Joint controllers
Two or more controllers that jointly determine the purposes and means of processing and must transparently allocate their responsibilities under Article 26 GDPR.
Under Article 26 GDPR, joint controllers are two or more controllers that jointly determine the purposes and means of a processing operation. Joint participation may result from a common decision or from converging decisions that complement one another. The decisive question is whether both parties make an essential, interlinked contribution to determining the purposes and means of the specific processing activity.
The joint controllers must transparently agree who is responsible for which obligations. This includes, in particular, handling data subject rights and meeting the information duties under Articles 13 and 14 GDPR. The arrangement must reflect the parties’ actual functions and relationship, and its essence must be made available to data subjects. The parties may also designate a contact point.
The agreement does not determine the role by itself. The assessment remains based on the parties’ actual influence in the relevant processing activity. A service provider is therefore not necessarily a processor merely because a contract uses that label. An organisation that determines its own purposes or materially shapes the processing together with another party may be a controller or joint controller for that activity.
Data subjects may exercise their rights against each individual joint controller despite the internal allocation of tasks. Businesses should therefore examine the data flow, each party’s decisions and the Article 26 arrangement together. The privacy compliance and governance section provides the organisational context; the role check offers an initial orientation on the allocation of roles.
Learn more
General orientation, not individual advice.
-
Controller
The natural or legal person, public authority or other body that alone or jointly decides the purposes and means of processing personal data.
-
Processor
A natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller and under the controller’s instructions.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000