GDPR Article 26: Joint Controllers

GDPR Article 26: Joint Controllers

Article 26 of the GDPR explained

When two or more controllers jointly determine the purposes and means of processing, they must:

  • Clearly define their respective responsibilities (information, exercise of rights, security, etc.);
  • Formalise their agreement, particularly in a clear contract accessible to the data subjects;
  • Allow data subjects to exercise their rights with either of the controllers.

Why This Article Is Important for Your GDPR Compliance

Partnerships, commercial co-responsibilities or joint projects are frequent. This article ensures legal clarity between the parties, and prevents responsibility from being unclear in the event of a dispute or a complaint from a data subject.

How to Comply with GDPR Article 26?

  • Identify situations of joint controllership (co-management, projects with partners).
  • Draft a clear agreement between the parties, with a division of obligations.
  • Make the elements of this agreement available to data subjects (particularly in your privacy policy).
  • Prepare to manage data subject requests in a coordinated manner.

GDPR Article 26 Application Examples

  • A marketing agency and its client jointly determine the purposes of a targeted campaign.
  • An online platform and a logistics provider share the management of customer data.
  • Two university institutions co-manage a student database for a common programme.

Related Resources

Accelerate Your Compliance in a Few Clicks

With our all-in-one solution, you can easily accelerate and ensure your compliance:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Educate your teams with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our GDPR self-assessment, free and without obligation.

GDPR: Self-assess now