Skip to main content
Category: Controller & Processor Roles

Joint Controllership Arrangement

Also known as: JCA, Joint Controller Agreement, Joint Controllership
Simply put

A joint controllership arrangement exists where two or more organisations together decide why and how the same personal data is processed, making them joint controllers rather than one being in charge alone. When this happens, the parties are expected to agree, in a transparent way, who takes responsibility for meeting which data protection obligations. This does not always mean the parties share responsibilities equally, and the exact allocation depends on the specific facts of how they cooperate.

Formal definition

A joint controllership arrangement arises, under Article 26 of the GDPR (and the corresponding provision of the UK GDPR), where two or more controllers jointly determine the purposes and means of processing the same personal data. In such cases the parties must, in a transparent manner, determine their respective responsibilities for compliance, in particular as regards the exercise of data subject rights and their information duties, typically through an arrangement between them; the essence of that arrangement may be required to be made available to data subjects. Whether joint controllership exists is a factual assessment of who influences the purposes and means, and it is distinct from a controller-processor relationship (governed by the Article 28 data processing agreement) and from sole controllership. The precise division of obligations is agreed between the parties, but it does not necessarily exclude joint and several liability toward data subjects, and the boundaries of the concept continue to be shaped by regulatory guidance and case law; practitioners should verify allocation of duties and current regulatory positions against the applicable official text and guidance.

Why it matters

Correctly identifying a joint controllership arrangement matters because it determines who is accountable for meeting data protection obligations toward individuals. Where two or more organisations jointly determine the purposes and means of processing the same personal data, they are joint controllers under Article 26 of the GDPR (and the corresponding UK GDPR provision), and each may bear responsibility for compliance rather than being able to point to a single party as solely in charge. Misclassifying such a relationship, for example, treating a co-decision-making partner as a mere processor under an Article 28 arrangement, can leave obligations unallocated and expose the parties to enforcement and to claims from data subjects.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify when a collaboration crosses into joint controllership, ensure a transparent arrangement is in place, and confirm that responsibilities, especially for data subject rights and information duties, are clearly allocated. They should treat classification as a fact-specific assessment and revisit it as guidance and case law evolve.
Legal and Contracting Teams
Lawyers drafting collaboration agreements must distinguish an Article 26 joint controllership arrangement from an Article 28 data processing agreement and from sole controllership, and reflect the correct roles. They should address how responsibilities are divided while recognising that internal allocation does not necessarily exclude joint and several liability toward data subjects.
Organisations in Data-Sharing Partnerships
Businesses that co-decide the purposes and means of processing shared personal data, for example, partners contributing to a common processing objective, may be joint controllers and should assess this against the facts of how they cooperate, rather than assuming one party is solely responsible.
Engineers and System Architects
Technical teams designing shared platforms or integrations should understand that decisions influencing how personal data is processed can contribute to a joint controllership determination. Documenting who influences purposes and means helps support an accurate factual assessment of roles.

Inside JCA

Joint Determination of Purposes and Means
The defining element of joint controllership under Article 26 GDPR: two or more controllers jointly determine the purposes and means of processing. This determination need not be equal or symmetrical, and CJEU case law has indicated that jointly pursuing a shared purpose can suffice even where each party's involvement differs. Whether joint controllership exists is a factual assessment of the actual influence exercised, not merely how the parties label their relationship.
Arrangement Between the Parties (Article 26(1))
Joint controllers are required to determine their respective responsibilities for compliance in a transparent manner by means of an arrangement, in particular regarding the exercise of data subject rights and their respective duties to provide information under Articles 13 and 14. The arrangement should reflect the parties' real roles vis-a-vis data subjects.
Essence Made Available to Data Subjects (Article 26(2))
The essence of the arrangement should generally be made available to data subjects, so that they understand how responsibilities are allocated. This supports the transparency obligations owed to individuals.
Data Subject Rights Against Any Controller (Article 26(3))
Irrespective of the terms of the arrangement, a data subject may generally exercise their rights under the GDPR in respect of and against each of the joint controllers. The internal allocation of responsibilities does not limit the data subject's ability to approach any of the joint controllers.
Distinction from Processor and Independent Controller Relationships
Joint controllership is distinct from a controller-to-processor relationship (typically governed by an Article 28 Data Processing Agreement) and from separate independent controllers who each determine purposes and means on their own. Correct characterization depends on who actually influences the purposes and means of the processing.

Common questions

Answers to the questions practitioners most commonly ask about JCA.

Does a joint controllership arrangement mean each party is only responsible for its own portion of the processing?
No, this is a common misconception. In a joint controllership, two or more controllers jointly determine the purposes and means of processing, and they do not simply carve up responsibility so that each is liable only for its own slice. Under Article 26 GDPR, the parties must agree an arrangement setting out their respective responsibilities, but data subjects may generally exercise their rights against, and hold, each of the joint controllers, regardless of the internal allocation. The internal arrangement governs the relationship between the controllers; it does not, by itself, limit a data subject's ability to bring a claim against any one of them. The precise scope of joint responsibility has been shaped by case law of the Court of Justice, and readers should assess each relationship on its facts.
Is a joint controllership the same as a controller-processor relationship, just with two controllers?
No. The two relationships are distinct and are governed by different provisions. A controller-processor relationship, addressed in Article 28 GDPR, arises where one party processes personal data on behalf of and under the instructions of the controller, and it requires a data processing agreement with the content specified in that Article. A joint controllership, addressed in Article 26 GDPR, arises where the parties jointly determine the purposes and means of processing, and it requires an arrangement allocating their respective compliance responsibilities. Determining which relationship applies is a factual assessment of who decides the why and how of the processing, and a single organisation can occupy different roles across different processing activities. Conflating the two, or using the wrong instrument, can misstate the parties' obligations.
How do we determine whether we are actually in a joint controllership rather than another role?
The assessment turns on whether the parties jointly determine the purposes and means of the processing, which is a factual question rather than one settled solely by how the contract labels the parties. It is generally advisable to map the specific processing activities, identify who decides the purposes and the essential means for each, and document the reasoning. Joint determination can arise from a common decision or from converging decisions that complement each other, and the analysis has been developed through Court of Justice case law and regulatory guidance. Because the same organisations may be joint controllers for some activities and hold different roles for others, the analysis should be conducted activity by activity, and readers should check current guidance from the relevant supervisory authority.
What should the Article 26 arrangement between joint controllers cover?
Article 26 GDPR requires the joint controllers to determine, in a transparent manner, their respective responsibilities for complying with the Regulation, in particular as regards the exercise of data subject rights and their respective duties to provide the information referred to in the transparency provisions. In practice the arrangement typically allocates responsibility for matters such as handling data subject requests, providing privacy information, managing security and breach response, and identifying a contact point. The essence of the arrangement should generally be made available to data subjects. The arrangement governs the internal allocation and does not, in most cases, override a data subject's ability to exercise rights against each controller. Confirm the specific required content against the current text of the Regulation.
How should legal bases and transparency be handled where processing is shared?
Each joint controller generally needs a valid legal basis under Article 6 for its part in the processing, and the appropriate basis depends on the context rather than defaulting to consent. Where special category data under Article 9 is involved, an additional Article 9 condition is also required. Because joint controllers must address transparency, the privacy information provided to data subjects should reflect the joint controllership and, typically, the essence of the Article 26 arrangement, including how rights can be exercised. The specific bases and conditions should be assessed for each activity and each party, and positions can be affected by member state implementing law, so a case-by-case analysis is advisable.
How does joint controllership affect handling of data subject requests and breaches in practice?
Because data subjects may generally approach any of the joint controllers to exercise their rights, it is common for the Article 26 arrangement to designate which party handles particular requests and to set out cooperation procedures, while recognising that the internal allocation does not necessarily limit a data subject's choice of controller. Similar coordination is typically addressed for security incidents, including how the parties will assess and, where applicable, notify a breach within the relevant timeframes. Clear operational procedures, defined contact points, and agreed cooperation help the parties meet their respective obligations, but the arrangement should be tested against the actual processing and against current supervisory authority guidance, as regulator expectations can vary.

Common misconceptions

Joint controllers must share responsibility equally and carry identical obligations.
Responsibility need not be equal. The parties allocate their respective compliance duties by arrangement, and CJEU case law suggests joint controllership can exist even where the parties' involvement, access to data, or degree of influence differs. However, this internal allocation does not, on its own, limit a data subject's ability to exercise rights against any of them.
Labelling the relationship in a contract as joint controllership (or as processor) determines the legal status.
Status is generally assessed on the factual reality of who determines the purposes and means of processing, not on the label the parties choose. A contract cannot convert what is factually joint controllership into a processor arrangement, or vice versa.
An Article 26 joint controller arrangement is the same instrument as an Article 28 processor agreement.
These are distinct instruments addressing distinct relationships. An Article 26 arrangement allocates responsibilities between co-controllers who jointly determine purposes and means, whereas an Article 28 Data Processing Agreement governs a processor acting on a controller's instructions. Conflating the two can misstate the parties' roles and obligations.

Best practices

Assess the factual relationship before drafting: analyze who actually determines the purposes and means of the processing, rather than relying on the label the parties prefer, and confirm whether the situation is joint controllership, independent controllership, or a controller-processor relationship.
Put in place a transparent Article 26 arrangement that clearly allocates respective responsibilities for compliance, giving particular attention to handling data subject rights and to the information duties under Articles 13 and 14.
Make the essence of the arrangement available to data subjects, and ensure your transparency notices accurately reflect the allocation of roles between the joint controllers.
Design intake and response processes on the assumption that a data subject may exercise their rights against any joint controller, including internal escalation and coordination mechanisms so requests are handled even when they reach the party not primarily responsible under the arrangement.
Do not treat the Article 26 arrangement as a substitute for an Article 28 processor agreement or other required instruments; identify separately whether any onward processing involves processors requiring their own agreements.
Revisit the characterization and the arrangement when the processing operations or the parties' respective roles change, since joint controllership status is context-dependent and should be verified against the current facts and applicable guidance.