PII Controller
A PII controller is the organization or person that decides why and how personal data (personally identifiable information) is collected and used. In everyday terms, it is the party that makes the key decisions about the processing, rather than simply carrying out instructions on someone else's behalf. Because it holds this decision-making role, it generally carries the primary responsibilities and accountability for that data.
A PII controller is the entity that determines the purposes and means of processing personal data, that is, the 'why' and 'how' of the processing. The term is used in ISO/IEC 27701 and corresponds closely to the concept of a 'data controller' under the EU and UK GDPR, where controllers bear more obligations than processors because they decide what personal data is collected and how it is used. Where two or more entities jointly determine the purposes and means, they may be joint controllers and, under frameworks such as ISO/IEC 27701, are generally expected to determine and agree on their respective roles and responsibilities. The precise classification of an entity as controller or processor depends on the specific facts of the processing arrangement and the applicable legal regime, which are outside the scope of this definition; note also that 'PII' terminology (common in ISO standards and some US contexts) and 'personal data' (used in the GDPR) are not always defined identically across jurisdictions.
Why it matters
The controller designation is the pivot point for accountability in data protection. Because the PII controller decides why and how personal data is processed, it generally carries the primary legal obligations for that processing. Under the EU and UK GDPR, controllers (including joint controllers) have more obligations than processors, precisely because they determine what personal data is collected and how it is used. For cookie consent specifically, this means the organization that decides to deploy analytics, advertising, or other non-essential cookies is typically the party responsible for ensuring a valid lawful basis exists and, where required, that appropriate consent has been obtained.
Misidentifying who acts as controller can create real compliance exposure. An organization that assumes it is merely a processor executing another party's instructions may overlook obligations that actually fall on it as a controller, or fail to put in place the arrangements expected of joint controllers. Under frameworks such as ISO/IEC 27701, joint PII controllers are expected to determine and agree on their respective roles and responsibilities, and the absence of such agreements can leave gaps in accountability. Because the classification depends on the specific facts of the processing arrangement, getting it wrong is not merely a paperwork error but can misplace responsibility for consent, transparency, and data subject rights.
It is worth noting that the precise consequences and the exact scope of controller obligations vary by legal regime, and the terminology itself is not uniform. 'PII' as used in ISO standards and some US contexts and 'personal data' as used in the GDPR are not always defined identically. Organizations operating across jurisdictions should treat controller classification as a fact-specific and jurisdiction-specific question rather than assuming a single global answer.
Who it's relevant to
Inside PII Controller
Common questions
Answers to the questions practitioners most commonly ask about PII Controller.

