Roles & Responsibilities (DPO, Data Controller, Data Processor)

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Controller-Processor Agreement

A legally required contract outlining responsibilities between a data controller and processor (Article 28(3)).

Data Controller

The entity that determines the purposes and means of processing personal data (Article 4(7)).

Data Processor

An entity that processes personal data on behalf of the data controller (Article 4(8)).

Data Protection Officer (DPO)

A professional appointed to oversee GDPR compliance and advise organizations on data protection (Articles 37–39).

Joint Controllers

Two or more organisations that jointly decide why and how personal data is processed, sharing responsibility for GDPR compliance (Article 26).

Records of Processing Activities (ROPA)

An internal log an organisation keeps recording what personal data it processes, why, and how — a core accountability requirement (Article 30).

Sub-processor

A third party a data processor brings in to help carry out processing on the controller’s behalf, who must be bound by the same data protection obligations (Article 28).

Supervisory Authority (Data Protection Authority)

The independent public body responsible for monitoring and enforcing GDPR in each EU country — in Cyprus, the Office of the Commissioner for Personal Data Protection (Article 51).