Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Who Is the Data Controller, Data Custodian, or Data Steward in a Research Project?

Data controller, data custodian, and data steward can describe very different responsibilities. Controller is a legally defined role in many privacy frameworks, while custodian and steward are usually institution-specific governance roles.

311
Controller, Custodian, and Steward Guide 311 of 398
01 · The Question

Three Data Roles, but Do They Mean the Same Thing?

Your data management plan identifies the principal investigator as the "data steward." The university's IT unit is called the "data custodian." Your privacy documentation says the university is the "data controller." Who, then, is actually responsible for the research data?

All three labels may be correct because they describe different kinds of responsibility. The problem begins when researchers assume that controller, custodian, and steward are interchangeable titles.

They are not. A data controller or personal information controller is a legally defined role under particular data protection frameworks. Data steward and data custodian are commonly used data-governance roles, but their definitions vary between institutions. You need to know which vocabulary you are using before assigning responsibilities.

02 · The Short Answer

The Controller Is a Legal Role; Steward and Custodian Usually Are Governance Roles

In Brief

A data controller determines the purposes and essential means of processing personal data, while data steward and data custodian usually describe internal governance or operational responsibilities whose precise meanings depend on the institution.

Do not identify the controller merely by looking for whoever is called the steward or custodian. Determine the legal role from the applicable data protection framework and actual decision-making, then use your institution's own definitions for stewardship and custodianship.

03 · What You Need to Know

Separate Legal Roles From Internal Data Governance Roles

What is a data controller?

Under the EU General Data Protection Regulation, a controller is the natural or legal person, public authority, agency, or other body that determines the purposes and means of processing personal data. In practical terms, the controller makes the substantive decisions about why personal data are processed and how the processing will occur.

In research conducted through a university, hospital, company, research institute, government agency, or other organization, that organization may be the controller even though individual researchers make many day-to-day decisions about the study.

The University of Edinburgh, for example, explains controller status in terms of an organization's authority to decide how and why personal data are processed, including decisions concerning their use, storage, and deletion. This illustrates why the person physically holding the research file is not necessarily the controller.

The Philippines uses the term personal information controller

The Philippine Data Privacy Act defines a personal information controller as a person or organization that controls the collection, holding, processing, or use of personal information, including one that instructs another person or organization to perform such processing on its behalf.

The Act distinguishes this role from a personal information processor, which is a natural or juridical person to whom a personal information controller may outsource processing of personal data.

The terminology differs somewhat from the GDPR, but the practical lesson is similar: determine who exercises the relevant decision-making authority rather than simply asking who possesses the dataset.

What is a data steward?

Unlike controller, data steward does not have one universal definition across research institutions. It is generally a data-governance role associated with oversight, appropriate use, quality, policy implementation, access, or management across the data lifecycle.

For example, Iowa State University identifies principal investigators as stewards of research data under their control and gives research data stewards responsibilities including managing access, implementing appropriate security, establishing procedures, and selecting dissemination methods.

Western University defines a data steward somewhat differently as a university representative responsible for managing the lifecycle of particular administrative or research data and ensuring that appropriate protection and policies are implemented.

Those definitions overlap, but they are institutional definitions rather than a universal legal definition of stewardship.

What is a data custodian?

Custodian commonly refers to the person or unit responsible for operational or technical management of data. A custodian may implement access controls, maintain systems, provide secure infrastructure, perform backups, manage repositories, or carry out procedures specified by a steward or another responsible authority.

Again, institutions use the term differently. Iowa State describes graduate students, faculty, and staff who possess or control research data as possible custodians. Western University describes custodians more technically as those responsible for processing and storage and for implementing controls specified by the steward. The University of Delaware similarly defines a custodian as an employee or unit with operational responsibility for managing a shared data repository on behalf of a steward.

Terminology Varies

Do not copy another university's definition of "data steward" or "data custodian" into your project and assume it applies locally. These are governance labels whose responsibilities should be verified in your own institution's policies. Legal controller or processor status must be determined separately under the applicable law.

