Joint Controllers
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Multiple controllers jointly determining purposes and means
Overview
18 sources · Jul 23, 2026Legal Framework
Article 26 GDPR governs joint controllership, applying when two or more entities jointly determine the purposes and means of processing. The rationale is to ensure that data subjects have clear avenues to exercise their rights when multiple parties collaborate. Joint controllers must establish their respective responsibilities via an arrangement, unless the processing is mandated by law. This arrangement must designate which controller responds to data subjects' requests, and the essence of the arrangement must be made available to data subjects. The concept is broad, encompassing situations where parties are involved in different stages of the processing but jointly determine its purposes and means.
Key Developments
The CJEU ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW eV established that a website operator embedding a social plugin can be a joint controller, even if it does not receive the collected data. However, liability is limited to the specific processing operations for which the operator jointly determines purposes and means. The court also clarified that the operator triggering the processing must obtain user consent prior to data collection, as relying on the plugin provider for consent would not ensure efficient protection of data subject rights. In Jehovah's Witnesses, the CJEU emphasized that joint controllers cannot systematically deny access rights without analyzing specific circumstances, reinforcing that joint controllership arrangements cannot impede data subject rights. Enforcement actions highlight the necessity of formalizing these relationships. The DPA of Niedersachsen fined a real estate company for failing to conclude a joint controllership agreement. Similarly, the CNIL's EUR 40 million fine against CRITEO demonstrates the severe financial consequences of mismanaging data subject rights in complex retargeting advertising ecosystems.
Practical Guidance
- Execute a formal Article 26 arrangement whenever your organization collaborates with another entity to determine processing purposes and means. The Niedersachsen enforcement action confirms that the absence of this agreement constitutes a standalone violation.
- Clearly allocate responsibility for obtaining consent. Under Fashion ID, the party triggering the processing—such as a website operator embedding a third-party tool—must secure consent prior to data collection, rather than deferring to the other controller.
- Limit liability by defining the scope of each party's involvement. The Fashion ID ruling dictates that joint controller liability does not extend to processing operations where a party lacks determining influence.
- Ensure the essence of the joint controllership arrangement is transparent and accessible to data subjects. The arrangement must designate a contact point for data subjects to exercise their rights effectively.
- Avoid blanket denials of data subject requests. As affirmed in Jehovah's Witnesses, requests must be assessed on their individual merits, and joint controllers cannot use internal arrangements to systematically deny access.