Skip to content
Topic Contested in court

Joint Controllers

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Multiple controllers jointly determining purposes and means

78 linked items 35 Case Law29 Guidance8 Enforcement3 News3 Literature

Overview

21 sources · Aug 27, 2026

Legal Framework

Joint controllership arises when two or more controllers together determine the purposes and means of processing. Article 26(1) GDPR establishes this definition and requires joint controllers to transparently allocate their respective responsibilities — particularly regarding data subject rights and the information obligations under Articles 13 and 14 — through an arrangement between them, unless EU or Member State law already allocates those responsibilities.

"Wanneer twee of meer verwerkingsverantwoordelijken gezamenlijk de doeleinden en middelen van de verwerking bepalen, zijn zij gezamenlijke verwerkingsverantwoordelijken."
— GDPR Art. 26(1)

The arrangement must clearly set out each joint controller's role and relationship to data subjects, and its essential content must be made available to them (Article 26(2)). Article 26(3) preserves data subjects' right to exercise their rights against any joint controller, regardless of the internal allocation. Article 30(1)(a) requires controllers to record the name and contact details of any joint controller in their processing records, and Article 36(3)(a) requires disclosure of joint controllership arrangements during prior consultation with supervisory authorities.

Key Developments

The CJEU has clarified two essential thresholds. First, each joint controller must independently satisfy the definition of controller under Article 4(7):

Second, joint controllership does not require equal responsibility or equal access to data. In IAB Europe, the Court held that operators may be involved at different stages and to different degrees:

"the existence of joint controllership does not necessarily imply equal responsibility of the various operators engaged in the processing of personal data"
— IAB Europe v Gegevensbeschermingsautoriteit ¶58

A sectoral body prescribing technical standards for data processing can thus qualify as a joint controller without direct access to the personal data. In X v Russmedia, the Court further distinguished operations within a single processing chain, requiring individualized assessment of each actor's responsibility level — appropriate technical and organizational measures must be assessed concretely, considering the nature, scope, context, and purposes of the specific processing. Enforcement confirms that the Article 26 arrangement itself is scrutinized. In the CRITEO decision, CNIL found that:

"the agreement between the controller and a joint controller was incomplete"
— CRITEO §2

This contributed to a €40 million fine, alongside failures in consent withdrawal and data deletion.

Status of the Debate

The boundaries of joint controllership are actively contested. The IAB Europe ruling extended the concept to standard-setting organizations that prescribe how personal data should be generated, stored, and distributed — even without direct data access — while X v Russmedia emphasized individualized responsibility assessment for each actor in a processing chain. Whether joint controllership automatically extends to downstream processing by third parties who merely implement a standard remains an open question that the IAB Europe referral posed but the Court did not definitively resolve. A future CJEU ruling addressing automatic extension to subsequent processing would clarify the outer limits. DPAs continue to enforce the arrangement requirement strictly, as CRITEO demonstrates.

Practical Guidance

  • Execute a written Article 26 arrangement before commencing joint processing. The arrangement must allocate responsibilities for data subject rights, information obligations under Articles 13–14, and breach notification duties under Articles 33–34. EDPB guidance recommends designating which controller takes the lead on breach notification.
  • Make the arrangement's essential content available to data subjects as required by Article 26(2). An incomplete or undisclosed arrangement invites enforcement.
  • Document joint controllers in Article 30 records by name and contact details, and include joint controllership details in any Article 36 prior consultation filing.
  • Assess each party's responsibility individually per X v Russmedia. Technical and organizational measures under Articles 24–25 should be calibrated to each joint controller's actual role, the stage of processing they influence, and the specific risks they create.
  • Do not assume equal liability. As IAB Europe confirms, responsibility may be differentiated — but each joint controller remains individually answerable to data subjects under Article 26(3), so allocate responsibilities to match actual decision-making power.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Definition and criteria for joint controllership
why this is here
The overarching criterion for joint controllership to exist is the joint participation of two or more entities in the determination of the purposes and means of a processing operation.

The document extensively defines joint controllership, its criteria, and the required arrangement.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Joint responsibility
why this is here
the interaction between social media providers and other actors may give rise to joint responsibilities under EU data protection law.

Central theme discussing joint controllers in targeting.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Guidance EDPB Apr 2023 joint controllership and main establishment
why this is here
the notion of main establishment in the context of joint controllership

The document revises section 2.1.3 specifically on joint controllers, applying the main establishment concept to them.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 10/2020 restrictions under Article 23 GDPR Guidelines ·EDPB Guidance EDPB Oct 2021 Joint controllers' restrictions
why this is here
in case of joint controllership, especially in case where controllers are from different Member States, restrictions applicable in accordance with Article 23 should be considered

The document briefly mentions joint controllers in the context of restrictions, but it is not the central topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Joint controllership in use cases
why this is here
the information use cases concerning the privacy notice, joint controllership and data breach communications

The document lists joint controllership as one of the use case topics, but does not provide substantive analysis of joint controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€40M CRITEO: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 40 million on CRITEO. The controller is specialized in 'retargeting advertising'. This involves the company tracking the surfing behavior… CNIL Enforcement French Data Protection Authority (CNIL) Jun 2023 joint controller agreement incomplete
why this is here
the agreement between the controller and a joint controller was incomplete

The document explicitly identifies a joint controller relationship and criticizes the incompleteness of their agreement, directly addressing Article 26 GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Health data and use of cookies: DOCTISSIMO fined €380,000 Background information Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly… News CNIL May 2023 joint processing with other companies
why this is here
implements processing of personal data with other companies, in particular for the marketing of advertising spaces

The document mentions processing with other companies, which relates to joint controllership, but not central.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 35 Case Law