Skip to content
+370 5 212 1506 info@dat.lt

Sharing data with a partner: controller, processor or joint controller

24 September 2026 · Good to know

Before you pass personal data to another company, you need to establish what that company will be in relation to the data. If it processes the data on your behalf and on your instructions, it is a processor. If it uses the data for its own purposes, it is a separate controller. If you decide the purposes and means together, you are joint controllers (Article 26(1) GDPR). The role is decided by the facts, not by the title of the contract.

Three things depend on the answer: whether the disclosure itself needs a legal basis, who informs the people concerned, and which agreement you need. Here we cover how to identify the role, why passing data to another controller needs its own basis, and what happens when the role is stated wrongly. We do not go into the contents of a data processing agreement with a processor here.

Three roles and how to tell them apart

A controller is the one who, alone or jointly with others, determines the purposes and means of processing (Article 4(7) GDPR). A processor is the one who processes personal data on behalf of the controller (Article 4(8) GDPR). Everyone who is not the data subject, the controller, the processor or a person under their direct authority is a third party (Article 4(10) GDPR).

The European Data Protection Board (EDPB), in its Guidelines 07/2020 on the concepts of controller and processor (version 2.0, 7 July 2021), gives several practical criteria:

  • a controller does not need to have access to the data itself;
  • joint control can arise not only from a common decision, but also from separate decisions that complement each other and without which the processing would not take place;
  • a shared database or shared infrastructure alone does not mean joint control, if each entity decides its own purposes;
  • within a group of companies, another group company that is neither the controller nor the processor is a third party.

One EDPB example is very close to the situation of one of our clients. A parent company asks its subsidiaries to send employee data for group-wide statistics. Once it receives the data, the parent company is a third party, and when it processes the data for statistics it is a controller.

In Case C-683/21 (5 December 2023), the Court of Justice held that entities can be joint controllers even if they have concluded no arrangement with each other. Joint control therefore comes from what the parties do, not from what they have signed.

Every disclosure needs a legal basis

When you pass data to a processor, it processes the data for your purpose, so this is part of your own processing. When you pass it to another controller, the transfer itself is a separate processing operation. It needs one of the bases in Article 6(1) GDPR. The EDPB stresses in its guidelines that every disclosure of data needs a legal basis and a compatibility assessment, whether the recipient is a separate or a joint controller.

Compatibility means this. Data is collected for specified purposes and not further processed in a manner incompatible with those purposes (Article 5(1)(b) GDPR). If passing data to a partner is a new purpose, you need to assess, among other things, the link between the purposes, the context in which the data was collected, the nature of the data and the possible consequences for the people concerned (Article 6(4) GDPR).

For groups of companies, the Regulation gives one pointer. Group companies may have a legitimate interest in transmitting customer or employee data within the group for internal administrative purposes (Recital 48 GDPR). This is a possibility, not a permission: the legitimate interest must still be assessed and people must be informed. We explain when that basis is enough in our article on legitimate interest.

The duty to inform falls on both sides. The controller passing the data must name the recipients or categories of recipients in its privacy notice (Article 13(1)(e) GDPR). The controller receiving the data, if it did not obtain it from the person, must inform the person itself (Article 14(1) GDPR), save in the cases listed in Article 14(5) GDPR, usually within one month at the latest (Article 14(3)(a) GDPR).

Example: a register extract for a partner

A client asked whether it could pass a partner an extract from a state register about a legal entity. Such extracts also contain data about natural persons. The client obtained such extracts under a statutory duty that applied to some of its customers. The partner asked for an extract about a person to whom that duty did not apply.

Our answer: no. The client obtained register data for a specific purpose – to meet that legal duty. Where the duty does not apply, that basis does not exist, and the client had no other. Such a transfer could also breach the register’s own rules on data use. If the partner needs the data, it must obtain it itself, on its own basis.

The lesson goes beyond this case. Holding data lawfully does not mean you may pass it on. And having shared similar data before on a different basis does not mean you may share it this time.

Which agreement you need

Processor. You need the contract or other legal act required by Article 28(3) GDPR. If the processor starts deciding the purposes and means of processing itself, it is treated as a controller for that processing (Article 28(10) GDPR). When a data processing agreement is required is covered in Data processing agreement: when required and the risk without one.