The three roles answer different questions

Role Main question Typical focus Universal meaning?
Controller / Personal Information Controller Who determines why and how personal data are processed? Legal accountability and substantive processing decisions Defined by the applicable data protection law
Data Steward Who oversees appropriate management and use of the data? Governance, policy, access, quality, lifecycle management, or oversight No; institutional definitions vary
Data Custodian Who holds, operates, or technically manages the data or systems? Storage, infrastructure, access implementation, backup, security, or operational handling No; institutional definitions vary

A single person or organizational unit can sometimes occupy more than one governance role. Conversely, one dataset may involve several custodians while having one controller, multiple controllers, or joint controllers under the applicable legal framework.

The person holding the file is not necessarily the controller

Suppose a research assistant has a copy of a participant dataset on an approved university system. The assistant possesses and works with the information, but that fact alone does not make the assistant the controller.

Similarly, a university IT department may administer the server and control technical access without determining the research purposes for which the information is processed.

This distinction matters because possession, technical control, governance oversight, and legal decision-making are different forms of control. Everyday language unfortunately uses the word "control" for all of them, which is where the academic paperwork begins to develop its own ecosystem.

The principal investigator is not automatically the controller

A PI may design the protocol, determine variables, supervise collection, and make important research decisions. Nevertheless, institutional research may be conducted under the authority of a university or another organization that is the controller under the applicable framework.

In other circumstances, an individual researcher could potentially be a controller. The answer depends on who actually determines the relevant purposes and means and on the governing law.

Do not infer controller status from authorship, grant leadership, possession of the data, or the title "principal investigator." Verify the institutional arrangement.

What about a data processor?

Controller should also be distinguished from processor. Under the GDPR, a processor processes personal data on behalf of a controller. Under the Philippine Data Privacy Act, the comparable term is personal information processor.

A transcription company, cloud provider, external data-management company, survey platform, or other service provider may act as a processor when it handles personal data only on the controller's instructions. Its role depends on the actual arrangement, not simply on being an external company.

If an external party begins determining its own purposes for processing the information, its legal role may be different. This is one reason the contractual and operational arrangements matter when using commercial cloud services for research data.

Collaborating institutions can complicate the picture

Imagine two universities jointly designing a study, determining which participant data will be collected, and agreeing how the shared dataset will be analyzed. Depending on the applicable framework and actual arrangement, they may be joint controllers.

Now imagine instead that University A designs the study and sends a narrowly defined dataset to University B solely to perform a specified analysis according to University A's instructions. The relationship may be different.

Scientific collaboration does not itself establish the legal data relationship. Before transferring research data between institutions, determine what each institution will actually do with the information.

Why these distinctions matter in practice

Role definitions affect who approves access, establishes safeguards, responds to data-subject requests, negotiates processing agreements, handles security incidents, authorizes sharing, implements retention requirements, and demonstrates compliance.

If roles remain ambiguous, important tasks can fall between them. The PI assumes IT is responsible for access review. IT assumes the PI decides who should retain access. The collaborator assumes the originating institution handled consent. Everyone has a piece of responsibility, yet no one owns the decision.

Clear roles help translate the broader question of who is responsible for protecting personal research data into specific tasks.

04 · A Practical Example

One Dataset Can Involve Several Different Roles

Hypothetical Example

A university research project with centralized storage

A university approves a study involving identifiable interview data. The principal investigator manages the project. The university's research IT service hosts the encrypted repository, and a research assistant uploads transcripts and maintains the study files.

Legal role After applying the relevant data protection framework and institutional arrangements, the university determines that it is the controller for the research processing.
Stewardship role Under this hypothetical university's own governance policy, the PI is designated as research data steward and oversees appropriate use, access, and lifecycle decisions.
Custodial role Research IT acts as technical custodian of the repository, implementing approved access controls, backups, security configurations, and other infrastructure safeguards.
Data user The research assistant is authorized to work with particular files according to the study protocol and institutional requirements.

No contradiction exists. The university can be the controller while the PI acts as steward and IT performs custodial functions. Those labels describe different dimensions of responsibility.

At another university, however, the steward and custodian labels might be assigned differently. That part of the example cannot simply be copied from one institution to another.

05 · What Researchers Often Get Wrong

Common Mistakes When Assigning Research Data Roles

Misconception

Is the Data Steward Automatically the Data Controller?

No. Steward is usually an institutional governance role, while controller is determined under the applicable data protection framework. One entity could potentially perform both functions, but one title does not establish the other.

Misconception

Is Whoever Stores the Data the Controller?

No. Storage or possession does not by itself establish controller status. A technical custodian or processor may store enormous amounts of personal data without determining the purposes for which those data are processed.

Misconception

Is the Principal Investigator Always the Data Steward?

No universal rule says so. Some universities explicitly designate PIs as stewards of research data, while other institutions use different governance structures. Check your own policy.

Misconception

Is "Data Custodian" a Legal Privacy Role?

Not generally in the same sense as controller or processor under frameworks such as the GDPR. Custodian is commonly an organizational governance or operational term. Its precise responsibilities depend on the institution using it.

Misconception

Can You Determine Roles From the Research Protocol Alone?

Not always. The protocol may describe responsibilities, but legal roles depend on the actual processing arrangements and applicable law. Contracts, institutional policies, collaboration arrangements, and operational practices may also need to be examined.

06 · What This Means for You

Define Roles by Function Before Assigning Labels

Instead of beginning with titles, begin with decisions and tasks. Map who determines the purposes of processing, who makes essential decisions about how processing occurs, who manages the dataset, who operates the infrastructure, who approves access, and who merely uses the information for authorized work.

A simple role-mapping framework

If a person or organization determines the purposes and essential means of personal-data processing
Assess controller or personal information controller status under the applicable law.
If an external party processes personal data only on another party's instructions
Assess whether it is a processor and whether the required contractual arrangements are in place.
If someone oversees appropriate use, lifecycle management, policy, or access
Check whether your institution defines that function as data stewardship or uses another term.
If someone operates storage, infrastructure, access controls, or other technical safeguards
Check whether your institution defines that function as custodianship or assigns it differently.

Record the result in the project's data management and governance documentation. If another institution or service provider becomes involved later, reassess the relationship rather than assuming the original role map still applies.

07 · A Quick Checklist

Before Assigning Research Data Roles

Confirm that you have identified:
Who determines why the personal data are processed.
Who makes the essential decisions about how that processing occurs.
Who processes information only on another party's instructions.
How your own institution defines data steward, data custodian, data owner, and any related governance roles.
Who approves access and who technically implements that access.
Whether collaborating institutions independently or jointly determine processing purposes and means.
Whether role assignments are documented in the data management plan, agreements, or other appropriate governance records.
08 · Frequently Asked Questions

Common Questions About Research Data Roles

Is the principal investigator the data controller?

Not automatically. In institutional research, a university, hospital, sponsor, company, or another organization may be the controller. Determine the role from actual decision-making and the applicable data protection framework.

Is a data steward legally responsible for the data?

A steward may have substantial institutional responsibilities, but the title itself does not establish legal controller status. The meaning of stewardship depends on the organization's governance framework.

Can the PI be both a steward and custodian?

Potentially, if the institution defines and assigns the roles that way. Some governance frameworks allow one person to perform multiple functions. That does not automatically determine the person's legal role under data protection law.

Is a cloud provider a data custodian or processor?

Potentially both descriptions could be used in different frameworks. "Custodian" might describe an institutional or operational function, while processor has a specific legal meaning under applicable data protection law. Determine the provider's legal role from what it actually does with the personal data.

Can two universities both be controllers?

Yes. Depending on the arrangement, they might be separate controllers or joint controllers. Joint controllership under GDPR-style frameworks depends on jointly determining the purposes and means of the relevant processing.

Which definition of data custodian should I use?

Use the definition adopted by your institution or governing research framework. There is no universal research definition that can safely replace local policy.

09 · The Bottom Line

Do Not Let Similar-Sounding Titles Blur Different Responsibilities

The Bottom Line

A controller is defined by applicable data protection law and substantive decision-making, while data steward and data custodian are usually institution-specific governance roles concerned with oversight and operational management.

Map what each person or organization actually decides and does before assigning labels. Most importantly, never assume that being called the steward, custodian, PI, or data owner automatically establishes who the legal controller is.

10 · Sources and Further Reading

Authoritative Sources on Research Data Roles

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes