Data controllers determine how and why information is processed. Simply put, if an organization determines and controls the processing of information, it is a data controller who is responsible for privacy.
The term has its foundation in the UK Data Protection Act of 1998. GDPR specifically defines the term in Article 4: Data Controller: “’controller’ means the natural or legal person, public authority, agency or other body which alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.”
Data controllers bear the primary responsibility for data subject rights and for data protection as specified by GDPR, regardless if the processing is done by the controller themselves, or contracted out to a data processor.