Skip to main content
Category: Controller & Processor Roles

Arrangement Between Joint Controllers

Also known as: Joint Controller Arrangement, Joint Controllership Agreement
Simply put

When two or more organisations together decide why and how personal data is processed, they are joint controllers and are generally expected to put an arrangement in place setting out their agreed roles and responsibilities. This helps clarify which party handles which obligations, including how individuals can exercise their rights. The specific form and content of the arrangement depend on the circumstances and should be checked against the current legal text and regulatory guidance.

Formal definition

An arrangement between joint controllers is the instrument through which two or more controllers who jointly determine the purposes and means of processing allocate their respective responsibilities for compliance. Under Article 26 GDPR, where two or more controllers jointly determine the purposes and means of processing they are joint controllers by means of an arrangement between them. Guidance from regulators such as the ICO indicates that, in contrast to a controller-processor relationship, a joint controller relationship does not require a contract but does require a transparent arrangement setting out the agreed roles, including in relation to data subjects' rights and transparency obligations. The scope and required content of such arrangements can be subject to regulatory interpretation and case law, and practitioners should verify the precise requirements against the current official text of Article 26 GDPR (and the UK GDPR equivalent, where relevant) and applicable regulatory guidance.

Why it matters

Where two or more organisations genuinely determine together why and how personal data is processed, GDPR treats them as joint controllers rather than as independent controllers or as a controller and processor. Getting this classification right matters because it shapes who owes which compliance obligations, how those obligations are divided, and how individuals can enforce their rights. The Court of Justice of the EU has, in a line of case law, taken a relatively broad view of when parties jointly determine purposes and means, so organisations cannot assume they fall outside joint controllership simply because their involvement is partial or indirect. The precise boundaries continue to be shaped by regulatory interpretation and case law and should be verified against current sources.

A well-drafted arrangement reduces ambiguity about which party responds to access, erasure, and other data subject requests, who provides transparency information, and who takes the lead on particular compliance duties. Without such an arrangement, parties risk gaps or overlaps in responsibility, disputes about accountability, and difficulty demonstrating compliance to a regulator. It is important to note, however, that under Article 26 GDPR data subjects may generally exercise their rights against any of the joint controllers regardless of how responsibilities are allocated internally; the arrangement governs the relationship between the controllers but does not necessarily limit an individual's ability to approach whichever controller they choose.

Because the required scope and content of these arrangements can be subject to regulatory interpretation, organisations should treat the arrangement as a living compliance instrument rather than a one-off formality. The distinction between joint controllers and other relationships (such as separate controllers processing the same data, or a controller-processor relationship) is often finely balanced and fact-specific, so practitioners should assess each relationship on its facts and against the current official text of Article 26 GDPR and applicable guidance.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads are typically responsible for identifying when a relationship amounts to joint controllership and ensuring a transparent arrangement is put in place. They generally need to map how responsibilities are allocated, how data subject rights and transparency obligations are handled, and how the arrangement is documented as part of the organisation's accountability record, checking the position against current Article 26 requirements and guidance.
Privacy and commercial lawyers
Lawyers advising on collaborations, platforms, and data-sharing arrangements often need to determine whether the parties are joint controllers, separate controllers, or in a controller-processor relationship, since each carries different documentation requirements. They generally draft or review the arrangement between joint controllers, distinguishing it from a controller-processor contract, and advise on the fact-specific and evolving nature of the classification under case law and guidance.
Business and partnership owners
Teams that build joint offerings, co-branded services, or shared data initiatives with other organisations are often the ones whose activities create joint controllership. They typically need to engage early with legal and privacy colleagues to confirm the relationship type, because how purposes and means are decided in practice can determine whether an Article 26 arrangement is required.
Individuals and data subjects
The arrangement is relevant to individuals because Article 26 GDPR is generally understood to allow data subjects to exercise their rights against any of the joint controllers, irrespective of the internal allocation of responsibilities. Transparency about the essence of the arrangement is intended to help individuals understand who is processing their data and how to enforce their rights.

Inside Arrangement Between Joint Controllers

Determination of Respective Responsibilities
The core of the arrangement allocates responsibilities between the joint controllers for compliance with data protection obligations, in particular regarding the exercise of data subject rights and the provision of information under Article 13 and Article 14. This allocation reflects the joint controller relationship recognised under Article 26 GDPR, which arises where two or more controllers jointly determine the purposes and means of processing.
Contact Point Provision
The arrangement may designate a contact point for data subjects. This does not remove the ability of data subjects to exercise their rights against each controller, as Article 26 generally allows data subjects to exercise their rights in respect of and against each of the joint controllers irrespective of the internal allocation.
Essence Made Available to Data Subjects
The essence of the arrangement is generally required to be made available to data subjects so they understand the broad allocation of roles. The internal arrangement itself need not typically be published in full, but its key elements should be transparent.
Legal Basis and Purpose Alignment
Because joint controllers jointly determine purposes and means, the arrangement operates against a shared or coordinated processing purpose. Each controller remains responsible for having an appropriate Article 6 legal basis (and an Article 9 condition where special category data is involved), which the arrangement does not itself supply.
Distinction from a Processor Instrument
An Article 26 joint controller arrangement is distinct from an Article 28 Data Processing Agreement, which governs the controller-to-processor relationship. It is also distinct from a Data Protection Impact Assessment under Article 35. Conflating these instruments is a common source of error.

