Answers to the questions practitioners most commonly ask about JCA.
Does a joint controllership arrangement mean each party is only responsible for its own portion of the processing?
No, this is a common misconception. In a joint controllership, two or more controllers jointly determine the purposes and means of processing, and they do not simply carve up responsibility so that each is liable only for its own slice. Under Article 26 GDPR, the parties must agree an arrangement setting out their respective responsibilities, but data subjects may generally exercise their rights against, and hold, each of the joint controllers, regardless of the internal allocation. The internal arrangement governs the relationship between the controllers; it does not, by itself, limit a data subject's ability to bring a claim against any one of them. The precise scope of joint responsibility has been shaped by case law of the Court of Justice, and readers should assess each relationship on its facts.
Is a joint controllership the same as a controller-processor relationship, just with two controllers?
No. The two relationships are distinct and are governed by different provisions. A controller-processor relationship, addressed in Article 28 GDPR, arises where one party processes personal data on behalf of and under the instructions of the controller, and it requires a data processing agreement with the content specified in that Article. A joint controllership, addressed in Article 26 GDPR, arises where the parties jointly determine the purposes and means of processing, and it requires an arrangement allocating their respective compliance responsibilities. Determining which relationship applies is a factual assessment of who decides the why and how of the processing, and a single organisation can occupy different roles across different processing activities. Conflating the two, or using the wrong instrument, can misstate the parties' obligations.
How do we determine whether we are actually in a joint controllership rather than another role?
The assessment turns on whether the parties jointly determine the purposes and means of the processing, which is a factual question rather than one settled solely by how the contract labels the parties. It is generally advisable to map the specific processing activities, identify who decides the purposes and the essential means for each, and document the reasoning. Joint determination can arise from a common decision or from converging decisions that complement each other, and the analysis has been developed through Court of Justice case law and regulatory guidance. Because the same organisations may be joint controllers for some activities and hold different roles for others, the analysis should be conducted activity by activity, and readers should check current guidance from the relevant supervisory authority.
What should the Article 26 arrangement between joint controllers cover?
Article 26 GDPR requires the joint controllers to determine, in a transparent manner, their respective responsibilities for complying with the Regulation, in particular as regards the exercise of data subject rights and their respective duties to provide the information referred to in the transparency provisions. In practice the arrangement typically allocates responsibility for matters such as handling data subject requests, providing privacy information, managing security and breach response, and identifying a contact point. The essence of the arrangement should generally be made available to data subjects. The arrangement governs the internal allocation and does not, in most cases, override a data subject's ability to exercise rights against each controller. Confirm the specific required content against the current text of the Regulation.
How should legal bases and transparency be handled where processing is shared?
Each joint controller generally needs a valid legal basis under Article 6 for its part in the processing, and the appropriate basis depends on the context rather than defaulting to consent. Where special category data under Article 9 is involved, an additional Article 9 condition is also required. Because joint controllers must address transparency, the privacy information provided to data subjects should reflect the joint controllership and, typically, the essence of the Article 26 arrangement, including how rights can be exercised. The specific bases and conditions should be assessed for each activity and each party, and positions can be affected by member state implementing law, so a case-by-case analysis is advisable.
How does joint controllership affect handling of data subject requests and breaches in practice?
Because data subjects may generally approach any of the joint controllers to exercise their rights, it is common for the Article 26 arrangement to designate which party handles particular requests and to set out cooperation procedures, while recognising that the internal allocation does not necessarily limit a data subject's choice of controller. Similar coordination is typically addressed for security incidents, including how the parties will assess and, where applicable, notify a breach within the relevant timeframes. Clear operational procedures, defined contact points, and agreed cooperation help the parties meet their respective obligations, but the arrangement should be tested against the actual processing and against current supervisory authority guidance, as regulator expectations can vary.