# Joint controllers — GDPR — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/gdpr/art-26
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Joint controllers — Joint controllers

*GDPR, gdpr-art-26-en — https://overview.legal/laws/gdpr/art-26*

1. Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.

2. The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.

3. Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.

## Related recitals

### Recital 106 — commission monitoring of adequacy decisions

The Commission should monitor the functioning of decisions on the level of protection in a third country, a territory or specified sector within a third country, or an international organisation, and monitor the functioning of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy decisions, the Commission should provide for a periodic review mechanism of their functioning. That periodic review should be conducted in consultation with the third country or international organisation in question and take into account all relevant developments in the third country or international organisation. For the purposes of monitoring and of carrying out the periodic reviews, the Commission should take into consideration the views and findings of the European Parliament and of the Council as well as of other relevant bodies and sources. The Commission should evaluate, within a reasonable time, the functioning of the latter decisions and report any relevant findings to the Committee within the meaning of Regulation (EU) No 182/2011 of the European Parliament and of the Council (12) as established under this Regulation, to the European Parliament and to the Council.

## Enforcement

9 decision(s) on record cite Article 26, totalling approximately €11,543,600 in fines (median €41,000).

Top fines:
- **Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security** (GREECE, €6,000,000) — https://overview.legal/posts/47139
- **Experian Nederland B.V.: Insufficient legal basis for data processing** (THE NETHERLANDS, €2,700,000) — https://overview.legal/posts/49023
- **Experian Nederland B.V.: Onvoldoende juridische basis voor de verwerking van gegevens.** (THE NETHERLANDS, €2,700,000) — https://overview.legal/posts/52019
- **DPC (Ireland) - 05/SIU/2018** (Ireland, €50,000) — https://overview.legal/posts/125613
- **Autonome Provincie Bozen: Niet-naleving van algemene principes voor gegevensverwerking.** (ITALY, €32,000) — https://overview.legal/posts/52056

## Guidance

### Guidelines on processing of personal data through blockchain technologies

*EDPB — https://overview.legal/posts/125668*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Template for Cross-Regulatory Cooperation Agreements

*EDPB — https://overview.legal/posts/125669*

1 | Adopted Template for Cross-Regulatory Cooperation Agreements Adopted by the EDPB on July 7 th 2026 2 | Adopted Explanatory note Cross-regulatory cooperation between data protection supervisory authorities (DPAs) and other national and EU competent authorities has become increasingly important as legal and practical challenges emerge at the intersection of different regulatory fields. Cooperation agreements can be an important basis to organise and strengthen cooperation and dialogue between…

### Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group

*EDPB — https://overview.legal/posts/125670*

Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group

*EDPB — https://overview.legal/posts/125671*

Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*EDPB — https://overview.legal/posts/125672*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Related topics

- **Controllers** — https://overview.legal/topics/controllers
  ## Legal Framework
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-26 · 2026-08-22
