Skip to main content
Category: Supervisory Authorities & Enforcement

Joint Investigations

Also known as: JIT, Joint Investigation Team, Joint Investigation Teams
Simply put

A joint investigation is a coordinated inquiry carried out together by more than one authority, and in the EU context it usually refers to a Joint Investigation Team (JIT), which is a formal cross-border cooperation tool for criminal matters. A JIT is set up under a written agreement between the competent judicial and law enforcement authorities of two or more EU member states (and sometimes other partners) to investigate specific offences together for a limited period. Its main purpose is to make it easier for national agencies to share information and coordinate directly rather than relying only on slower formal requests.

Formal definition

In the EU criminal-justice context, a Joint Investigation Team (JIT) is an international cooperation instrument established by legal agreement between the competent judicial and/or law enforcement authorities of two or more member states, and potentially with third parties, to conduct criminal investigations of a defined scope for a limited duration. JITs are supported operationally and financially by bodies such as Eurojust and Europol, which facilitate their setting-up and functioning. The EU legal framework for JITs derives from Council Framework Decision 2002/465/JHA on joint investigation teams; national implementing law and, in some cases, mutual legal assistance or specific bilateral or multilateral agreements govern the detailed operation of a given team, so the precise legal basis and rules should be verified against the applicable instruments. Note that this term denotes a law-enforcement cooperation mechanism and is distinct from data-protection concepts; where personal data are processed in a JIT, data relating to criminal convictions and offences are addressed under Article 10 GDPR (not Article 9), subject to applicable law-enforcement data-protection rules and derogations, which the reader should confirm against current sources.

Why it matters

Joint Investigation Teams are among the most advanced tools available for cross-border cooperation in criminal matters within the EU. They allow the competent judicial and law enforcement authorities of two or more member states to work together directly under a single legal agreement, sharing information and coordinating operational activity in real time rather than depending solely on slower formal channels such as mutual legal assistance requests. For organizations that may receive data requests or become involved as witnesses or affected parties, understanding the JIT mechanism helps clarify how and why authorities from different jurisdictions may act in concert.

JITs also matter from a data-protection standpoint because they involve the processing of personal data across borders, including data relating to criminal convictions and offences. Under the GDPR, such data are addressed under Article 10 (not Article 9, which concerns special categories of data), and processing in a law-enforcement context is typically governed by the Law Enforcement Directive and national implementing law rather than the GDPR alone. Because the applicable rules, derogations, and safeguards can vary by member state and by the specific instruments underpinning a given team, the precise data-protection position should be verified against the current applicable sources.

For compliance leads and data protection officers, the significance lies in recognizing the boundary between a law-enforcement cooperation mechanism and the data-protection framework that governs any personal data flowing through it. Misclassifying the relevant legal basis or the category of data at issue can lead to material errors in how requests are handled and documented.

Who it's relevant to

Data Protection Officers
DPOs advising organizations that may interact with cross-border criminal investigations need to understand that data relating to alleged or established offences fall under Article 10 GDPR, not Article 9, and that law-enforcement processing is typically governed by the Law Enforcement Directive and national implementing law. The precise position, including applicable derogations and safeguards, should be verified against current sources for each situation.
Compliance and Legal Teams
Legal and compliance staff who receive or respond to requests from authorities benefit from recognizing when a JIT is the underlying cooperation mechanism, since it enables direct coordination between multiple member states under a single agreement. They should confirm the specific legal basis, which derives from Council Framework Decision 2002/465/JHA together with national implementing law and any bilateral or multilateral agreements applicable to the team in question.
Law Enforcement and Judicial Authorities
Competent judicial and law enforcement authorities are the parties that establish and staff JITs, working with operational and financial support from bodies such as Eurojust and Europol. They are responsible for defining the scope and duration of the investigation and for ensuring that personal data processing complies with the applicable law-enforcement data-protection rules.

Inside JIT

Joint Investigation Team (JIT)
A cooperative arrangement in which competent authorities of two or more jurisdictions conduct a coordinated investigation. In the EU context, JITs are established under a defined legal framework (see Council Framework Decision 2002/465/JHA) and typically operate on the basis of an agreement setting out the purpose, participants, and duration. The specific instruments and their current wording should be verified against the official text.
Applicable data protection regime
Processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, or prosecution of criminal offences generally falls under the Law Enforcement Directive (Directive (EU) 2016/680) and its national implementations, rather than the GDPR. Practitioners should identify which regime applies before assessing obligations, as the position can vary by member state and by the nature of the participating body.
Data relating to criminal offences
Personal data relating to criminal convictions, offences, or related security measures is addressed under Article 10 GDPR (and correspondingly within the Law Enforcement Directive framework where that regime applies). This is distinct from special category data under Article 9. Article 10 processing is generally permitted only under the control of official authority or where authorised by Union or member state law providing appropriate safeguards.
Cross-border transfer element
Because a JIT involves authorities in more than one jurisdiction, personal data may move between participants. Any transfer must be assessed against the applicable transfer rules; where the Law Enforcement Directive applies, its own international transfer provisions govern rather than the GDPR Chapter V mechanisms. Transfer tools, adequacy positions, and safeguards evolve and should be verified against current sources.
Roles and accountability
Each participating authority typically remains responsible for the lawfulness of its own processing within the JIT. Determining who determines purposes and means, and whether any joint arrangement exists, is a fact-specific assessment that should be documented rather than assumed.
Purpose limitation and safeguards
Data shared within a JIT is generally intended for the specified investigative purpose. Onward use, retention, and further sharing are subject to the safeguards in the applicable instrument and the relevant data protection regime, and can be constrained by conditions imposed by the disclosing authority.