Joint controllers. They must, by an arrangement between them, set out transparently who is responsible for which obligation, in particular as regards people’s rights and the duty to inform (Article 26(1) GDPR). The arrangement must reflect the actual roles of each and their relationship with the people concerned, and people must be able to see its essence (Article 26(2) GDPR). The EDPB recommends putting the arrangement into a binding document and notes that obligations need not be split equally. Whatever the parties agree, a person may exercise their rights against each of them (Article 26(3) GDPR). What a joint controller arrangement must cover and who is liable for what is covered in Joint controllers: what the arrangement must cover and who is liable.

Separate controllers. The GDPR does not require any particular form of contract. But the controller must be able to demonstrate compliance (Article 5(2) GDPR). So where data is shared regularly or in large volumes, we recommend a controller-to-controller data sharing agreement: which data, for what purpose and on what basis it is shared, that the recipient will not use it for other purposes, how it is secured and when it is deleted, and how the parties cooperate when a person makes a request or a breach occurs. This is our practice recommendation, not a legal requirement. One group of companies asked for exactly this document when preparing GDPR documentation for its companies.

If the partner is outside the European Economic Area, transfer rules apply as well. We cover them in our article on transferring personal data outside the EEA.

What happens when the role is set wrongly

One company collected customer orders through its platform and passed them to subcontractors who did the work. The platform’s privacy policy said the company would act with the subcontractors as joint controllers. But the subcontractors did the work on the company’s behalf. Our conclusion: a data processing agreement was needed with each subcontractor, and the privacy policy had to be corrected so that people would know in advance to whom and when their data is passed. A wrongly stated role means the notice to people is inaccurate too.

The consequences depend on what was missed:

  • Passing data without a legal basis breaches Articles 5 and 6 GDPR. The fine can reach up to twenty million euros or, for an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR).
  • A missing joint controllership arrangement or data processing agreement breaches the obligations in Articles 26 to 28. The fine can reach up to ten million euros or, for an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR).
  • Where several controllers or processors are involved in the same processing and are responsible for damage, each is held liable for the entire damage (Article 82(4) GDPR). Having paid full compensation, it may claim back the others’ share (Article 82(5) GDPR). So a weaker partner’s mistake can become your cost.

In Case C-683/21 the Court of Justice also held that an administrative fine can be imposed only if the infringement was intentional or negligent. But a controller can be fined for processing carried out on its behalf by a processor, unless the processor acted for its own purposes, departed from the arrangements set by the controller, or acted in a way the controller cannot reasonably be taken to have consented to.

When to call a lawyer

  • when a partner asks for data you obtained from a register, under a legal obligation or for another purpose;
  • when you build a joint product, platform or campaign with another company;
  • when group companies exchange customer or employee data;
  • when a partner wants to use the data it receives for its own purposes too, such as marketing;
  • when a contract or privacy policy describes the roles differently from what actually happens.

Frequently asked questions

Can data be passed freely within a group of companies?

No. Another group company that is neither the controller nor the processor is a third party, so the transfer needs a legal basis and people must be informed. The Regulation recognises that group companies may have a legitimate interest in transmitting data for internal administrative purposes (Recital 48 GDPR), but that interest must be assessed. If the group company is outside the EEA, the rules on transfers to third countries also apply.

Do joint controllers have to sign an agreement?

You become joint controllers even without an agreement if you decide the purposes and means together. But Article 26(1) GDPR requires joint controllers to set out their responsibilities by an arrangement between them. If there is no arrangement, that duty is breached, and a person can still turn to either of them.

Can a partner use the data we pass to it for its own marketing?

Only if it has its own legal basis for that and people have been informed. Your basis for passing the data does not cover the partner’s marketing. Electronic marketing to individuals usually needs prior consent; see our article on direct marketing.

Do we need a person’s consent to pass their data to a partner?

Not necessarily. Any basis in Article 6(1) GDPR can apply, for example performance of a contract, a legal obligation or legitimate interest. The GDPR sets no hierarchy between the bases; consent is the route when no other basis fits, and it must be specific, meaning it must cover that transfer to that recipient for that purpose.

How to start

List to whom you pass data and who passes data to you: partners, group companies, subcontractors. Send us your contracts with them and your privacy notice. We will tell you who is what, where a legal basis is missing and which agreements you need.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles