Data controller
The person or organisation that decides why and how personal data is processed (GDPR Article 4(7)).
The controller carries the primary responsibility under the GDPR: it needs a lawful basis for each processing, answers data subjects’ requests and must be able to demonstrate compliance. When it hands processing to a vendor, it may use only processors that give sufficient guarantees, and must bind them by contract (Article 28(1) and (3)).
For a B2B SaaS company, the customer is usually the controller of the data in the product, and the SaaS company the controller of its own business data, such as billing records.
Source: GDPR Art. 4(7) ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.