A comprehensive framework for understanding, implementing, and governing joint controllership under the General Data Protection Regulation.
GDPR Article 26 establishes the legal framework governing situations where two or more controllers jointly determine the purposes and means of processing personal data. It addresses accountability gaps that can emerge when multiple organisations collaborate in processing activities.
Article 26 operationalises the GDPR accountability principle by requiring transparent allocation of responsibilities among joint controllers. The article reflects the GDPR's broader governance philosophy that responsibility follows influence over processing decisions.
Regulatory authorities and courts consistently emphasise that factual reality prevails over contractual labels.
The jurisprudence of the Court of Justice of the European Union has significantly expanded the interpretation of joint controllership beyond traditional business partnerships.
The provision directly targets responsibility fragmentation in collaborative data ecosystems where multiple parties share influence.
Jointly determine processing purposes and means, each exercising meaningful influence.
Both why data is processed and how data is processed must be jointly influenced.
Data subjects may exercise rights against any joint controller, regardless of internal allocations.
Liability principles under Articles 82 and 83 continue to apply irrespective of internal responsibility allocations.
The essence of the arrangement must be made available to data subjects to enable informed rights exercise.
Joint determination occurs where multiple parties influence why data is processed and how data is processed. Influence may be direct, indirect, parallel, or complementary — and need not be equal.
A retailer and a loyalty-programme operator jointly design customer profiling criteria, marketing objectives, and reward calculations. Both determine purposes and means — both are likely joint controllers.
Explicit decisions on processing design
Influence through platform configuration
Simultaneous independent decisions
Decisions that complete each other
A cloud hosting provider stores customer data solely under client instructions. The provider does not determine purposes and acts as a processor under Article 28 rather than a joint controller under Article 26.
Common purpose does not require identical interests. Controllers may pursue separate commercial objectives through the same processing ecosystem. Regulatory analysis focuses on convergence of decision-making.
Social media platform and advertiser jointly establish targeting parameters. The platform seeks advertising revenue; the advertiser seeks customer acquisition. Purposes differ commercially but converge operationally.
Joint influence over key means may establish joint controllership even where purposes differ. Means include:
Data categories, collection mechanisms, technical architecture, access models
Algorithms, profiling logic, retention periods

Administrator of a Facebook fan page was found to participate in determining processing. Selection of audience parameters created influence over purposes and means. Partial influence may create joint controllership — technical ownership is not required.
Website operator embedding a Facebook Like button became joint controller regarding collection and transmission phases only. Joint controllership may apply only to specific processing stages.
Religious organisation and individual members jointly determined processing activities. Formal access to data was not required. Organisational influence may create controllership even without direct possession of personal data.
Following Fashion ID and subsequent regulatory guidance, joint controllership is not binary. Organisations may be joint controllers for one processing activity but not another — responsibility follows actual participation at each stage.
This means Article 26 assessments must be conducted on a processing-activity-by-processing-activity basis, not at the level of the overall relationship.
This diagram illustrates how joint controllership may apply to only certain stages of a processing chain — a critical insight for practitioners designing Article 26 arrangements.
Access, rectification, erasure, restriction, portability, and objection requests
Privacy notices, information provision, and data subject communications
Security obligations, incident management, and regulatory engagement
Record keeping, impact assessments, international transfer governance, vendor management, and data quality
The arrangement must reflect actual operational reality, not merely legal aspirations. Data subjects must understand who is involved, who performs which obligations, and how rights may be exercised.
Controllers must coordinate across all rights types:
Definitions
Principles relating to processing
Lawfulness of processing
Conditions for consent
Special category data
Criminal offence data
Responsibility of the controller
Data protection by design and default
Joint controllers
Processors
Processing under authority
International transfers framework
Compensation, administrative fines, and penalties

A processor acts on controller instructions and does not determine purposes or means of processing. Processors are governed primarily by Article 28 and must operate under a data processing agreement.
A sub-processor is engaged by a processor to support processor services. Sub-processors are subject to the controller-approved processing chain and must operate under equivalent contractual obligations.
Does the party exercise any meaningful influence over why or how data is processed? If yes, they may be a joint controller — not a processor.
Use this decision framework as a starting point when classifying parties in a data processing relationship. Always validate against operational reality.
Inadequate safeguards, jurisdictional conflicts, government access concerns
Excessive privileges, orphaned accounts, segregation failures
Unclear notification ownership, delayed containment, inconsistent communications
Retention conflicts, inconsistent deletion, litigation hold failures
Missed deadlines, fragmented fulfilment, incomplete responses
Conflicting obligations, undefined responsibilities, indemnification disputes
Process breakdowns, escalation failures, workflow fragmentation
Excessive surveillance, unfair profiling, manipulative processing
The following technical and organisational controls form the foundation of a robust Article 26 compliance programme. Each control addresses specific accountability and governance obligations.
Defines accountability structure, maps GDPR obligations, and establishes escalation paths across all joint controllers.
Defines Responsible, Accountable, Consulted, and Informed parties for every GDPR obligation — eliminating ambiguity.
Comprehensive data flow mapping that identifies shared processing decisions across all joint controllers.
Harmonised Article 30 records with consistent processing inventories maintained across all parties.
Consistent classification across controllers with standardised handling requirements for each data category.
Embedded architecture reviews with early risk identification before processing activities are deployed.
Common risk scoring and consistent mitigation criteria applied across all joint controller processing activities.
Validates legal basis assignment and ensures alignment among all controllers for each processing activity.
Manages collection, recording, withdrawal, and synchronisation of consent across all joint controllers.
Tracks data subject rights requests across all controllers and provides full auditability of fulfilment.
Tracks movement and transformation of personal data across the joint controller ecosystem to support accountability.
Enforces least privilege, role-based access, and segregation of duties across all joint controller systems.
Encryption in transit, encryption at rest, and key governance across all shared processing environments.
Centralised logging, correlation analysis, and threat detection across the joint controller environment.
Shared incident procedures, notification workflows, and regulatory reporting ownership clearly defined.
Supplier due diligence, security reviews, and ongoing monitoring of all vendors in the processing chain.
SCC management, transfer impact assessments, and jurisdiction monitoring for all international data flows.
Consistent retention schedules and coordinated deletion processes across all joint controllers.
Regular audits, testing, and control validation to maintain ongoing compliance across the joint controller arrangement.
Rights response performance, breach indicators, compliance KPIs, and executive oversight reporting.
Organisations frequently classify relationships as controller-processor or independent controller arrangements. Actual facts may indicate joint controllership. Regulators focus on operational reality, not contractual labels.
Different processing stages may create different responsibilities. Analysis must be processing-specific.
A website operator and social media platform may be joint controllers during collection and transmission — but not necessarily joint controllers during later platform analytics.
Modern ecosystems increasingly involve complex arrangements that require careful Article 26 analysis at every processing layer:
Shared analytics environments with complex influence patterns
Multi-party targeting and measurement ecosystems
Federated identity and authentication services
Shared model training and inference environments
Article 26 represents one of the GDPR's most sophisticated accountability mechanisms. It prevents responsibility fragmentation in collaborative data ecosystems and is grounded in functional reality rather than contractual labels.
Compliance requires coordinated governance structures that span all joint controllers, not merely a signed agreement.
Coordinated operational controls must be embedded across all processing activities and technical systems.
Synchronised rights management ensures data subjects can effectively exercise rights against any joint controller.
Transparent accountability must reflect operational reality — not aspirational contractual language.
Technical and organisational safeguards must be calibrated to the actual risk profile of joint processing activities.
Article 26 (Joint Controllers)