Skip to main content
Category: Compliance and Monitoring

Joint Controller

Also known as: Joint Controllers
Simply put

A joint controller is one of two or more organisations that together decide why and how the same personal data is processed. Because they share responsibility for those decisions, they generally share accountability for how that data is handled. This concept sits under the EU GDPR and, in similar form, the UK GDPR; it does not by itself cover how the organisations must divide their specific duties or how they arrange their relationship in detail.

Formal definition

Under Article 26 of the EU GDPR (and the equivalent provision in the UK GDPR), joint controllers exist where two or more controllers jointly determine the purposes and means of processing the same personal data. Joint controllership is distinct from a controller-processor relationship: a processor acts only on a controller's documented instructions and does not determine the purposes and means, whereas each joint controller participates in that determination. The joint nature turns on genuine shared decision-making over purposes and means; parties that each determine processing for separate purposes are generally separate controllers rather than joint controllers, and the factual arrangement, not merely a contractual label, drives the classification. This entry defines the role and its basis for allocation of responsibility; it does not detail the required transparency arrangement between the parties, the apportionment of individual obligations, cross-border transfer mechanics, retention, or enforcement consequences, and treatment may differ under regimes outside the EU and UK GDPR.

Why it matters

Joint controllership matters because it determines where accountability lands when more than one organisation shapes the same processing activity. Under the EU GDPR and, in similar form, the UK GDPR, parties that jointly determine the purposes and means of processing the same personal data share responsibility for that processing. This means an organisation cannot assume that using another party's platform, or contributing to a shared processing arrangement, automatically makes it a mere processor or removes it from controller-level obligations. The classification turns on the factual reality of who decides why and how the data is processed, not on the label the parties assign in a contract.

Getting the classification wrong has practical consequences for how obligations are understood and evidenced. An organisation that believes it is only a processor, when it in fact participates in determining purposes and means, may fail to recognise responsibilities it actually bears as a joint controller. Because accountability under GDPR-style frameworks requires demonstrable evidence rather than stated intent, misclassification can leave gaps that are difficult to defend to a supervisory authority or to affected individuals. Conversely, treating genuinely separate controllers as joint controllers can create confusion about who is answerable for which decisions.

This entry addresses the existence and basis of the joint controller role. It does not set out how the parties must arrange transparency between themselves, how individual obligations are apportioned, or the mechanics of cross-border transfers, retention, or enforcement. Those aspects are governed by further provisions and by the specific arrangement the parties put in place, and treatment may differ under regimes outside the EU and UK GDPR.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads need to classify processing relationships accurately, because whether a party is a joint controller, a separate controller, or a processor determines which responsibilities it bears. They should assess the factual decision-making over purposes and means rather than relying on how an agreement is labelled.
Legal and compliance teams
Legal and compliance teams reviewing arrangements between organisations that process the same personal data should test whether the parties jointly determine the purposes and means. This affects how accountability is understood and evidenced, though the detailed apportionment of obligations and the required transparency arrangement fall outside the scope of this classification.
Information governance and data stewardship functions
Governance and stewardship functions mapping data flows and ownership across organisations need to identify where shared decision-making creates joint controllership. Recognising these relationships supports demonstrable accountability, which under GDPR-style frameworks requires evidence rather than stated intent.
Business and platform owners entering shared processing arrangements
Owners of services or platforms that process the same personal data alongside another organisation should not assume that a supplier or partner label settles their status. If they participate in determining why and how the data is processed, they may be a joint controller and share responsibility accordingly.

Inside Joint Controller

Joint Determination of Purposes and Means
A joint controller relationship arises, under the EU and UK GDPR, where two or more controllers jointly determine the purposes and means of processing personal data. The essential feature is shared decision-making over the why and how of processing, rather than one party acting solely on another's instructions.
Arrangement Between the Parties
Joint controllers are generally expected to establish an arrangement that sets out their respective responsibilities for compliance, in particular regarding the exercise of data subject rights and the provision of transparency information. The essence of that arrangement is typically made available to data subjects.
Allocation of Obligations
The arrangement allocates who is responsible for which obligations, such as responding to data subject requests, providing privacy information, and handling other duties. Allocation clarifies internal responsibility but does not, on its own, limit a data subject's ability to exercise rights against either party.
Distinction from Controller-Processor and Separate Controllers
A joint controller differs from a processor, which acts only on a controller's documented instructions, and from independent or separate controllers, who determine purposes and means individually rather than jointly. The classification depends on the actual roles in the processing, not merely on contractual labels.
Data Subject Rights Against Either Party
Regardless of how obligations are divided in the arrangement, data subjects may generally exercise their rights in respect of and against each of the joint controllers. The internal allocation does not override this.

Common questions

Answers to the questions practitioners most commonly ask about Joint Controller.

Does a joint controller arrangement mean each party shares equal responsibility for all processing?
No. Joint controllership means two or more controllers jointly determine the purposes and means of processing, but this does not imply equal or identical responsibility. Under the EU GDPR and UK GDPR, joint controllers are expected to determine their respective responsibilities through an arrangement between them, and responsibility can be allocated according to the actual influence each party has over the relevant processing activity. The allocation should reflect the real-world roles rather than assuming a uniform split. This entry does not address how liability is apportioned in enforcement or litigation, which depends on jurisdiction and the specifics of the case.
Is a joint controller the same as a processor acting on behalf of a controller?
No, and the distinction matters. A processor acts on behalf of and under the instructions of a controller and does not determine the purposes and means of processing. Joint controllers, by contrast, together determine those purposes and means. The relationships are governed differently: a controller-processor relationship generally requires a data processing agreement with specified terms, whereas joint controllers are generally expected to establish an arrangement setting out their respective responsibilities. Mislabeling a joint controllership as a processor relationship can result in the wrong contractual instrument and misallocated obligations. This entry does not cover the full content requirements of either instrument.
What should the arrangement between joint controllers typically cover?
Under the EU GDPR and UK GDPR, joint controllers are generally expected to set out their respective responsibilities in a transparent manner, particularly regarding how data subjects can exercise their rights and who provides required information to them. In practice, the arrangement often addresses which party handles which processing activities, points of contact, and how responsibilities are divided. The specific enforceable requirements are set by the applicable regulation and its interpretation; this entry does not reproduce the exact provisions or prescribe a template, and treatment may differ outside the EU and UK regimes.
How should data subject requests be handled when there are joint controllers?
Data subjects can generally exercise their rights against each joint controller, regardless of how the joint controllers have divided responsibilities between themselves in their arrangement. For this reason, the arrangement typically designates who will handle particular types of requests and how the parties will coordinate to respond within applicable timeframes. Operationally, this usually requires agreed communication channels and clear internal routing so that a request received by one party is actioned appropriately. This entry does not cover the substantive requirements for responding to specific data subject rights, which are addressed separately.
How do we determine whether we are actually in a joint controllership rather than acting independently?
The assessment generally turns on whether the parties jointly determine the purposes and means of the processing, which is a factual question about who actually decides why and how personal data is processed for a given activity. Parties can be independent controllers if each determines purposes and means separately, or joint controllers where they do so together, even if their contributions differ. The analysis should be conducted per processing activity rather than assumed for the entire relationship. This entry describes the concept and does not provide a legal determination for any specific arrangement, which should be assessed against the applicable regime and facts.
What evidence should joint controllers maintain to demonstrate accountability?
Consistent with the accountability principle, joint controllers should generally be able to demonstrate, with documentation, how they have allocated their respective responsibilities and how they meet their obligations. This typically includes the arrangement between them and records reflecting how the agreed responsibilities are operationalized. Accountability under these frameworks requires demonstrable evidence rather than stated intent, so documented and maintained records are important. This entry does not specify records of processing activities requirements or retention obligations, which are governed separately and may differ by jurisdiction.

Common misconceptions

A written arrangement between joint controllers limits each party's liability to only the obligations assigned to it.
The arrangement allocates responsibilities internally, but under the EU and UK GDPR data subjects can generally exercise their rights against each joint controller irrespective of that allocation. The arrangement does not by itself shield a party from a data subject or, depending on the facts, from regulatory scrutiny.
Any two organizations that share personal data are joint controllers.
Joint controllership specifically requires that the parties jointly determine the purposes and means of the processing. Parties that determine purposes and means separately are independent controllers, and a party acting only on another's instructions is a processor. Data sharing alone does not establish joint control; the nature of the decision-making does.
Calling a party a processor or joint controller in a contract settles its legal status.
The classification depends on the actual roles and the degree of influence over purposes and means in practice. A contractual label does not override the factual reality of who determines why and how personal data is processed.

Best practices

Assess the actual decision-making over purposes and means in each processing activity to determine whether the relationship is genuinely joint controllership, separate controllership, or a controller-processor arrangement, rather than relying on contractual labels alone.
Establish a documented arrangement that clearly allocates responsibilities between the parties, particularly for responding to data subject rights requests and for providing transparency information.
Make the essence of the arrangement available to data subjects, and provide a clear point of contact, recognizing that individuals may generally exercise their rights against either joint controller.
Maintain demonstrable evidence of how the arrangement operates in practice, since accountability under these frameworks requires more than a stated allocation of duties.
Revisit the classification and the arrangement when the processing purposes, means, or the roles of the parties change, as the assessment turns on the actual processing rather than a fixed label.
Consult qualified legal advice on jurisdiction-specific treatment, as this entry addresses the joint controller concept under the EU and UK GDPR and does not cover cross-border transfer mechanics, retention rules, enforcement or penalty exposure, or how comparable arrangements are treated under other regimes such as the CCPA and CPRA or HIPAA.