What is a data controller?
Under the GDPR, a data controller is “the natural or legal person, public authority, agency or other body which alone or jointly with others, determines the purposes and means of the processing of personal data”.
So the determining factor here is control, rather than possession. In plain English, the data controller is the person (or organisation) that decides why and how personal data is processed. They control the data but don’t necessarily store or process it, although they are responsible for how it’s used, stored and deleted.
What is a data processor?
A data processor, on the other hand, is “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”.
This could include something as simple as storing the data on a third party’s server, but also includes for example payroll companies, CRM, email marketing agencies, accountants and market research businesses.