Arrangement Between Joint Controllers
When two or more organisations together decide why and how personal data is processed, they are joint controllers and are generally expected to put an arrangement in place setting out their agreed roles and responsibilities. This helps clarify which party handles which obligations, including how individuals can exercise their rights. The specific form and content of the arrangement depend on the circumstances and should be checked against the current legal text and regulatory guidance.
An arrangement between joint controllers is the instrument through which two or more controllers who jointly determine the purposes and means of processing allocate their respective responsibilities for compliance. Under Article 26 GDPR, where two or more controllers jointly determine the purposes and means of processing they are joint controllers by means of an arrangement between them. Guidance from regulators such as the ICO indicates that, in contrast to a controller-processor relationship, a joint controller relationship does not require a contract but does require a transparent arrangement setting out the agreed roles, including in relation to data subjects' rights and transparency obligations. The scope and required content of such arrangements can be subject to regulatory interpretation and case law, and practitioners should verify the precise requirements against the current official text of Article 26 GDPR (and the UK GDPR equivalent, where relevant) and applicable regulatory guidance.
Why it matters
Where two or more organisations genuinely determine together why and how personal data is processed, GDPR treats them as joint controllers rather than as independent controllers or as a controller and processor. Getting this classification right matters because it shapes who owes which compliance obligations, how those obligations are divided, and how individuals can enforce their rights. The Court of Justice of the EU has, in a line of case law, taken a relatively broad view of when parties jointly determine purposes and means, so organisations cannot assume they fall outside joint controllership simply because their involvement is partial or indirect. The precise boundaries continue to be shaped by regulatory interpretation and case law and should be verified against current sources.
A well-drafted arrangement reduces ambiguity about which party responds to access, erasure, and other data subject requests, who provides transparency information, and who takes the lead on particular compliance duties. Without such an arrangement, parties risk gaps or overlaps in responsibility, disputes about accountability, and difficulty demonstrating compliance to a regulator. It is important to note, however, that under Article 26 GDPR data subjects may generally exercise their rights against any of the joint controllers regardless of how responsibilities are allocated internally; the arrangement governs the relationship between the controllers but does not necessarily limit an individual's ability to approach whichever controller they choose.
Because the required scope and content of these arrangements can be subject to regulatory interpretation, organisations should treat the arrangement as a living compliance instrument rather than a one-off formality. The distinction between joint controllers and other relationships (such as separate controllers processing the same data, or a controller-processor relationship) is often finely balanced and fact-specific, so practitioners should assess each relationship on its facts and against the current official text of Article 26 GDPR and applicable guidance.
Who it's relevant to
Inside Arrangement Between Joint Controllers
Common questions
Answers to the questions practitioners most commonly ask about Arrangement Between Joint Controllers.