Skip to content
+370 5 212 1506 info@dat.lt

Joint controllers: what the arrangement must cover and who is liable

25 September 2026 · Good to know

When two organisations jointly determine the purposes and means of processing, they are joint controllers and must set out, in an arrangement between them, who is responsible for which GDPR obligation (Article 26(1) GDPR). People must be able to see the essence of that arrangement (Article 26(2) GDPR). But the arrangement binds only the parties: a person can exercise their rights against each of them (Article 26(3) GDPR), and each is liable for the entire damage (Article 82(4) GDPR).

How to tell whether a partner is a processor, a separate controller or a joint controller is covered in our article Sharing data with a partner: controller, processor or joint controller. This article is about what happens once the answer is “joint”: where it usually arises, what the arrangement must cover and how liability is shared.

Where joint control arises without anyone noticing

A joint event or campaign. The European Data Protection Board (EDPB), in Guidelines 07/2020, gives an example: two companies organising a joint event merge their customer data into an invitation list and decide together on sending invitations, collecting feedback and later marketing. For the event data they can be regarded as joint controllers.

A page on a social network. In case C-210/16 (5 June 2018) the Court of Justice held that the administrator of a fan page on a social network, by setting parameters according to its target audience and business objectives, takes part in determining the purposes and means of processing visitors’ data. It is therefore a joint controller with the platform.

A plugin or button on a website. In case C-40/17 (29 July 2019) the Court held that a website operator which embeds a social network plugin, through which visitors’ data is sent to the plugin provider, can be regarded as a joint controller for the collection and transmission of that data.

Both judgments were given under the former Directive 95/46/EC. The EDPB notes that they remain valid under the GDPR, because the elements of the concept have not changed (footnote 18 of the guidelines).

A shared platform or shared surveillance. In the EDPB example, a travel agency, a hotel chain and an airline that build a joint booking platform become joint controllers for it. In our practice, a similar question came from an organisation that ran video surveillance together with another entity.

Joint control covers only the joint part

Joint responsibility covers only the processing operations whose purposes and means the parties determined together. An entity is not a controller for earlier or later operations in the chain whose purposes and means it did not determine (C-40/17, paragraphs 74 and 85). The website operator is responsible for collecting the data and transmitting it to the plugin provider, but not for what the provider does with it afterwards. The EDPB travel example says the same: outside the joint platform, each company remains a separate controller.

Each joint controller needs its own legal basis. In C-40/17 the Court said that each of them must pursue a legitimate interest where the processing relies on it (paragraph 96). The EDPB adds that joint control does not give the controller receiving the data a right to use it for further purposes of its own (footnote 76 of the guidelines).

What the arrangement must cover

The GDPR requires three things. The arrangement sets out transparently who is responsible for which obligation, in particular for data subjects’ rights and for providing information under Articles 13 and 14, unless and in so far as this is already set by law (Article 26(1) GDPR). It duly reflects each party’s actual role and relationship with data subjects (Article 26(2) GDPR). And it may designate a single contact point for data subjects.

In Guidelines 07/2020 the EDPB explains what is worth agreeing:

  • who applies the principles and on what legal basis, who is responsible for security, breach notifications, impact assessments, engaging processors, transfers outside the EEA and contact with people and with the supervisory authority (paragraph 166);
  • what data, whose and for what purpose is processed (paragraph 175);
  • who informs people, how, and who answers their requests (paragraph 177);
  • how the parties pass on requests to each other, so that a person does not have to find the “right” addressee (paragraph 189);
  • how the parties deal with the supervisory authority (paragraph 190).

Duties need not be split equally. Joint responsibility does not mean equal responsibility: the parties may be involved at different stages and to different degrees (C-210/16, paragraph 43). But the split must match what actually happens (paragraph 178 of the EDPB guidelines). The GDPR does not prescribe a form, but the EDPB recommends a binding document, such as a contract (paragraph 173). Only then can one party require the other to do what it took on.

Impact assessment. If the joint processing needs a data protection impact assessment, one assessment can be done. The GDPR allows a single assessment to cover a set of similar operations that present similar high risks (Article 35(1) GDPR). The EDPB adds that the assessment should state which party is responsible for which measures (footnote 75 of the guidelines). When an organisation asked whether two joint controllers could commission one assessment of shared video surveillance, our view was: yes, but the purposes and means of both controllers must be assessed, almost separately for each. What an assessment involves and how long it takes is covered in our article on the data protection impact assessment.

What people must be told

A person must be able to see the essence of the arrangement (Article 26(2) GDPR). The Regulation does not say what the “essence” is. The EDPB recommends that it cover at least all the information under Articles 13 and 14, stating for each element which controller is responsible for it, and the contact point if one is designated (paragraph 180 of the guidelines). The controllers choose how to provide it, for example in the privacy notice (paragraph 181).

In practice this means the privacy notice must explain both controllers. One of our lawyers, assessing a planned project, noted: if any controllers turn out to be joint, a joint controllership arrangement will be needed, and the privacy notices will have to cover both controllers, possibly as two separate notices.

Who is liable when something goes wrong

Damage. Where several controllers are involved in the same processing and are liable for the damage, each is held liable for the entire damage (Article 82(4) GDPR). A controller that has paid full compensation can claim back the other parties’ shares (Article 82(5) GDPR). A controller is exempt only if it proves that it is not in any way responsible for the event giving rise to the damage (Article 82(3) GDPR). So the arrangement does not change your liability towards the person, but it can shape from whom, and how much, you recover: under Article 82(5) GDPR each pays back the part matching its responsibility for the damage.

The supervisory authority. VDAI is not bound by the arrangement, either as to who counts as a joint controller or as to the contact point. It can approach any of the joint controllers (paragraph 191 of the EDPB guidelines).

Fines. A missing arrangement, or one that does not reflect the parties’ actual roles, breaches Article 26 GDPR. The fine can reach ten million euros or, for an undertaking, 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). For a public authority or body the fine for such a breach is up to 0.5 % of its budget for the current year and other gross annual income received in the previous year, but no more than thirty thousand euros (Article 33(1) of the Law on the Legal Protection of Personal Data, ADTAĮ). If the body carries out commercial activity, the general GDPR fines apply (Article 33(3) ADTAĮ).

What most often goes wrong

  • There is no arrangement. The parties have worked together for years, but nobody wrote down who answers requests or reports a breach. When a complaint arrives, each thinks it is the other’s job.
  • The arrangement does not match reality. The document calls one party a processor, although it decides the purposes itself. The EDPB stresses that the facts count, not the formal label (paragraph 52 of the guidelines).
  • People do not know about the second controller. The privacy notice names only one company, although both use the data.
  • Requests are “sent elsewhere”. The EDPB considers that requiring a person to contact only the contact point would be an excessive burden (paragraph 189).
  • Joint control is stretched too far. A partner starts using data from the event list for its own marketing, although it has no legal basis of its own for that.

When to call a lawyer

  • when you organise a joint event, campaign, platform or project with another organisation;
  • when you use social network pages, their analytics or plugins on your website and do not know what you are responsible for;
  • when you share video surveillance of premises with another entity;
  • when a partner offers its standard arrangement that shifts all responsibility to you;
  • when you receive a request or complaint from a person about joint processing.

Frequently asked questions

Can we agree that only the partner will answer all requests?

Yes, between yourselves you can split duties this way and designate a contact point. But the person can still come to you, and you cannot simply redirect them (Article 26(3) GDPR). Provide in the arrangement how you will pass a request on to the partner without delay and who will answer.

Are we responsible for everything the platform does with our page visitors’ data?

Not for everything. Joint responsibility covers only the operations whose purposes and means you determined together, for example collecting data through your page or website (C-40/17, paragraph 85). The platform is responsible for what it later does for its own purposes. But you are responsible for the joint part, including information and the legal basis.

Does the arrangement have to be a separate document?

The GDPR does not prescribe a form. The arrangement can be an annex or a section of the main contract. The EDPB recommends making it a binding document so that it can be enforced and proved (paragraph 173 of the guidelines). What matters most is that it states clearly who does what.

Does the arrangement protect us from a person’s claim for damages?

No. Towards the person, each joint controller is liable for the entire damage (Article 82(4) GDPR). The arrangement helps determine how you later share it between yourselves (Article 82(5) GDPR).

How to start

List the projects in which you decide together with another organisation what data to collect and how to use it: events, campaigns, platforms, social network pages, shared surveillance. Send us the documents signed with the partners and your privacy notice. We will tell you where an arrangement is missing and what it needs to cover.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles