Article 26 (Joint Controllers)

A comprehensive framework for understanding, implementing, and governing joint controllership under the General Data Protection Regulation.


Introduction and Legal Context

What Article 26 Establishes

GDPR Article 26 establishes the legal framework governing situations where two or more controllers jointly determine the purposes and means of processing personal data. It addresses accountability gaps that can emerge when multiple organisations collaborate in processing activities.

Core Governance Philosophy

Article 26 operationalises the GDPR accountability principle by requiring transparent allocation of responsibilities among joint controllers. The article reflects the GDPR's broader governance philosophy that responsibility follows influence over processing decisions.

Factual Reality Prevails

Regulatory authorities and courts consistently emphasise that factual reality prevails over contractual labels.

CJEU Expansion

The jurisprudence of the Court of Justice of the European Union has significantly expanded the interpretation of joint controllership beyond traditional business partnerships.

Accountability Gaps

The provision directly targets responsibility fragmentation in collaborative data ecosystems where multiple parties share influence.

Textual Purpose of Article 26

When Article 26 Applies

Two or More Entities

Jointly determine processing purposes and means, each exercising meaningful influence.

Shared Determination

Both why data is processed and how data is processed must be jointly influenced.

Obligations of Joint Controllers

  • Determine their respective responsibilities
  • Document those responsibilities in a formal arrangement
  • Make the essence of the arrangement available to data subjects
  • Ensure data subject rights can be effectively exercised

Key Principles

Data Subject Rights

Data subjects may exercise rights against any joint controller, regardless of internal allocations.

Liability Persists

Liability principles under Articles 82 and 83 continue to apply irrespective of internal responsibility allocations.

Transparency Mandatory

The essence of the arrangement must be made available to data subjects to enable informed rights exercise.

Core Elements of Joint Controllership

Joint Determination

Joint determination occurs where multiple parties influence why data is processed and how data is processed. Influence may be direct, indirect, parallel, or complementary — and need not be equal.

Example: Joint Controllers

A retailer and a loyalty-programme operator jointly design customer profiling criteria, marketing objectives, and reward calculations. Both determine purposes and means — both are likely joint controllers.

Forms of Influence

Direct

Explicit decisions on processing design

Indirect

Influence through platform configuration

Parallel

Simultaneous independent decisions

Complementary

Decisions that complete each other

Counterexample: Processor

A cloud hosting provider stores customer data solely under client instructions. The provider does not determine purposes and acts as a processor under Article 28 rather than a joint controller under Article 26.

Common Purpose and Shared Means

Common Purpose

Common purpose does not require identical interests. Controllers may pursue separate commercial objectives through the same processing ecosystem. Regulatory analysis focuses on convergence of decision-making.

Social media platform and advertiser jointly establish targeting parameters. The platform seeks advertising revenue; the advertiser seeks customer acquisition. Purposes differ commercially but converge operationally.

Shared Means

Joint influence over key means may establish joint controllership even where purposes differ. Means include:

Data Architecture

Data categories, collection mechanisms, technical architecture, access models

Processing Logic

Algorithms, profiling logic, retention periods

Major CJEU Cases Defining Article 26

1

Wirtschaftsakademie (C-210/16)

Administrator of a Facebook fan page was found to participate in determining processing. Selection of audience parameters created influence over purposes and means. Partial influence may create joint controllership — technical ownership is not required.

2

Fashion ID (C-40/17)

Website operator embedding a Facebook Like button became joint controller regarding collection and transmission phases only. Joint controllership may apply only to specific processing stages.

3

Jehovah's Witnesses (C-25/17)

Religious organisation and individual members jointly determined processing activities. Formal access to data was not required. Organisational influence may create controllership even without direct possession of personal data.

Segmented Joint Controllership

The Segmentation Principle

Following Fashion ID and subsequent regulatory guidance, joint controllership is not binary. Organisations may be joint controllers for one processing activity but not another — responsibility follows actual participation at each stage.

This means Article 26 assessments must be conducted on a processing-activity-by-processing-activity basis, not at the level of the overall relationship.

Practical Implications

  • Map each discrete processing activity separately
  • Assess influence at each stage independently
  • Document which parties are joint controllers for which activities
  • Ensure arrangements reflect segmented responsibilities accurately
  • Review arrangements when processing activities change

This diagram illustrates how joint controllership may apply to only certain stages of a processing chain — a critical insight for practitioners designing Article 26 arrangements.

Elements Required in an Article 26 Arrangement

Allocation of GDPR Responsibilities

Rights Handling

Access, rectification, erasure, restriction, portability, and objection requests

Transparency Obligations

Privacy notices, information provision, and data subject communications

Security and Incidents

Security obligations, incident management, and regulatory engagement

Governance Controls

Record keeping, impact assessments, international transfer governance, vendor management, and data quality

Transparency Requirements

The arrangement must reflect actual operational reality, not merely legal aspirations. Data subjects must understand who is involved, who performs which obligations, and how rights may be exercised.

Rights Management in Practice

Controllers must coordinate across all rights types:

  • Access, rectification, and erasure requests
  • Restriction and portability requests
  • Objection requests

Articles Intersecting with Article 26

Foundational Governance

Article 4

Definitions

Article 5

Principles relating to processing

Article 6

Lawfulness of processing

Article 7

Conditions for consent

Article 9

Special category data

Article 10

Criminal offence data

Accountability Framework

Article 24

Responsibility of the controller

Article 25

Data protection by design and default

Article 26

Joint controllers

Article 28

Processors

Article 29

Processing under authority

Transparency, Rights, Security & Enforcement

Transparency and Rights (Articles 12–22)

Security and Risk (Articles 30–36)

International Transfers & Enforcement

Articles 44–49

International transfers framework

Articles 82–84

Compensation, administrative fines, and penalties

Comparison of Controller Roles and Responsibilities

Processors and Sub-Processors

Processor (Article 28)

A processor acts on controller instructions and does not determine purposes or means of processing. Processors are governed primarily by Article 28 and must operate under a data processing agreement.

Typical Examples

  • SaaS hosting provider
  • Managed backup provider
  • Outsourced payroll processor

Sub-Processor

A sub-processor is engaged by a processor to support processor services. Sub-processors are subject to the controller-approved processing chain and must operate under equivalent contractual obligations.

Key Distinguishing Question

Does the party exercise any meaningful influence over why or how data is processed? If yes, they may be a joint controller — not a processor.

Use this decision framework as a starting point when classifying parties in a data processing relationship. Always validate against operational reality.

Entangled Risk Domains: Governance, Legal, Regulatory & Cyber

Governance Risk

  • Ambiguous ownership
  • Fragmented accountability
  • Inconsistent decision-making
  • Creates privacy control gaps

Legal Risk

  • Incorrect controller classification
  • Defective contracts
  • Invalid lawful basis
  • Exposure to enforcement action

Regulatory Risk

  • Supervisory investigations
  • Corrective orders
  • Administrative fines

Cybersecurity Risk

  • Shared attack surfaces
  • Uneven security maturity
  • Third-party compromise propagation

Extended Risk Domains: Third-Party, Data Quality, AI & Analytics

Third-Party Risk

  • Vendor dependencies
  • Subprocessor exposure
  • Supply-chain vulnerabilities

Data Quality Risk

  • Inconsistent records
  • Conflicting updates
  • Synchronisation failures

AI and Analytics Risk

  • Profiling bias
  • Automated decision opacity
  • Inferential privacy risks

Operational, Incident & Rights Risk Domains

Cross-Border Transfer Risk

Inadequate safeguards, jurisdictional conflicts, government access concerns

Identity and Access Management Risk

Excessive privileges, orphaned accounts, segregation failures

Incident Response Risk

Unclear notification ownership, delayed containment, inconsistent communications

Records Management Risk

Retention conflicts, inconsistent deletion, litigation hold failures

Data Subject Rights Risk

Missed deadlines, fragmented fulfilment, incomplete responses

Contractual Risk

Conflicting obligations, undefined responsibilities, indemnification disputes

Operational Risk

Process breakdowns, escalation failures, workflow fragmentation

Ethical Risk

Excessive surveillance, unfair profiling, manipulative processing

Strategic, Financial & Reputational Risk Domains

Reputational Risk

  • Publicised violations
  • Customer distrust
  • Partner confidence erosion

Financial Risk

  • Litigation costs
  • Compensation claims
  • Remediation expenses

Business Continuity Risk

  • Controller dependency
  • Service interruption
  • Data availability issues

Intellectual Property Risk

  • Shared analytics models
  • Joint datasets
  • Ownership disputes

Strategic Risk

  • Misaligned objectives
  • Governance conflicts
  • Long-term compliance instability

Twenty Cross-Cutting Controls: Part 1 (Controls 1–10)

The following technical and organisational controls form the foundation of a robust Article 26 compliance programme. Each control addresses specific accountability and governance obligations.

