Privacy
Data controller
Also called controller.
Data controller is the party that decides why and how personal data is processed. Under GDPR it carries the main legal duties.
How it is measured
Decide by asking who sets the purpose. The company that chooses to measure its own site's audience is the controller of that analytics data. Two parties can be joint controllers if they decide together.
Look at the contracts and the privacy notice. The notice names the controller and its contact. The agreements with vendors should name who is who.
Worked example
A dental clinic uses an online booking tool. The clinic decides to collect patient names and times, so it is the controller. The tool's vendor stores and sends reminders on its instructions, so it is a processor.
A patient asks for their data. The clinic, not the vendor, answers within one month.
How it differs
A data controller decides purposes. A data processor acts on the controller's instructions. The controller excludes no one from duties; the processor excludes the right to use the data for its own aims.
Common errors
Assuming only large companies are controllers. Calling a vendor a processor when it uses data for itself. Skipping the notice. Having no contact for requests. Missing joint controller duties with a social plugin.
In practice
Write down, for each tool, who decides the purpose. Make sure your notice names you. Check each vendor contract for the right role.