// THREAT DETECTION AND DATA PRIVACY TERM

Data Controller

A data controller is the organization or individual that determines the purposes and means for processing personal data. They hold the primary responsibility for ensuring data is handled legally and securely.

Data Controller — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

A data controller is a legal entity (person, public authority, agency) that, alone or jointly, determines the purposes and means of processing personal data, bearing primary accountability for compliance with data protection regulations like GDPR and CCPA. The controller is distinct from a data processor, which processes data on the controller's behalf.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Controller
  • Data Owner
  • Responsible Party
  • Data Fiduciary
  • PII Controller
  • Information Controller

USAGE NOTE

The distinction between a controller and a processor is a critical legal concept that dictates responsibility and liability for data breaches and non-compliance.

DEVELOPERS

Organizations developing technology related to Data Controller.

  • OneTrust

    Develops a privacy, security, and governance platform that helps organizations operationalize compliance with regulations like GDPR. The software automates tasks essential for data controllers, including data mapping, consent management, and handling data subject access requests (DSARs).

  • BigID

    Provides an AI-powered data intelligence platform for privacy, security, and governance. Their technology helps data controllers automatically discover, classify, and manage sensitive and personal data across their entire data landscape, from cloud to on-premises systems.

  • Varonis

    Offers a data security platform that protects sensitive information from cyber threats. Their technology provides data controllers with visibility and control over their data by automating permissions management, monitoring data activity, and detecting anomalous behavior.

  • Microsoft

    Develops Microsoft Purview, a unified data governance and compliance solution. It provides a suite of tools for data discovery, classification, data loss prevention (DLP), and risk management, enabling data controllers to manage and protect their data across hybrid and multi-cloud environments.

  • Securiti.ai

    Offers an AI-powered platform for unified data controls across privacy, security, and governance. The technology helps data controllers automate key obligations such as DSAR fulfillment, data discovery, consent management, and breach notifications.

  • Collibra

    Provides a Data Intelligence platform focused on data governance, cataloging, and quality. Their technology enables data controllers to establish a system of record for their data, define policies, and understand data lineage to ensure responsible management.

  • Immuta

    Develops an automated data access control and security platform. Their technology allows data controllers to enforce granular, attribute-based access policies on cloud data, ensuring that data is only accessed for its intended and authorized purpose.

  • TrustArc

    Provides a suite of privacy management solutions designed to help organizations manage compliance and risk. Their platform offers tools for data inventory and mapping, risk assessments, and consent management, supporting the core operational needs of a data controller.

RELATED TERMS IN COMPLIANCE & PRIVACY