Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

Joint controller: definition, scope and what it obliges you to do

What "Joint controller" means in practice, where the definition comes from, and the obligations that attach once the term applies to you.

A joint controller arrangement occurs when two or more entities jointly determine the purposes and means of processing personal data. This concept creates shared compliance obligations under the GDPR. Organizations must clearly allocate responsibilities between the parties involved.

Definition of joint controllers under the GDPR

Under the GDPR, joint controllership arises when two or more entities jointly determine the purposes and means of processing personal data. The legal foundation for this concept is established in the framework governing data controllers. When multiple organizations participate in setting the overarching goals and operational methods for handling specific data sets, they share responsibilities. This differs significantly from the relationship between a data controller and a data processor, where one party acts strictly on documented instructions from the other. Compliance teams should consult the official text found in Regulation (EU) 2016/679 (GDPR) — full text to verify the exact statutory language. Establishing this status impacts how organizations maintain their record of processing activities and how they structure internal data flows. Legal operations professionals frequently review these relationships to ensure accountability aligns with actual data handling practices across all participating corporate entities.

The functional test for joint controllership

Determining whether joint controllership applies relies on a functional assessment of influence rather than formal contractual labels. Organizations must examine whether each entity exercises decisive influence over the purposes and means of the processing activity. If two companies collaborate to launch a shared marketing initiative or joint platform, and both dictate why and how the personal data is collected, they meet the criteria. Guidance from the EDPB — guidelines, recommendations and best practices provides detailed scenarios and criteria for evaluating these arrangements. Compliance programs often utilize a data protection impact assessment to evaluate these risks before launching collaborative projects. If only one party determines the purposes while the other merely executes technical operations, joint controllership does not apply, and the operational model defaults to a traditional controller-processor structure. Misidentifying this relationship can lead to severe structural compliance gaps.

Mandatory arrangements and transparency requirements

Once joint controllership is established, the participating entities must designate their respective responsibilities for compliance with the GDPR in a transparent manner. This allocation must specifically determine who handles data subject rights requests and who fulfills information obligations. While data subjects may exercise their rights against any of the joint controllers, the internal arrangement must clarify accountability. Organizations should reference Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses for relevant contractual frameworks and clauses that assist in structuring cross-border data transfer relationships. The essence of the arrangement must be made available to data subjects, often through a publicly accessible privacy notice. Legal teams should also coordinate with the data protection officer to ensure internal governance policies accurately reflect the agreed-upon division of tasks and supervisory reporting lines.

Common compliance mistakes with joint controllership

Compliance teams frequently misapply standard vendor agreements to joint controller scenarios by treating one partner as a simple service provider. This mistake ignores the shared decision-making power regarding data processing purposes. Another frequent error involves failing to document the allocation of responsibilities required under the GDPR, leaving both entities exposed to regulatory enforcement. Organizations also neglect to update their record of processing activities to reflect the joint nature of the processing operations. Finally, companies often fail to provide clear contact points for data subjects, mistakenly directing inquiries back and forth between the participating entities. Addressing these errors requires a thorough review of data flows, governance structures, and contractual documentation across all collaborating business units.

| Common Mistake | Correct Approach | Regulatory Reference | |---|---|---| | Using processor clauses for joint controllers | Draft bespoke joint controller arrangements | GDPR Article 28 — Processor | | Omitting joint status from documentation | Update internal inventories | GDPR Article 30 — Records of processing activities | | Failing to assign a primary contact | Publish clear contact mechanisms | Regulation (EU) 2016/679 (GDPR) — full text |

Distinguishing joint controllers from processors and sub-processors

Legal and compliance operations must carefully distinguish joint controllers from data processors and downstream sub-processors. A processor processes personal data exclusively on behalf of a controller without determining the underlying purposes. In contrast, joint controllers actively participate in determining those purposes and means together. Similarly, a sub-processor is engaged by a primary processor to perform specific processing activities under a chain of contracts governed by provisions such as GDPR Article 28 — Processor. Confusing these roles can invalidate compliance documentation and lead to improper allocation of liability during an audit. Compliance frameworks maintained via record of processing activities tools must clearly categorize each partner's exact legal status to prevent enforcement actions.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

How does joint controllership affect data subject access requests?

Data subjects may exercise their rights under the regulation against any of the joint controllers involved in the processing operation. The arrangement between the entities must clearly specify which party is responsible for responding to these requests, though the individual retain the option to submit inquiries to any participating organization.

Can two companies be joint controllers if they process different data sets?

Joint controllership requires that the entities jointly determine the purposes and means of the same processing operations. If two organizations process completely separate data sets for independent purposes without shared decision-making over those operations, they operate as separate controllers rather than joint controllers.

What happens if the joint arrangement fails to allocate responsibilities?

Failing to establish a transparent arrangement outlining respective obligations does not exempt either party from liability. Supervisory authorities can enforce compliance against any of the entities involved, and courts may examine actual operational control to determine accountability when disputes arise.

Do joint controllers need a written contract?

The governing regulation requires joint controllers to determine their respective responsibilities for compliance through an arrangement. This agreement must transparently reflect the roles and relationships of the parties with respect to the data subjects and must be properly documented.

Are joint controllers required to share a single privacy notice?

While the entities must ensure that data subjects receive all required statutory information, they are not strictly required to use a single unified privacy notice. However, the arrangement must clearly designate how transparency obligations are fulfilled and which entity handles communications.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact