Simplified the data controller is the individual or legal person who determines the purposes for which and the means by which personal data is processed.
According to the legal definition in Art. 4 (7) GDPR, the full definition of a data controller is:
” `controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law”
It is also important to note that there can be multiple data controllers that are responsible for the same data processing.