Joint Controllers
Joint controllers are two or more organisations that together decide why and how the same personal data is processed. Because they share responsibility for those decisions, each can be held responsible for the processing, and individuals may be able to seek redress against any of them.
Under Article 26 GDPR, joint controllers exist where two or more controllers jointly determine the purposes and means of processing of the same personal data. This joint determination distinguishes them from independent controllers (who separately determine their own purposes and means) and from processors (who act on a controller's instructions); the assessment is fact-specific and turns on who actually influences the purposes and means, not solely on contractual labels. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, subject to the liability and redress provisions of the GDPR. Note that Article 26 also contemplates an arrangement between joint controllers allocating respective responsibilities; the detailed content and effect of such arrangements, and the precise boundary between joint and separate controllership, can depend on the facts and on regulator and case-law interpretation, and readers should verify the position against the current text of Article 26 and applicable guidance.
Why it matters
Joint controllership matters because it changes who bears responsibility when personal data is processed. Where two or more organisations together decide why and how the same personal data is handled, GDPR does not allow either to treat compliance as solely the other's concern. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, which means an individual seeking redress may be able to pursue any one of the joint controllers rather than having to identify and apportion blame among them in advance.
This has practical consequences for how organisations structure collaborations. Because the assessment is fact-specific and turns on who actually influences the purposes and means of processing, contractual labels alone do not settle the question. Parties who describe one another as "controller and processor" may nonetheless be treated as joint controllers if they in fact jointly determine the purposes and means, and this can expose an organisation to responsibilities and potential liability it did not anticipate.
Article 26 GDPR also contemplates an arrangement between joint controllers allocating their respective responsibilities. Getting that allocation wrong, or failing to put one in place, can leave obligations such as responding to data subjects unclear. The detailed effect of such arrangements and the precise boundary between joint and separate controllership can depend on the facts and on regulator and case-law interpretation, so organisations should assess each relationship on its own facts rather than assuming a default position.
Who it's relevant to
Inside Joint Controllers
Common questions
Answers to the questions practitioners most commonly ask about Joint Controllers.