Data Protection HubIndividual TopicsControllers and Processors

Joint Controllers (Article 26 GDPR)

When two or more bodies are joint controllers: criteria, categories of cases and CJEU case law, as well as the arrangement on the allocation of obligations under Article 26 GDPR, making its essence available to data subjects and joint and several liability.

Joint controllership exists where two or more controllers jointly determine the purposes and means of a processing operation. It must be distinguished from processing on behalf of a controller (one body acts on another's instructions) and from separate controllership (each body decides independently).

Key takeaways

  • Joint controllers are two or more controllers that jointly determine the purposes and means (Article 26(1) GDPR).
  • The threshold is low: the determination need not take place on an equal footing; it is sufficient that a body does not determine the purposes and means alone or that it aligns itself with the other party's decision.
  • Access to the data is not required; what is decisive is the influence on the what for and the how, not the possibility of access.
  • Joint controllers must conclude an arrangement allocating the obligations between them, in particular as regards the rights of data subjects (Article 26(1), second sentence, GDPR).
  • Externally, data subjects may exercise their rights against each controller (Article 26(3) GDPR); liability is joint and several (Article 82 GDPR).

1 Existence of joint controllership

1.1 Basic concept

The assessment proceeds in two steps. First, it must be established for each body involved whether it is a controller at all, that is, whether it co-determines the purposes and the essential means and does not merely act on instructions as a processor. Only then does the question arise whether several controllers determine the purposes and means jointly.

A deliberate, conscious interaction is required. Where several bodies process the same data alongside one another purely by coincidence, without any coordinated determination, there is no joint controllership but separate controllership.

1.2 Criteria

According to the case law, the requirements attaching to the element of acting "jointly" are low:

  • No determination on an equal footing required. It is sufficient that a body does not determine the purposes and means alone or that it aligns itself with the other party's decision. "Jointly" means "together with" or "not alone". Nor must the parties involved pursue the same purposes; it is enough that their decisions complement each other and are mutually dependent.
  • Inseparable processing. A key criterion is that the processing would not be possible without the simultaneous involvement of the parties, so that their processing activities are inextricably linked with one another.
  • No access to the data required. A body may be a joint controller even where it has no access to the data or receives them only in anonymized or pseudonymized form. What is decisive is the influence on the decision, not the possibility of access.
  • Limited scope. Joint controllership extends only as far as the what for and the how are in fact determined jointly. Where a project consists of several work packages or stages, these must be assessed separately if they are not inextricably linked.
  • Purpose or means suffice. Under the interpretive guidance of the supervisory authorities (EDPB, Guidelines 07/2020 on the concepts of controller and processor), not every body must decide on the purpose and the means at the same time. Complementary (converging) decisions suffice, for example where one body provides the means and the other decides to make use of them as well, provided that both exert a tangible influence on the processing.
  • A shared benefit is not sufficient. A merely mutual benefit from a processing operation, including an economic one, does not in itself establish joint controllership; the joint determination of purpose and means remains necessary.

The supervisory authorities illustrate these criteria with examples. They assume joint controllership, for instance, where a travel company, a hotel chain and an airline set up a joint booking platform and decide together on its purposes and essential functions, or where several companies jointly determine the target audience and the data to be analyzed for a joint, co-branded marketing campaign. In the case of a platform that pools data for the complementary research purposes of several institutes, joint controllership may likewise exist for the pooling itself. By contrast, there is no joint controllership where a service provider processes data on behalf of several companies without those companies coordinating purposes and means among themselves, or where data are merely passed along a chain, for example from an employer to the tax authorities, each of which decides independently on its own processing. Where a body merely provides a technical system or an infrastructure without co-determining the purposes of the individual users, it is not a joint controller for that reason alone.

Practical indicators of joint controllership are jointly agreed purposes, a project description drawn up and followed jointly, a shared infrastructure (for example a common database) as well as complex processing operations involving many parties and an unclear allocation of responsibilities.

1.3 Categories of cases

Tends toward joint controllershipTends toward separate controllership (not joint)
Several bodies set up a joint platform or database and decide together on its functions and access rights (for example a travel agency, a hotel chain and an airline with a joint booking platform)Mere transmission of data along a chain, without any joint determination (for example transmission of employee data to the tax authority)
Embedding a social plugin or operating a fan page, insofar as the collection and transmission of visitor data is concernedA bank and a payment service that participate successively in a financial transaction, each with its own purpose
A jointly agreed project in which the processing activities of the parties are inextricably linkedShared use of a corporate group database in which each company uses the data for its own purposes (separate controllership)
A shared infrastructure with coordinated, complementary purposesA reporting body and a credit reference agency, each of which decides independently on its own processing
A joint advertising campaign or online advertising in which several bodies co-determine the targeting and the analysisA group company merely provides a technical system (for example an HR or CRM system) that each of the others uses for its own purposes (processing on behalf of a controller or separate controllership)
A coordinated project with a project description drawn up and followed jointlySuccessive statistical analyses in which each body decides independently on its own step

1.4 Leading judgments of the CJEU

The CJEU has interpreted joint controllership broadly and has developed the criteria set out above in doing so.

JudgmentFactsKey holding
Wirtschaftsakademie (C-210/16)Operator of a Facebook fan pageThe fan page operator is a joint controller together with the network. By setting up the page it makes the collection of data possible and influences that collection through the parameter settings. Joint controllership presupposes neither equal participation nor access to the data.
Jehovah's Witnesses (C-25/17)A religious community and its members engaged in preaching activityParticipation may take different forms and relate to different stages; the community need not have access to the data. Organizing and giving guidance on the activity may in itself establish joint controllership.
Fashion ID (C-40/17)Embedding the Like button on a websiteThe website operator is a joint controller, but only for the operations it co-determines, that is, the collection and transmission of the data, and not for the subsequent processing by the network. Controllership is limited to the individual stages of processing.

1.5 Scope and practical limits

The broad interpretation carries the risk of overextending joint controllership. Three limitations are important in practice:

  • Limitation to the joint stages. A body is a joint controller only for those processing operations it actually co-determines. It bears no responsibility for downstream operations determined solely by the other body (this being the limitation drawn in the Fashion ID judgment).
  • Actual ability to exert influence. What is decisive is whether a body is genuinely able to influence the processing. A party that is merely exposed in fact to a predetermined processing operation, without being able to steer it, is not a joint controller for that reason alone.
  • Narrow subject matter of the assessment. In doubtful cases, the individual processing activity pursued for a specific purpose is to be examined, rather than the cooperation as a whole in blanket fashion. This makes it possible to clarify for which operations a joint determination in fact exists.

2 Arrangement between joint controllers

2.1 Obligation and form

Joint controllers must determine in an arrangement which of them fulfills which obligations under the GDPR, in particular as regards the exercise of the rights of the data subject and the duties to provide information under Articles 13 and 14 GDPR (Article 26(1), second sentence, GDPR). No particular form is prescribed; for evidentiary reasons, a written or electronic version is strongly recommended.

The arrangement is not constitutive: joint controllership arises from the actual joint determination, not from the contract. The absence of an arrangement is subject to fines (Article 83(4)(a) GDPR), but it does not render the processing itself unlawful (CJEU, judgment of 4 May 2023, C-60/22).

2.2 Minimum content

The arrangement must duly reflect the respective actual roles and relationships of the parties vis-à-vis the data subjects (Article 26(2), first sentence, GDPR). Beyond that, it may govern further points, similar to a data processing agreement.

Point to be governedContent
Roles and stagesDescription of which body carries out which processing at which stage
Rights of data subjectsWho responds to requests for access, rectification and erasure; where appropriate, a single point of contact (Article 26(1), third sentence, GDPR)
Duties to provide informationWho informs the data subjects pursuant to Articles 13 and 14 GDPR
Security and data breachesTechnical and organizational measures, notification channels under Articles 33 and 34 GDPR
Data protection impact assessmentCooperation in the assessment under Article 35 GDPR
Legal basesWho determines the legal basis and obtains any consent required
International transfersDetermination of the mechanisms and responsibilities where a third country is involved
TerminationHandling of the data after the end of the cooperation
Liability in the internal relationshipApportionment between the parties for damages and fines

The obligations need not be allocated evenly. An asymmetric allocation is permissible, under which one body assumes certain tasks in full, for example responding to all data subject requests, even where the other body has no access to the data.

2.3 Making the essence available to data subjects

The essence of the arrangement must be made available to the data subjects (Article 26(2), second sentence, GDPR). In practice, this is regularly done in the privacy notice, which discloses that joint controllership exists, who is involved and whom data subjects may contact.

Irrespective of the internal allocation, the data subject may exercise his or her rights in respect of and against each of the controllers (Article 26(3) GDPR). Externally, joint controllers are jointly and severally liable (Article 82 GDPR); the internal apportionment follows the arrangement. Joint controllership brings no relief as regards the legal basis: each party requires a legal basis of its own under Article 6 GDPR, and there is no group privilege.

Unlike in the case of processing on behalf of a controller, joint controllers are third parties and recipients in relation to one another (Article 4(9) and (10) GDPR); the joint determination of the purposes specifically does not privilege the passing on of data. Where one body passes data to the other or makes them accessible to it, that operation is therefore a step of transmission that must be justified in its own right and requires its own legal basis under Article 6 GDPR (and, in the case of special categories, Article 9 GDPR in addition). The arrangement under Article 26 GDPR does not replace that legal basis; it presupposes it.

In addition, each joint controller may be the sole addressee of measures taken by the supervisory authority. Infringements of the obligations under Article 26 GDPR, in particular the absence of the arrangement, are subject to fines (Article 83(4)(a) GDPR, up to EUR 10 million or 2% of the total worldwide annual turnover of the preceding financial year).

Joint controllership poses the greatest challenges of all the roles: it gives rise to joint external liability of all parties involved, which also covers infringements committed by the other party, and it requires a contractual arrangement in the internal relationship. Where joint controllership is a possibility, it should therefore be examined carefully whether it really covers all parties and all processing operations or whether it is confined to particular sub-areas, work packages or stages.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn