An organization is always a data controller for its _____________.
Under the DSCI Privacy Framework and consistent with global definitions (including GDPR and APEC), a ''Data Controller'' is the entity that determines the purposes and means of processing personal data. For its own employees, an organization inherently controls how their personal data is collected, used, and stored --- making it the data controller by default. This is not necessarily the case for clients or supervisory authorities, whose data processing may be governed by different contractual or legal terms.
Aimee
16 days ago