Joint controllership under GDPR Article 26 – when does it apply?
Share
By Mallbutiken · Fact checked October 6, 2026 · GDPR Article 26 and EDPB Guidelines 07/2020
Short answer: Joint controllership arises when two or more controllers jointly determine the purposes and means of processing. Article 26 of the GDPR then requires the parties to openly regulate their respective responsibilities, particularly regarding data subjects' rights and information under Articles 13–14. It is the actual distribution of responsibilities—not the title of the agreement—that determines the role.
- Joint controllers determine key elements of the processing's purposes and means together.
- A standard controller-to-controller cooperation is not automatically joint controllership.
- A processor instead processes data on behalf of the controller.
- Article 26 requires a mutual arrangement regarding the distribution of responsibilities.
- The essential content of the arrangement must be made available to the data subjects.
What is joint controllership?
According to Article 26 of the GDPR, two or more entities are joint controllers when they jointly determine the purposes and means of the processing. The EDPB emphasizes that the assessment must be made based on the actual processing and the parties' real influence.
Joint responsibility does not necessarily mean that the parties are responsible for exactly the same tasks or have identical influence. Their participation may look different, but there must be a common determination such that the processing cannot reasonably be understood as two completely separate processing activities.
Joint controller, controller-to-controller, or processor?
| Relationship | Core question | Typical document |
|---|---|---|
| Joint controllership | Do the parties determine purposes and central means together? | Article 26 arrangement / Joint Controller Arrangement |
| Independent controllers | Does each party decide for their own processing? | Data sharing / controller-to-controller agreement where appropriate |
| Controller + processor | Does the supplier process data only on the controller's behalf and instructions? | Data Processing Agreement (DPA) under Article 28 |
Also read Controller vs. processor – what is the difference? for a broader role analysis.
What should an Article 26 arrangement contain?
The GDPR requires joint controllers to transparently determine their respective responsibilities for compliance with the regulation. In practice, the arrangement should address, among other things:
- which processing activities are covered and their purposes,
- the parties' roles and actual influence,
- legal basis and responsibility for documentation,
- who provides information under Articles 13 and 14,
- how data subjects' rights are received and handled,
- security measures and incident management,
- DPIA and risk assessments where required,
- record of processing activities, retention, and deletion,
- sub-processors, third-country transfers, and further sharing,
- point of contact and how the essential content is made available to data subjects.
What is meant by "purposes and means"?
Purpose answers why personal data is processed. Means concerns how the processing is carried out. All practical or technical details do not need to be jointly decided for joint controllership to arise; particularly significant decisions regarding, for example, data categories, data subjects, storage, and recipients carry significant weight.
A supplier may be permitted to decide on certain non-essential technical details without automatically becoming a controller.
Role assessment step-by-step
- Map the data flow. Which parties collect, access, analyze, or share the data?
- Describe every purpose. Who decides why each specific processing happens?
- Identify central decisions. Who decides data categories, data subjects, recipients, storage, and key functions?
- Test the dependency. Would the processing look significantly different without the other party's decision or participation?
- Classify the relationship. Joint controllers, separate controllers, or controller–processor.
- Document the reasons. Keep a record of why the role was chosen and which processing activities the assessment applies to.
- Establish the right agreement. Article 26 arrangement, C2C agreement, or Article 28 agreement depending on the result.
Common mistakes
The title is used as evidence even though the supplier in practice decides their own purposes.
Two independent controllers can share data without having joint responsibility.
The parties do not know who handles rights, incidents, and transparency.
Article 26 is treated as a purely internal agreement despite the transparency requirement.
Frequently asked questions about GDPR Article 26
Do joint controllers need a written agreement?
Article 26 requires an "arrangement" that must be able to demonstrate how responsibility is divided. In practice, this should be documented in writing and be concrete enough to support accountability.
Are two companies sharing customer data automatically joint controllers?
No. The determining factor is whether they jointly decide the purposes and means of the specific processing.
Can a data subject only contact the party identified in the agreement?
No. The GDPR states that the data subject may exercise their rights against each of the joint controllers.
Can the same partnership involve multiple GDPR roles?
Yes. Parties can be joint controllers for one processing activity, independent controllers for another, and controller–processor in a third data flow. The assessment must be performed per processing activity.
Document data sharing and division of responsibility
Mallbutiken's package includes role assessment, Article 26 arrangement, controller-to-controller agreement, data sharing map, transparency/rights matrix, and Excel logs in Swedish and English.
View Data Sharing Agreement & Joint Controllership GDPR 2026/2027Related guides
- Controller vs. processor – what is the difference?
- Data Processing Agreement – when is it needed and what should be included?
- TIA and SCC under GDPR – international data transfers
Sources
- General Data Protection Regulation (EU) 2016/679, specifically Article 26
- EDPB Guidelines 07/2020 – controller and processor