A data controller is the entity — person, company, or public authority — that determines the purposes and means of processing personal data. It's defined in GDPR Article 4(7), distinct from a data processor (Article 4(8)) who processes data on the controller's behalf. Controllers carry primary accountability under GDPR: choosing a lawful basis (Article 6), providing transparency notices (Articles 13-14), fulfilling data subject rights, notifying breaches within 72 hours, and appointing a DPO where required. Contract labels don't decide the role — regulators look at who actually decides the purposes and means. Two or more parties can be joint controllers under Article 26.