Skip to main content
Category: Controller & Processor Roles

Joint Controllers

Simply put

Joint controllers are two or more organisations that together decide why and how the same personal data is processed. Because they share responsibility for those decisions, each can be held responsible for the processing, and individuals may be able to seek redress against any of them.

Formal definition

Under Article 26 GDPR, joint controllers exist where two or more controllers jointly determine the purposes and means of processing of the same personal data. This joint determination distinguishes them from independent controllers (who separately determine their own purposes and means) and from processors (who act on a controller's instructions); the assessment is fact-specific and turns on who actually influences the purposes and means, not solely on contractual labels. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, subject to the liability and redress provisions of the GDPR. Note that Article 26 also contemplates an arrangement between joint controllers allocating respective responsibilities; the detailed content and effect of such arrangements, and the precise boundary between joint and separate controllership, can depend on the facts and on regulator and case-law interpretation, and readers should verify the position against the current text of Article 26 and applicable guidance.

Why it matters

Joint controllership matters because it changes who bears responsibility when personal data is processed. Where two or more organisations together decide why and how the same personal data is handled, GDPR does not allow either to treat compliance as solely the other's concern. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, which means an individual seeking redress may be able to pursue any one of the joint controllers rather than having to identify and apportion blame among them in advance.

This has practical consequences for how organisations structure collaborations. Because the assessment is fact-specific and turns on who actually influences the purposes and means of processing, contractual labels alone do not settle the question. Parties who describe one another as "controller and processor" may nonetheless be treated as joint controllers if they in fact jointly determine the purposes and means, and this can expose an organisation to responsibilities and potential liability it did not anticipate.

Article 26 GDPR also contemplates an arrangement between joint controllers allocating their respective responsibilities. Getting that allocation wrong, or failing to put one in place, can leave obligations such as responding to data subjects unclear. The detailed effect of such arrangements and the precise boundary between joint and separate controllership can depend on the facts and on regulator and case-law interpretation, so organisations should assess each relationship on its own facts rather than assuming a default position.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads need to identify when a collaboration creates joint controllership rather than a controller-processor or independent-controller relationship, because this determines who holds which obligations and how liability may fall. Since the assessment turns on who actually influences the purposes and means, they should examine the substance of each arrangement rather than relying on contractual labels, and consider whether an Article 26 arrangement allocating responsibilities is needed.
Legal and contracting teams
Lawyers structuring joint ventures, data-sharing arrangements, and platform partnerships should assess whether the parties jointly determine purposes and means, and, where they do, put in place an arrangement allocating respective responsibilities as contemplated by Article 26. They should note that each joint controller may, per ICO guidance, be liable for the entire damage caused by the processing, and that the precise boundary between joint and separate controllership can depend on the facts and on interpretation.
Business and product owners running shared processing
Teams that pool or co-process personal data with another organisation for shared purposes should recognise that this may make them joint controllers, with the responsibilities and potential liability that entails. Because individuals may be able to seek redress against any joint controller, product owners should clarify early who handles data subject requests and other obligations, subject to assessment of the specific facts.

Inside Joint Controllers

Joint Determination of Purposes and Means
Joint controllership arises under Article 26 GDPR where two or more controllers jointly determine the purposes and means of processing. The joint nature of the determination, rather than a mere sharing of data, is the defining feature. Case law of the Court of Justice of the EU has indicated that joint control can exist even where the parties' involvement is at different stages or to different degrees, so an equal or identical role is not required.
Arrangement Between the Parties (Article 26(1))
Joint controllers are required to determine their respective responsibilities for compliance in a transparent manner by means of an arrangement, in particular as regards the exercise of data subject rights and the provision of information under Articles 13 and 14. The allocation should reflect the actual roles of the parties. This arrangement is distinct in purpose from a controller-processor contract under Article 28.
Availability of the Essence to Data Subjects
The essence of the joint controller arrangement is generally required to be made available to data subjects, so that individuals understand the allocation of roles. The precise form of making the essence available may be subject to regulator guidance and practical assessment.
Data Subject Rights Against Any Controller (Article 26(3))
Irrespective of the terms of the arrangement, a data subject may in most cases exercise their rights under the GDPR in respect of and against each of the joint controllers. The internal allocation of responsibility does not limit where the data subject can direct a request.
Distinction From Related Roles
Joint controllership is distinct from a single controller acting alone, from a processor acting on behalf of a controller under Article 28, and from separate independent controllers who each determine their own purposes without a common determination. Correctly characterising the relationship is a factual assessment based on the influence each party exercises over purposes and means.

