A data controller is a person or organization that determines the use of personal information. The role of the data controller can be shared by many people or organizations.

Rights and responsibilities of data controllers include:

  • establishing a lawful data process and observing the rights of Data subject s (including collecting data subject Consent s and requests)
  • issuing instructions on data processing (including appointing employees to serve as point of contact) for the Data processor – the data processor should handle data exclusively in the manner prescribed by the controller.

Read more about data controller on the Piwik PRO blog and in the resources section:


  • PHI and PII

    HIPAA violations and fines: What healthcare organizations need to know

    Quick summary HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew.  What this guide covers: HIPAA violation…

  • The EDPB’s new data anonymization guidelines: what they mean for your analytics data

    Removing names, cookies and IP addresses is no longer enough to anonymize data. Here’s what the 2026 EDPB framework actually requires for anonymous data collection, what’s still unresolved, and how to configure your analytics to stay compliant while keeping the full view of traffic marketers rely on.