Skip to main content

Controller

Under GDPR, the party that determines the purposes and means of processing personal data. An organization can be a controller for data it collects directly and remain a controller, or a joint controller, for data it receives from a vendor or partner if it also determines how that incoming data is used, meaning it cannot outsource its own lawful basis obligations to the supplier.

Defined in 2 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Data Governance: The Data Chair

Under GDPR, the party that determines the purposes and means of processing personal data. An organization can be a controller for data it collects directly and remain a controller, or a joint controller, for data it receives from a vendor or partner if it also determines how that incoming data is used, meaning it cannot outsource its own lawful basis obligations to the supplier.

AI Governance: Applied Mastery

Under the GDPR, the natural or legal person that determines the purposes and means of processing personal data. The controller is responsible for carrying out the DPIA. A public agency running its own scoring system is the controller of that processing.

AI Data Governance: The Data Chair

Under GDPR, the organization that decides why and how personal data is processed. Controllers must maintain the fuller Article 30(1) record, including purposes, lawful bases, and retention periods.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.