a lawful basis, answer subject access requests, report qualifying breaches to the ICO within 72 hours, and keep records of processing activities.
A worked example. A physiotherapy clinic uses a cloud booking platform. The clinic decides what to collect, why, and how long to keep it, so the clinic is the controller. The platform stores and processes the data strictly on the clinic's instructions, so it is the processor, and the relationship must be documented in a written contract covering security, sub-processors, breach notification, and deletion at the end of the contract. When a patient asks for a copy of her records, the request lands on the clinic — it cannot redirect her to the platform. If the platform suffers a breach, it must tell the clinic without undue delay, and the clinic decides whether the ICO and the patients must be told.
Common pitfalls. The commonest is assuming that outsourcing outsources responsibility: it does not, and a controller remains accountable for a processor it chose badly. The second is failing to have a written data processing agreement at all, which is itself a breach. The third is confusing joint controllers with processors — two organisations that jointly decide purposes must agree in writing who handles which obligations, and individuals can enforce their rights against either.
How it relates to other terms. Controller and processor roles are defined by UK GDPR and the Data Protection Act 2018, and both are supervised by the Information Commissioner's Office, to which most controllers must pay an annual data protection fee. The rights that controllers have to service — access, rectification, erasure, restriction, portability, and objection — are described under UK GDPR and subject access request.
What to do next. Work out your role first, then read our data protection guide for the controller obligations that follow. Publish accurate privacy information using privacy policies and cookies, and read UK GDPR for individuals to understand the requests you will have to answer.
Related terms
Related guides
Data Protection Basics for SMEs
Almost every UK business handles personal data — whether collecting customer email addresses, managing employee records, or running a mailing list. UK GDPR and the Data Protection Act 2018 impose legal obligations on all organisations that handle personal data, regardless of size.
7 min
Privacy Policy and Cookies
If your business has a website that collects any personal data — including via analytics, contact forms, or simply cookies — you need compliant privacy and cookie notices. Getting these wrong can attract ICO enforcement and damage customer trust.
5 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min