Joint controllership under Article 26 GDPR
The status arises as soon as two bodies jointly determine the purposes and the means. A contract is not a precondition for it but the duty that follows from it.
Two group companies run a shared recruitment portal, a research consortium analyses data from several institutions together, a professional body keeps a registry that its members fill. There are contracts in all three cases, yet none of them settles data protection between the participants.
The status therefore tends to come up late, on a subject access request, an inspection or an incident. By then it has long since arisen.
The status arises without intent and without a contract
Whether a collaboration triggers the status is decided by the statutory test alone. Article 26(1) GDPR ties it to two or more controllers jointly determining the purposes and means of processing.
Triggers the status
- A joint decision on purpose and means
- Converging decisions that complement each other
- Embedding a tool whose data accrues at the other body
- A purpose of one’s own pursued alongside the partner’s
Is irrelevant
- That no arrangement was concluded
- That one side never gets to see the data
- That nobody intended the status
- That the contributions differ in size
On 5 December 2023 the Court of Justice of the European Union held that the arrangement is not a precondition of the classification but a duty following from it (C-683/21). Converging decisions suffice as well, provided they complement each other so that each has a concrete effect on purposes and means.
Responsibility reaches only as far as the determination
What is actually answered for is a different question, and the relief lies here. Under the decision of 29 July 2019 a body is responsible only for the operations whose purposes and means it helps determine. For upstream or downstream operations in the processing chain, for which it determines neither purposes nor means, that responsibility does not attach (C-40/17).
What the arrangement under Article 26 GDPR has to contain
What belongs in the arrangement follows from the division of tasks and not from a template. Article 26(2) GDPR requires it to duly reflect the actual roles and relationships, and those roles differ in every undertaking.
- The joint processing operation is delimited, and the stages before and after it are named
- It is settled who provides the information under Articles 13 and 14 GDPR
- It is settled who handles access, rectification and erasure, and within what period the other side contributes
- A contact point for data subjects is designated
- The essence of the arrangement is held in a form in which it can be made available
- It is settled who reports a personal data breach and who leads towards the authority
The allocation operates internally. Under Article 26(3) GDPR the data subject may nonetheless exercise their rights in respect of and against each of the controllers, which is why the arrangement sensibly also settles the contribution owed where a request arrives at the wrong party.
Groups and research consortia lie differently
How the case lies turns on the structure and not on what the collaboration is called.
Setting 1: Within a group
The status is often assumed because a shared infrastructure exists. What counts remains the individual operation. For centrally mandated systems the parent may co-determine, for the subsidiary’s personnel file as a rule not.
Setting 2: In a research consortium
The status is overlooked because every institution has its own ethics committee and its own legal basis. Once the analysis design is settled jointly, however, the test is met.
Setting 3: In both settings
Each body keeps its own record under Article 30(1) GDPR. Anyone listing a joint operation there without an arrangement is documenting the shortcoming.
How we help
- ClassificationWe examine for each processing operation whether the test is met, and delimit it against processing on behalf and separate controllership.
- The arrangementWe draft the arrangement along the actual division of tasks, including internal contributions and deadlines.
- In a research projectWe accompany the project as a consortium partner and align the arrangement with the consortium agreement.
Not covered here is processing on behalf of a controller, which presupposes processing on instructions and therefore meets a different test.
A collaboration is running, and the arrangement is missing?
We allocate the operations and draft what Article 26 GDPR requires.
Have the collaboration reviewedFrequently asked questions
We have not signed anything. Are we joint controllers all the same?
Possibly yes. On 5 December 2023 the Court of Justice of the European Union held that the classification does not presuppose an arrangement and that the arrangement is a duty following from the classification (C-683/21). Even converging decisions by two bodies suffice, provided they complement each other so that each has a concrete effect on the purposes and means.
We never see the data. Can the status still apply to us?
Yes. According to the Court it is not required that every participant has access to the data (C-25/17). What matters is the decision on purposes and means, not actual sight of the data. The case arises frequently where one body provides or embeds a tool whose data accrues at the other.
Are we liable for everything the partner does with the data?
No. According to the Court a body is responsible only for the operations whose purposes and means it helps determine, and not for upstream or downstream operations in the processing chain (C-40/17). The degree of responsibility may also differ, because the participants are involved at different stages and to different extents.
Is there a template for the arrangement?
For the structure yes, for the content no. Article 26(2) GDPR requires the arrangement to duly reflect the respective actual roles and relationships, and those roles differ in every undertaking. An adopted template describes somebody else's division of tasks and is measured against precisely that in a review.
Can we allocate data subject rights to one partner?
Internally yes, externally no. Article 26(1) GDPR calls for exactly that determination of who discharges which duty, and the arrangement may designate a contact point. Under Article 26(3) GDPR the data subject may nonetheless exercise their rights in respect of and against each of the controllers.