| name | joint-controller-art26 |
| title | Managing Joint Controller Arrangements |
| description | Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allocation of responsibilities, and transparency obligations. Activate when two or more controllers jointly determine purposes and means of processing, or when evaluating shared data platforms. Keywords: joint controller, Article 26, shared responsibility, arrangement, joint determination. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/joint-controller-art26 |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Managing Joint Controller Arrangements
Overview
Article 26 applies when two or more controllers jointly determine the purposes and means of processing. Joint controllers must enter into an arrangement that transparently determines their respective responsibilities for compliance, particularly regarding data subject rights and transparency obligations. The essence of the arrangement must be made available to data subjects.
Determining Joint Controllership
Joint controllership exists when two or more entities:
- Jointly determine the purposes — both entities influence why data is processed.
- Jointly determine the means — both entities influence how data is processed (essential means, not just technical implementation details).
Key Indicators
| Indicator | Points to Joint Controllership | Points Away |
|---|
| Shared decision on purpose | Both parties decide why data is processed | One party decides purpose; other merely executes |
| Shared platform | Both parties upload/access data on a common platform | One party hosts; other merely provides input |
| Shared dataset | Both parties contribute to and benefit from a combined dataset | One party processes only for the other's purpose |
| Mutual benefit | Both parties derive independent benefit from the processing | Only one party benefits; other is purely a service provider |
| Influence on means | Both parties have a say in essential aspects (what data, how long, who accesses) | One party determines all essential means; other party only implements |
CJEU Case Law Guidance
- Wirtschaftsakademie Schleswig-Holstein (C-210/16): A Facebook fan page admin is a joint controller with Facebook because the admin's creation of the page enables Facebook's processing and the admin benefits from visitor statistics.
- Jehovah's Witnesses (C-25/17): A religious community that organises door-to-door preaching and coordinates personal data collection by its members is a joint controller with those members.
- Fashion ID (C-40/17): A website embedding a Facebook Like button is a joint controller with Facebook for the collection and transmission of data triggered by the plugin.
Art. 26 Arrangement Requirements
The arrangement between joint controllers must determine in a transparent manner: