Joint Controller
A joint controller is one of two or more organisations that together decide why and how the same personal data is processed. Because they share responsibility for those decisions, they generally share accountability for how that data is handled. This concept sits under the EU GDPR and, in similar form, the UK GDPR; it does not by itself cover how the organisations must divide their specific duties or how they arrange their relationship in detail.
Under Article 26 of the EU GDPR (and the equivalent provision in the UK GDPR), joint controllers exist where two or more controllers jointly determine the purposes and means of processing the same personal data. Joint controllership is distinct from a controller-processor relationship: a processor acts only on a controller's documented instructions and does not determine the purposes and means, whereas each joint controller participates in that determination. The joint nature turns on genuine shared decision-making over purposes and means; parties that each determine processing for separate purposes are generally separate controllers rather than joint controllers, and the factual arrangement, not merely a contractual label, drives the classification. This entry defines the role and its basis for allocation of responsibility; it does not detail the required transparency arrangement between the parties, the apportionment of individual obligations, cross-border transfer mechanics, retention, or enforcement consequences, and treatment may differ under regimes outside the EU and UK GDPR.
Why it matters
Joint controllership matters because it determines where accountability lands when more than one organisation shapes the same processing activity. Under the EU GDPR and, in similar form, the UK GDPR, parties that jointly determine the purposes and means of processing the same personal data share responsibility for that processing. This means an organisation cannot assume that using another party's platform, or contributing to a shared processing arrangement, automatically makes it a mere processor or removes it from controller-level obligations. The classification turns on the factual reality of who decides why and how the data is processed, not on the label the parties assign in a contract.
Getting the classification wrong has practical consequences for how obligations are understood and evidenced. An organisation that believes it is only a processor, when it in fact participates in determining purposes and means, may fail to recognise responsibilities it actually bears as a joint controller. Because accountability under GDPR-style frameworks requires demonstrable evidence rather than stated intent, misclassification can leave gaps that are difficult to defend to a supervisory authority or to affected individuals. Conversely, treating genuinely separate controllers as joint controllers can create confusion about who is answerable for which decisions.
This entry addresses the existence and basis of the joint controller role. It does not set out how the parties must arrange transparency between themselves, how individual obligations are apportioned, or the mechanics of cross-border transfers, retention, or enforcement. Those aspects are governed by further provisions and by the specific arrangement the parties put in place, and treatment may differ under regimes outside the EU and UK GDPR.
Who it's relevant to
Inside Joint Controller
Common questions
Answers to the questions practitioners most commonly ask about Joint Controller.