Controller

Clause 6 of the DPA excludes from the definition of “controller” in Article 4 (7) of the GDPR: (1) processors for purposes for which a decree requires personal data to be processed and persons to whom a decree imposes an obligation to process the data, (2) the British Crown and (3) the British Parliament.

Public authority

The terms “public authorities” and “public entities” are governed by Clause 7 of the DPA. Consequently, this is only:

  • an authority within the meaning of the Freedom of Information Act 2000,
  • a Scottish Authority within the meaning of the Freedom of Information (Scotland) Act 2002,
  • and an authority or body designated or described by the Secretary of State in regulations.

Further, an authority or body is only a “public authority” or “public body” in the sense of the GDPR, if it carries out a task in the public interest or in the exercise of the public authority vested in it.