03 · What You Need to Know
Separate Legal Roles From Internal Data Governance Roles
What is a data controller?
Under the EU General Data Protection Regulation, a controller is the natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data. In practical terms, the controller makes the substantive decisions about why personal data are processed and how the processing will occur.
In research conducted through a university, hospital, company, research institute, government agency, or other organization, that organization may be the controller even though individual researchers make many day-to-day decisions about the study.
The University of Edinburgh, for example, explains controller status in terms of an organization's authority to decide how and why personal data are processed, including decisions concerning their use, storage, and deletion. This illustrates why the person physically holding the research file is not necessarily the controller.
The Philippines uses the term personal information controller
The Philippine Data Privacy Act defines a personal information controller as a person or organization that controls the collection, holding, processing, or use of personal information, including one that instructs another person or organization to perform such processing on its behalf.
The Act distinguishes this role from a personal information processor, which is a natural or juridical person to whom a personal information controller may outsource processing of personal data.
The terminology differs somewhat from the GDPR, but the practical lesson is similar: determine who exercises the relevant decision-making authority rather than simply asking who possesses the dataset.
What is a data steward?
Unlike controller, data steward does not have one universal definition across research institutions. It is generally a data-governance role associated with oversight, appropriate use, quality, policy implementation, access, or management across the data lifecycle.
For example, Iowa State University identifies principal investigators as stewards of research data under their control and gives research data stewards responsibilities including managing access, implementing appropriate security, establishing procedures, and selecting dissemination methods.
Western University defines a data steward somewhat differently as a university representative responsible for managing the lifecycle of particular administrative or research data and ensuring that appropriate protection and policies are implemented.
Those definitions overlap, but they are institutional definitions rather than a universal legal definition of stewardship.
What is a data custodian?
Custodian commonly refers to the person or unit responsible for operational or technical management of data. A custodian may implement access controls, maintain systems, provide secure infrastructure, perform backups, manage repositories, or carry out procedures specified by a steward or another responsible authority.
Again, institutions use the term differently. Iowa State describes graduate students, faculty, and staff who possess or control research data as possible custodians. Western University describes custodians more technically as those responsible for processing and storage and for implementing controls specified by the steward. The University of Delaware similarly defines a custodian as an employee or unit with operational responsibility for managing a shared data repository on behalf of a steward.
Terminology Varies
Do not copy another university's definition of "data steward" or "data custodian" into your project and assume it applies locally. These are governance labels whose responsibilities should be verified in your own institution's policies. Legal controller or processor status must be determined separately under the applicable law.
The three roles answer different questions
| Role |
Main question |
Typical focus |
Universal meaning? |
| Controller / Personal Information Controller |
Who determines why and how personal data are processed? |
Legal accountability and substantive processing decisions |
Defined by the applicable data protection law |
| Data Steward |
Who oversees appropriate management and use of the data? |
Governance, policy, access, quality, lifecycle management, or oversight |
No; institutional definitions vary |
| Data Custodian |
Who holds, operates, or technically manages the data or systems? |
Storage, infrastructure, access implementation, backup, security, or operational handling |
No; institutional definitions vary |
A single person or organizational unit can sometimes occupy more than one governance role. Conversely, one dataset may involve several custodians while having one controller, multiple controllers, or joint controllers under the applicable legal framework.
The person holding the file is not necessarily the controller
Suppose a research assistant has a copy of a participant dataset on an approved university system. The assistant possesses and works with the information, but that fact alone does not make the assistant the controller.
Similarly, a university IT department may administer the server and control technical access without determining the research purposes for which the information is processed.
This distinction matters because possession, technical control, governance oversight, and legal decision-making are different forms of control. Everyday language unfortunately uses the word "control" for all of them, which is where the academic paperwork begins to develop its own ecosystem.
The principal investigator is not automatically the controller
A PI may design the protocol, determine variables, supervise collection, and make important research decisions. Nevertheless, institutional research may be conducted under the authority of a university or another organization that is the controller under the applicable framework.
In other circumstances, an individual researcher could potentially be a controller. The answer depends on who actually determines the relevant purposes and means and on the governing law.
Do not infer controller status from authorship, grant leadership, possession of the data, or the title "principal investigator." Verify the institutional arrangement.
What about a data processor?
Controller should also be distinguished from processor. Under the GDPR, a processor processes personal data on behalf of a controller. Under the Philippine Data Privacy Act, the comparable term is personal information processor.
A transcription company, cloud provider, external data-management company, survey platform, or other service provider may act as a processor when it handles personal data only on the controller's instructions. Its role depends on the actual arrangement, not simply on being an external company.
If an external party begins determining its own purposes for processing the information, its legal role may be different. This is one reason the contractual and operational arrangements matter when using commercial cloud services for research data.
Collaborating institutions can complicate the picture
Imagine two universities jointly designing a study, determining which participant data will be collected, and agreeing how the shared dataset will be analyzed. Depending on the applicable framework and actual arrangement, they may be joint controllers.
Now imagine instead that University A designs the study and sends a narrowly defined dataset to University B solely to perform a specified analysis according to University A's instructions. The relationship may be different.
Scientific collaboration does not itself establish the legal data relationship. Before transferring research data between institutions, determine what each institution will actually do with the information.
Why these distinctions matter in practice
Role definitions affect who approves access, establishes safeguards, responds to data-subject requests, negotiates processing agreements, handles security incidents, authorizes sharing, implements retention requirements, and demonstrates compliance.
If roles remain ambiguous, important tasks can fall between them. The PI assumes IT is responsible for access review. IT assumes the PI decides who should retain access. The collaborator assumes the originating institution handled consent. Everyone has a piece of responsibility, yet no one owns the decision.
Clear roles help translate the broader question of who is responsible for protecting personal research data into specific tasks.
04 · A Practical Example
One Dataset Can Involve Several Different Roles
Hypothetical Example
A university research project with centralized storage
A university approves a study involving identifiable interview data. The principal investigator manages the project. The university's research IT service hosts the encrypted repository, and a research assistant uploads transcripts and maintains the study files.
Legal role
After applying the relevant data protection framework and institutional arrangements, the university determines that it is the controller for the research processing.
Stewardship role
Under this hypothetical university's own governance policy, the PI is designated as research data steward and oversees appropriate use, access, and lifecycle decisions.
Custodial role
Research IT acts as technical custodian of the repository, implementing approved access controls, backups, security configurations, and other infrastructure safeguards.
Data user
The research assistant is authorized to work with particular files according to the study protocol and institutional requirements.
No contradiction exists. The university can be the controller while the PI acts as steward and IT performs custodial functions. Those labels describe different dimensions of responsibility.
At another university, however, the steward and custodian labels might be assigned differently. That part of the example cannot simply be copied from one institution to another.