Common questions

Answers to the questions practitioners most commonly ask about Joint Controllers.

Does being a joint controller mean each party is equally responsible for every aspect of the processing?
No. Joint control does not imply equal, identical, or symmetrical responsibility. Joint controllers jointly determine the purposes and means of processing, but their respective involvement can differ across stages of the processing lifecycle, and one party may be involved in only certain operations. Their responsibilities are generally allocated through the arrangement required between them, though this allocation does not necessarily limit a data subject's ability to exercise rights against either party. The precise apportionment is subject to assessment of the actual roles played.
Are two organizations that simply share personal data with each other automatically joint controllers?
Not necessarily. Sharing data does not by itself create joint controllership. What matters is whether the parties jointly determine the purposes and means of the processing. Where each party independently determines its own purposes and means, they may instead be separate independent controllers, even if data flows between them. Where one party processes on behalf of and under the instructions of another, a controller-processor relationship may exist instead. The correct characterization depends on a factual assessment of who decides the why and how of the processing.
What should the arrangement between joint controllers typically cover?
The arrangement should transparently allocate the parties' respective responsibilities for compliance, and in most cases addresses which party handles particular obligations, including how data subject rights requests are managed and which party provides required information to data subjects. The essence of the arrangement is generally made available to data subjects. Regardless of the terms agreed, data subjects may typically be able to exercise their rights against each of the joint controllers. Parties should verify the specific content requirements against the current official text.
How do joint controllers identify a point of contact for data subjects?
The arrangement between joint controllers may designate a point of contact for data subjects. However, designating such a contact does not generally prevent a data subject from approaching whichever controller they choose to exercise their rights. Establishing a clear internal process for routing and responding to requests is a practical measure, but it should be documented in a way that does not misrepresent to individuals that their rights are restricted to a single party.
How should each legal basis be handled where processing involves joint controllers?
Each controller generally needs to be able to point to an appropriate lawful basis under Article 6 for the processing it is involved in, and an additional condition under Article 9 where special category data is processed. Joint controllership does not remove the need to establish and document a valid basis, and the appropriate basis is determined by the purpose and context rather than assumed to be consent. Parties should assess the basis applicable to their respective processing activities.
How does joint controllership affect handling and documentation of the relationship in practice?
In practice, parties typically document the joint controller arrangement separately from other instruments, and should not conflate it with a controller-processor Data Processing Agreement, which addresses a different relationship. Where the processing is likely to result in high risk, a Data Protection Impact Assessment may be required, and the parties should clarify which of them carries out or contributes to it. Record-keeping, transparency, and response processes should reflect the actual allocation of roles, subject to assessment of each party's involvement.

Common misconceptions

Joint controllers must share equal responsibility and identical roles.
Joint controllership does not require equal or symmetrical involvement. CJEU case law suggests joint control can exist where parties are involved at different stages or to differing degrees, and Article 26 anticipates that responsibilities will be allocated to reflect each party's actual role rather than split evenly.
An Article 26 joint controller arrangement is the same as an Article 28 data processing agreement.
These are distinct instruments serving different purposes. An Article 28 contract governs a controller-to-processor relationship, whereas an Article 26 arrangement allocates compliance responsibilities between parties who jointly determine purposes and means. The presence of one does not satisfy the requirement for the other, and mislabelling the relationship can misallocate obligations.
The internal arrangement determines where and against whom a data subject can bring a rights request.
Under Article 26(3), a data subject may generally exercise their rights against each of the joint controllers, regardless of how responsibilities are allocated in the arrangement. The arrangement governs the relationship between the controllers but does not restrict the data subject's ability to approach any of them.

Best practices

Conduct a documented factual assessment of whether each party genuinely participates in determining the purposes and means of processing, rather than assuming a controller-processor or joint controller label, and revisit the characterisation if roles change.
Put in place a written Article 26 arrangement that transparently allocates respective responsibilities for GDPR compliance, addressing in particular the exercise of data subject rights and the provision of information under Articles 13 and 14.
Make the essence of the arrangement available to data subjects in a manner appropriate to the processing, and confirm the expected form against current regulator guidance where uncertainty exists.
Design internal processes so that a data subject request received by any joint controller can be handled or routed appropriately, recognising that individuals may generally exercise rights against each controller under Article 26(3).
Keep the Article 26 arrangement distinct from any Article 28 processor contract, and ensure the correct instrument is used for each relationship rather than substituting one for the other.
Verify the applicable position where the UK GDPR, national implementing law, or member state derogations may apply, and confirm article references and evolving regulator guidance against the current official text before relying on them.