Joint Controllers Under GDPR Data Processing Responsibilities

Joint Controllers Under GDPR: Data Processing Responsibilities

Updated: August 2026

Joint controllers are two or more controllers that jointly determine the purposes and means of processing personal data under GDPR, creating shared responsibility for compliance obligations and liability. This arrangement differs from independent controller relationships and requires specific legal agreements to manage shared data protection responsibilities.

Joint controller relationships arise when companies decide together how and why to process the same personal data, making both parties liable for GDPR compliance across the entire processing activity.

Joint controllers face joint and several liability, meaning each party can be held liable for the entire damage resulting from non-compliance. They must establish joint controller agreements under Article 26 GDPR (or the equivalent UK GDPR provision), coordinate data subject rights responses, and maintain clear communication with data subjects about who is responsible for what.

What Is a Data Controller Under GDPR?

A data controller determines the purposes and means of processing personal data, bearing primary responsibility for GDPR compliance and data protection obligations.

The controller decides why personal data is processed (purposes) and how it is processed (means), distinguishing them from processors who act solely on the controller’s behalf. Understanding controller classification matters because it determines your compliance obligations, liability exposure, and relationship with data subjects.

How Do Independent Controllers Differ From Joint Controllers?

Independent controllers process personal data for their own purposes, with each controller responsible only for their separate processing activities and compliance obligations.

When companies operate as independent controllers, they maintain distinct lawful basis requirements, privacy notices, and data subject rights procedures. Independent arrangements contrast sharply with shared decision-making scenarios where responsibilities become interlinked, which is what turns two separate controllers into joint controllers.

How Do Controllers Differ From Processors?

Data processors act on a data controller’s behalf under specific contractual instructions, without determining processing purposes or essential means of processing.

Processors have limited compliance obligations compared to controllers, primarily focusing on security measures and following controllers’ instructions. Understanding processor roles helps distinguish scenarios where parties act under instruction from joint controller relationships involving shared decision-making authority.

What Does Joint Controllership Look Like in Practice?

Joint controllership emerges when two or more controllers jointly determine the purposes and means of processing the same personal data through converging decisions or inextricably linked processing activities.

When Does Joint Controllership Arise?

Joint controller relationships emerge when companies jointly determine the purposes of data collection, processing methods, or data use strategies, creating a shared influence over the same personal data processing activity.

Controllers don’t need identical purposes to be joint controllers. Their processing activities must be closely linked, complementary, or result from converging decisions that have a tangible impact on how personal data is processed. Joint controllership can arise from explicit agreements, collaborative arrangements, or technological integrations that create shared decision-making.

What Are Common Examples of Joint Controllers?

The European Data Protection Board has identified several scenarios where joint controllership commonly occurs:

Facebook Pages and administrators become joint data controllers when using Facebook’s Page Insights tool, as both parties jointly decide on targeted advertising and analytics purposes using visitor data collected through Facebook pixels.

Website operators using certain social media plugins may be considered joint controllers with the social media provider, but only for the initial collection and transmission of user data to the platform. The operator does not share responsibility for how the platform processes the data thereafter.

Joint research projects between multiple organisations establish joint controllership when companies decide together on research objectives, data collection methods, and analysis purposes for the same datasets.

Combined service offerings using shared data platforms create joint controller arrangements when each party’s business purposes are closely linked and require shared decision-making over customer data processing.

What Determines Whether Controllers Are Joint Controllers?

Joint controllership requires the joint determination of both the purposes and means of processing, which goes beyond simply having shared access to the same data.

What matters is whether parties jointly determine processing objectives and methods, regardless of whether their underlying reasons for processing are the same. Controllers must assess whether their decisions about personal data processing are made independently or through collaboration that influences how data subjects’ information is collected and used.

Once joint controller relationships are identified, specific legal requirements under Article 26 of the GDPR must be implemented.

What Does Article 26 GDPR Require From Joint Controllers?

Joint data controllers must comply with Article 26 GDPR requirements, establishing clear arrangements that allocate respective responsibilities and ensure coordinated compliance across both organisations.

How Do You Create a Joint Controller Agreement?

This is required under Article 26 GDPR for all joint controller relationships involving the processing of personal data.

1. Map data flows and processing activities: Document how each party collects, uses, and shares personal data, identifying where joint decision-making occurs and respective roles in the data processing activity.

2. Allocate specific GDPR compliance responsibilities: Assign obligations for privacy notices, lawful basis documentation, data protection impact assessments, and transparency obligations between parties clearly.

3. Designate contact points for data subject rights: Establish which party will serve as the primary contact for data subject requests, ensuring both controllers can demonstrate compliance with exercise of rights procedures.

4. Define liability arrangements and compensation terms: Specify how parties will handle joint and several liability, including indemnification clauses and procedures for when one party must pay compensation for entire damage claims.

5. Make arrangement essence available to data subjects: Ensure data subjects can access information about their respective responsibilities and contact details for exercising their rights under data protection law.

How Do Joint Controller Agreements Differ From Processor Contracts?

FeatureJoint Controller AgreementsProcessor Contracts
Decision-making authorityBoth parties jointly determine purposes and meansThe processor follows controller instructions only
Liability allocationJoint and several liability for the entire damageLimited processor liability for security breaches
GDPR obligationsBoth parties must comply with full controller obligationsThe processor has specific Article 28 requirements
Data subject rightsEither party can receive and respond to requestsThe processor assists the controller with responses

Joint controller agreements address scenarios where parties jointly determine the purposes and essential means of processing. Processor contracts, on the other hand, are used when one party (the processor) acts on the documented instructions of another (the controller) regarding those purposes and means.

Even with proper agreements, joint controllers face ongoing compliance challenges requiring practical solutions.

What Are Common Joint Controller Challenges and Solutions?

Joint controller arrangements create complex compliance scenarios that require active management of shared responsibilities and coordinated responses to data protection requirements.

How Do You Determine Controller Status in Complex Partnerships?

Conduct a detailed assessment of each party’s actual decision-making authority over data processing purposes and means, focusing on substance rather than contractual labels.

Assess whether parties make independent decisions about their own purposes or whether their decisions are inextricably linked such that processing wouldn’t occur without both parties’ involvement.

How Do You Manage Joint and Several Liability?

Put clear indemnification clauses and due diligence procedures in place within joint controller agreements to manage exposure to entire damage compensation claims.

Establish clear procedures for liability assessment, including insurance arrangements and risk allocation based on each party’s respective responsibilities and control over processing activities.

How Do You Coordinate Data Subject Rights Across Multiple Controllers?

Establish clear procedures for request handling, response coordination, and data consistency between joint controllers to ensure effective exercise of data subject rights.

Set up communication protocols with defined response timelines, shared databases for tracking requests, and procedures to ensure consistent responses when data subjects contact either controller.

Successful joint controller compliance requires an understanding of these frameworks and the implementation of appropriate governance structures.

Conclusion

Joint controllers share both decision-making authority and compliance responsibilities under the GDPR, creating shared liability for entire damage claims, while requiring specific agreements to manage their respective roles and obligations.

For processor relationships specifically, see our guide to Article 28 obligations.

Frequently Asked Questions

Do joint controllers need a written agreement?

Yes. Article 26 GDPR requires joint controllers to put a formal arrangement in place that allocates responsibilities, even though the regulation doesn’t mandate a specific format. Without one, both parties remain exposed to the full joint and several liability described above.

Can one joint controller be held liable for the other’s mistake?

Yes. Joint and several liability means a data subject can pursue either controller for the entire damage caused by non-compliance, regardless of which party was actually at fault. The controllers can sort out contribution between themselves afterwards, but that doesn’t change what the data subject is owed upfront.

Do both joint controllers need to be named in the privacy notice?

Yes. Data subjects need to know who is responsible for what, so the arrangement’s essential terms, including contact details for each controller, must be made available to them, typically through the privacy notice or an equivalent transparency document.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.