Joint Controllers
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Multiple controllers jointly determining purposes and means
Overview
21 sources · Aug 27, 2026Legal Framework
Joint controllership arises when two or more controllers together determine the purposes and means of processing. Article 26(1) GDPR establishes this definition and requires joint controllers to transparently allocate their respective responsibilities — particularly regarding data subject rights and the information obligations under Articles 13 and 14 — through an arrangement between them, unless EU or Member State law already allocates those responsibilities.
"Wanneer twee of meer verwerkingsverantwoordelijken gezamenlijk de doeleinden en middelen van de verwerking bepalen, zijn zij gezamenlijke verwerkingsverantwoordelijken."
— GDPR Art. 26(1)
The arrangement must clearly set out each joint controller's role and relationship to data subjects, and its essential content must be made available to them (Article 26(2)). Article 26(3) preserves data subjects' right to exercise their rights against any joint controller, regardless of the internal allocation. Article 30(1)(a) requires controllers to record the name and contact details of any joint controller in their processing records, and Article 36(3)(a) requires disclosure of joint controllership arrangements during prior consultation with supervisory authorities.
Key Developments
The CJEU has clarified two essential thresholds. First, each joint controller must independently satisfy the definition of controller under Article 4(7):
Second, joint controllership does not require equal responsibility or equal access to data. In IAB Europe, the Court held that operators may be involved at different stages and to different degrees:
"the existence of joint controllership does not necessarily imply equal responsibility of the various operators engaged in the processing of personal data"
— IAB Europe v Gegevensbeschermingsautoriteit ¶58
A sectoral body prescribing technical standards for data processing can thus qualify as a joint controller without direct access to the personal data. In X v Russmedia, the Court further distinguished operations within a single processing chain, requiring individualized assessment of each actor's responsibility level — appropriate technical and organizational measures must be assessed concretely, considering the nature, scope, context, and purposes of the specific processing. Enforcement confirms that the Article 26 arrangement itself is scrutinized. In the CRITEO decision, CNIL found that:
"the agreement between the controller and a joint controller was incomplete"
— CRITEO §2
This contributed to a €40 million fine, alongside failures in consent withdrawal and data deletion.
Status of the Debate
The boundaries of joint controllership are actively contested. The IAB Europe ruling extended the concept to standard-setting organizations that prescribe how personal data should be generated, stored, and distributed — even without direct data access — while X v Russmedia emphasized individualized responsibility assessment for each actor in a processing chain. Whether joint controllership automatically extends to downstream processing by third parties who merely implement a standard remains an open question that the IAB Europe referral posed but the Court did not definitively resolve. A future CJEU ruling addressing automatic extension to subsequent processing would clarify the outer limits. DPAs continue to enforce the arrangement requirement strictly, as CRITEO demonstrates.
Practical Guidance
- Execute a written Article 26 arrangement before commencing joint processing. The arrangement must allocate responsibilities for data subject rights, information obligations under Articles 13–14, and breach notification duties under Articles 33–34. EDPB guidance recommends designating which controller takes the lead on breach notification.
- Make the arrangement's essential content available to data subjects as required by Article 26(2). An incomplete or undisclosed arrangement invites enforcement.
- Document joint controllers in Article 30 records by name and contact details, and include joint controllership details in any Article 36 prior consultation filing.
- Assess each party's responsibility individually per X v Russmedia. Technical and organizational measures under Articles 24–25 should be calibrated to each joint controller's actual role, the stage of processing they influence, and the specific risks they create.
- Do not assume equal liability. As IAB Europe confirms, responsibility may be differentiated — but each joint controller remains individually answerable to data subjects under Article 26(3), so allocate responsibilities to match actual decision-making power.
why this is here
The overarching criterion for joint controllership to exist is the joint participation of two or more entities in the determination of the purposes and means of a processing operation.
The document extensively defines joint controllership, its criteria, and the required arrangement.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the interaction between social media providers and other actors may give rise to joint responsibilities under EU data protection law.
Central theme discussing joint controllers in targeting.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the notion of main establishment in the context of joint controllership
The document revises section 2.1.3 specifically on joint controllers, applying the main establishment concept to them.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
in case of joint controllership, especially in case where controllers are from different Member States, restrictions applicable in accordance with Article 23 should be considered
The document briefly mentions joint controllers in the context of restrictions, but it is not the central topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the information use cases concerning the privacy notice, joint controllership and data breach communications
The document lists joint controllership as one of the use case topics, but does not provide substantive analysis of joint controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
failing to conclude a joint controllership agreement
The document's primary legal basis is the failure to conclude a joint controllership agreement, which is the core issue under Article 26 GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the agreement between the controller and a joint controller was incomplete
The document explicitly identifies a joint controller relationship and criticizes the incompleteness of their agreement, directly addressing Article 26 GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
implements processing of personal data with other companies, in particular for the marketing of advertising spaces
The document mentions processing with other companies, which relates to joint controllership, but not central.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 35 Case Law