Common questions

Answers to the questions practitioners most commonly ask about JIT.

Does data about alleged criminal offences processed in a joint investigation count as special category data requiring an Article 9 condition?
No. This is a common but material error. Personal data relating to criminal convictions and offences, or related security measures, is governed by Article 10 of the GDPR, not Article 9. Article 9 concerns special categories such as health, biometric, or racial or ethnic origin data. Processing of Article 10 data must be carried out either under the control of official authority or when authorised by EU or member state law providing appropriate safeguards. Because national implementing laws and derogations vary, the precise conditions should be verified against the applicable jurisdiction's law rather than assumed.
Is the GDPR the only legal framework governing an EU Joint Investigation Team?
No. Describing a Joint Investigation Team by reference to the GDPR alone is incomplete. For EU Joint Investigation Teams, Council Framework Decision 2002/465/JHA is a key governing instrument establishing the framework for their creation and operation across member states. Data protection in the law enforcement context is also shaped by the Law Enforcement Directive rather than the GDPR alone in many circumstances. The interaction between these instruments, and any national implementing measures, should be assessed for each specific investigation.
How should participating parties allocate controller and processor roles at the outset of a joint investigation?
Roles should generally be determined and documented before processing begins, based on who determines the purposes and means of the processing. In a joint investigation, parties may act as separate controllers, joint controllers, or in some configurations as controller and processor, and the correct characterisation depends on the factual arrangement rather than labels chosen for convenience. Where joint controllership arises, the parties typically need an arrangement setting out their respective responsibilities. The applicable legal framework, including any law enforcement specific rules, should be identified before allocating roles, as this affects which obligations apply.
What should be documented to establish a lawful basis for processing within a joint investigation?
The documentation should identify the applicable legal basis for each processing activity. In an investigative context this is often a public task or legal obligation basis rather than consent, and consent is generally not the appropriate basis where an authority exercises official powers. Where data relating to criminal offences under Article 10 is involved, the authorisation under EU or member state law and its safeguards should be recorded. Because the governing framework may be the Law Enforcement Directive or national implementing law rather than the GDPR alone, the analysis should confirm which regime applies before finalising the basis.
What safeguards should accompany data sharing across borders in a joint investigation?
Cross border sharing in an investigative setting should be assessed against the transfer rules of the applicable framework, which may differ from the general GDPR transfer chapter where law enforcement instruments apply. Parties should consider the legal channel authorising the sharing, any conditions imposed by the disclosing authority, purpose limitation on onward use, and appropriate security measures. Because transfer tools, adequacy positions, and supplementary measures evolve, the arrangements should be verified against current instruments rather than treated as settled.
How should retention and deletion be handled for data collected during a joint investigation?
Retention periods should generally be defined by reference to the purpose of the investigation and the requirements of the applicable law, with data kept no longer than necessary for that purpose. Parties should agree how data is handled at the conclusion of the investigation, including return, deletion, or continued retention where a legal obligation or ongoing proceeding requires it. Where multiple parties or jurisdictions are involved, retention obligations may differ, so the position should be documented and reconciled against each applicable framework.

Common misconceptions

Data about alleged offences processed in a Joint Investigation Team is special category data requiring an Article 9 condition.
Personal data relating to criminal offences and convictions is governed by Article 10 GDPR (or the equivalent provisions of the Law Enforcement Directive where that regime applies), not by Article 9. Article 10 has its own requirement for processing to be under the control of official authority or authorised by Union or member state law with appropriate safeguards.
The GDPR is the governing framework for all personal data processing in a Joint Investigation Team.
Where processing is carried out by competent authorities for criminal law enforcement purposes, the Law Enforcement Directive (Directive (EU) 2016/680) and national implementing law generally apply instead of the GDPR. The applicable regime should be confirmed for each participant and activity.
Consent is the legal basis for sharing data within a Joint Investigation Team.
Consent is typically not the operative basis for law enforcement processing. Such processing generally relies on legal authority under the applicable framework rather than the data subject's consent, and treating consent as a universal requirement misstates the position.

Best practices

Confirm at the outset which data protection regime applies to each participating authority and activity, distinguishing GDPR processing from processing under the Law Enforcement Directive and national implementations.
Identify and document the legal instrument establishing the arrangement, including the EU JIT framework under Council Framework Decision 2002/465/JHA where relevant, and verify current wording against the official text.
Classify data relating to criminal offences under Article 10 (or the equivalent law enforcement provisions), and avoid analysing it as Article 9 special category data.
Assess any cross-border movement of data against the transfer rules of the applicable regime, and treat adequacy positions, transfer tools, and safeguards as subject to change requiring current verification.
Record which authority determines purposes and means for each processing operation, and set out responsibilities, retention, and onward-use conditions in the governing agreement.
Where regulator guidance or member state derogations create uncertainty, flag the open points and seek confirmation from the competent supervisory or judicial authorities before proceeding.