Governance

controller (responsable de traitement)

Entity determining purposes and means of processing personal data.

Definition

The natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data; responsible for ensuring compliance with legal bases, data subject rights, security measures, record-keeping and interaction with the CNIL. The law adopts the GDPR-aligned definition while preserving national statutory references.