Common questions

Answers to the questions practitioners most commonly ask about Arrangement Between Joint Controllers.

Does having a joint controller arrangement mean each party is only responsible for its own part of the processing?
No. While the arrangement should set out the respective responsibilities of each joint controller for compliance, this internal allocation does not, by itself, limit each controller's accountability toward data subjects and supervisory authorities. Under the GDPR's joint controllership provisions, data subjects can generally exercise their rights against each of the joint controllers, regardless of how responsibilities were divided in the arrangement. The allocation governs the internal relationship and helps clarify who does what, but it does not shield a party from external liability. You should verify the precise position against the current text of the Regulation and applicable regulatory guidance.
Is a joint controller arrangement the same thing as a Data Processing Agreement (DPA) under Article 28?
No, these are distinct instruments addressing different relationships. A joint controller arrangement governs the relationship between two or more controllers who jointly determine the purposes and means of processing. A DPA under Article 28 governs the relationship between a controller and a processor acting on the controller's behalf. Because the roles differ, the required content and legal function of each instrument differ as well. Mislabeling one as the other can misstate the parties' actual roles and obligations. Where a relationship is unclear, the roles should be assessed on the facts of who determines purposes and means rather than on the label used.
What should a joint controller arrangement typically address in practice?
In most cases the arrangement should transparently set out the respective responsibilities of each party for compliance, in particular regarding the exercise of data subject rights and the provision of the required information to data subjects. It commonly addresses which party handles specific rights requests, how information notices are delivered, points of contact, and how the parties coordinate on security, breach handling, and record-keeping. The exact required elements and the extent to which the essence of the arrangement must be made available to data subjects should be confirmed against the current Regulation text and relevant supervisory authority guidance, as interpretations can vary.
How do the parties determine whether they are actually joint controllers before drafting an arrangement?
Joint controllership typically arises where two or more parties jointly determine the purposes and means of a processing operation. This is a fact-based assessment, and case law from the Court of Justice of the European Union has interpreted the concept broadly in certain circumstances, sometimes finding joint controllership even where parties do not have equal influence over every stage. Before drafting, the parties should map the specific processing activities, identify who influences purposes and means for each, and document the reasoning. Because the boundary between joint controllership, separate controllership, and controller-processor relationships can be uncertain, this analysis should be revisited as processing evolves and checked against current guidance.
How should the arrangement handle data subject rights requests between the parties?
The arrangement should generally specify how the parties coordinate to respond to rights requests, including which party takes the lead for particular requests and how they support one another. However, this internal allocation does not prevent a data subject from exercising rights against any of the joint controllers. A practical approach is to define clear intake points, response timelines that allow the overall statutory deadlines to be met, and escalation procedures. The specific handling should reflect the actual division of processing responsibilities and be tested for workability, and the parties should confirm applicable timelines and obligations against the current Regulation text.
How does a joint controller arrangement interact with legal bases and, where relevant, special category data?
Each joint controller must still ensure there is an appropriate legal basis under Article 6 for the processing for which it is responsible; the arrangement itself does not create or substitute for a legal basis. Where the processing involves special category data, an additional condition under Article 9 is also required in addition to an Article 6 basis. The arrangement can help clarify which party is responsible for establishing and documenting these, but it does not remove the underlying requirement. Because legal bases must be assessed for each purpose and can vary with the facts, and because member state derogations may affect the position, these points should be assessed case by case and verified against the current text.

Common misconceptions

The internal arrangement between joint controllers limits or overrides a data subject's ability to exercise their rights against either party.
The allocation of responsibilities is an internal matter. Under Article 26, data subjects may generally exercise their rights in respect of and against each of the joint controllers, regardless of how the arrangement divides tasks between them.
A joint controller arrangement is the same as, or can be replaced by, a Data Processing Agreement.
An Article 26 arrangement governs relationships where parties jointly determine purposes and means of processing, whereas an Article 28 Data Processing Agreement governs a controller-processor relationship. The two address different roles and are not interchangeable; using the wrong instrument can misstate the parties' actual roles.
Signing a joint controller arrangement makes the parties fully compliant and jointly and severally responsible in an identical way for all obligations.
The arrangement allocates responsibilities but does not by itself establish full compliance, which is context and risk dependent. The precise consequences of joint controllership, including liability towards data subjects and supervisory authorities, depend on the arrangement, the facts of the processing, and applicable interpretation, and readers should verify the position against current official text and guidance.

Best practices

Confirm that the relationship is genuinely one of joint controllership, meaning the parties jointly determine purposes and means, before relying on an Article 26 arrangement rather than an Article 28 Data Processing Agreement or another instrument.
Clearly allocate responsibilities in the arrangement, in particular for handling data subject rights requests and for providing the information required under Article 13 and Article 14.
Make the essence of the arrangement available to data subjects in a transparent manner, even where the full internal document is not published.
Ensure each joint controller identifies and documents an appropriate Article 6 legal basis, and an additional Article 9 condition where special category data is processed, since the arrangement does not supply these.
Designate a contact point where helpful, while recognising that data subjects can generally still exercise their rights against each controller regardless of the internal allocation.
Review the arrangement periodically and against the current official GDPR text and relevant regulator guidance, noting that interpretation of joint controllership can evolve and may vary between supervisory authorities.