1

Joint Controller Governance Charter

Defines accountability structure, maps GDPR obligations, and establishes escalation paths across all joint controllers.

2

RACI Matrix for GDPR Obligations

Defines Responsible, Accountable, Consulted, and Informed parties for every GDPR obligation — eliminating ambiguity.

3

Processing Activity Mapping

Comprehensive data flow mapping that identifies shared processing decisions across all joint controllers.

4

Joint Records of Processing Activities

Harmonised Article 30 records with consistent processing inventories maintained across all parties.

5

Data Classification Framework

Consistent classification across controllers with standardised handling requirements for each data category.

1

Privacy-by-Design Review Process

Embedded architecture reviews with early risk identification before processing activities are deployed.

2

Shared DPIA Methodology

Common risk scoring and consistent mitigation criteria applied across all joint controller processing activities.

3

Lawful Basis Governance Control

Validates legal basis assignment and ensures alignment among all controllers for each processing activity.

4

Consent Lifecycle Management

Manages collection, recording, withdrawal, and synchronisation of consent across all joint controllers.

5

Rights Request Orchestration Platform

Tracks data subject rights requests across all controllers and provides full auditability of fulfilment.

Twenty Cross-Cutting Controls: Part 2 (Controls 11–20)

Data Lineage Monitoring

Tracks movement and transformation of personal data across the joint controller ecosystem to support accountability.

Identity and Access Governance

Enforces least privilege, role-based access, and segregation of duties across all joint controller systems.

Encryption Programme

Encryption in transit, encryption at rest, and key governance across all shared processing environments.

Security Event Monitoring

Centralised logging, correlation analysis, and threat detection across the joint controller environment.

Breach Coordination Framework

Shared incident procedures, notification workflows, and regulatory reporting ownership clearly defined.

Third-Party Risk Management

Supplier due diligence, security reviews, and ongoing monitoring of all vendors in the processing chain.

Cross-Border Transfer Governance

SCC management, transfer impact assessments, and jurisdiction monitoring for all international data flows.

Retention and Deletion Orchestration

Consistent retention schedules and coordinated deletion processes across all joint controllers.

Continuous Compliance Assurance

Regular audits, testing, and control validation to maintain ongoing compliance across the joint controller arrangement.

Metrics and Accountability Dashboard

Rights response performance, breach indicators, compliance KPIs, and executive oversight reporting.

Advanced Practitioner Challenges

Misclassification Risk

Organisations frequently classify relationships as controller-processor or independent controller arrangements. Actual facts may indicate joint controllership. Regulators focus on operational reality, not contractual labels.

Partial Joint Controllership

Different processing stages may create different responsibilities. Analysis must be processing-specific.

A website operator and social media platform may be joint controllers during collection and transmission — but not necessarily joint controllers during later platform analytics.

Multi-Party Ecosystems

Modern ecosystems increasingly involve complex arrangements that require careful Article 26 analysis at every processing layer:

Data Clean Rooms

Shared analytics environments with complex influence patterns

Advertising Networks

Multi-party targeting and measurement ecosystems

Identity Providers

Federated identity and authentication services

AI Platforms

Shared model training and inference environments

Conclusion

Article 26 represents one of the GDPR's most sophisticated accountability mechanisms. It prevents responsibility fragmentation in collaborative data ecosystems and is grounded in functional reality rather than contractual labels.

Integrated Governance

Compliance requires coordinated governance structures that span all joint controllers, not merely a signed agreement.

Operational Controls

Coordinated operational controls must be embedded across all processing activities and technical systems.

Rights Management

Synchronised rights management ensures data subjects can effectively exercise rights against any joint controller.

Transparent Accountability

Transparent accountability must reflect operational reality — not aspirational contractual language.

Risk-Based Safeguards

Technical and organisational safeguards must be calibrated to the actual risk profile of joint processing activities.

Datari Home