Data Protection HubCase Law

CJEU, judgment of 5 June 2018, C-210/16, Wirtschaftsakademie Schleswig-Holstein

The operator of a Facebook fan page is jointly responsible with the network for the processing of visitors' data. Landmark decision on the broad interpretation of joint controllership under Article 26 GDPR.

The CJEU (Grand Chamber) held that the operator of a Facebook fan page is jointly responsible with the network for the processing of visitors' data. The decision was still handed down under the earlier Data Protection Directive 95/46/EC, but its principles continue to apply to Article 26 GDPR.

1. Facts

The Wirtschaftsakademie Schleswig-Holstein, a private education provider, operated a fan page on the social network Facebook. When the page was accessed, Facebook collected data of the visitors by means of cookies, including data of visitors without a Facebook account of their own, and made anonymized usage statistics available to the operator on that basis. The competent supervisory authority, the Independent State Center for Data Protection of Schleswig-Holstein, ordered the Wirtschaftsakademie to deactivate the fan page because the visitors were not informed of the collection of their data. It was in dispute whether the fan page operator was jointly responsible for that processing.

2. Decision

2.1 Joint controllership of the fan page operator

The Court classified the fan page operator as a joint controller together with the network. By setting up the page, the operator enables the network to collect the visitors' data. At the same time, the operator takes part in determining the means, because it has a say in the parametrization of the statistics functions, whose collection it triggers and uses to its own advantage.

2.2 No equivalent participation, no access to the data required

Joint controllership does not presuppose that all those involved decide on the processing to the same extent. Controllership may take different forms. It is likewise immaterial that the fan page operator receives only anonymized statistics and has no access to the personal raw data. What is decisive is the influence exerted on the processing, not access to the data.

3. Significance for practice

The judgment is the landmark decision on the broad interpretation of joint controllership:

  • Anyone who, through decisions of their own, enables and influences another party's data processing may be a joint controller.
  • Equivalent participation is not required; the contributions may carry different weight.
  • Access to the data is not a precondition of controllership.
  • The reasoning extends beyond fan pages to other forms of technically interlinked processing (such as embedded tools and plugins).

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn