Glossary Terms

Joint Controller

Two or more parties that jointly determine the purposes and essential means of processing personal data.
On this page

What is a joint controller?

Joint controllers are two or more parties that jointly determine the purposes and essential means of processing personal data. They do not need to make every decision together or have equal influence. Joint controllership can arise when their decisions converge and the processing would not occur in the same way without each party’s participation.

The role is based on the factual arrangement rather than the title in a contract. Data sharing alone does not automatically create joint controllers, and cooperation between parties may instead involve separate controllers or a controller-processor relationship.

How are joint controllers identified?

The analysis should examine who initiated the activity, defined the shared objective, selected the data, determined affected people and shaped the essential processing. Parties may jointly determine one stage while acting independently at another, so roles should be assessed activity by activity.

Examples can include jointly operated platforms, shared campaigns, research projects or services where both parties influence the collection and use. Complex relationships may require specialist legal analysis.

What responsibilities do joint controllers have?

Joint controllers should transparently allocate responsibilities for notices, lawful basis, rights requests, security, breaches and regulator contact. The arrangement should reflect actual capabilities and provide effective contact routes for individuals.

Internal allocation does not necessarily prevent a person or regulator from approaching either party where the law permits. Cooperation procedures are therefore important, particularly for incidents and requests involving systems controlled by different organisations.

How should the arrangement be documented?

A written arrangement should describe the processing, parties, responsibilities, decision-making, contact points and information provided to individuals. It should also cover data sharing, retention, security, transfers and exit procedures.

The arrangement should be reviewed when purposes, technology, participants or control change. A document that contradicts actual operations will not reliably determine the legal role.

Frequently asked questions

Do joint controllers share responsibility equally?

Not necessarily. Responsibilities can be allocated according to actual involvement, although each party may retain legal exposure under the applicable framework.

Is a data-sharing agreement enough?

No. The agreement should reflect the role analysis and operational responsibilities, but the factual relationship remains decisive.

Can a processor also be a joint controller?

For a different activity, yes. If a processor independently helps determine a purpose, it may become a controller for that processing.

Who answers a data-subject request?

The arrangement should define coordination and contact points. Individuals should not be disadvantaged by uncertainty between the parties.

Can joint controllership change over time?

Yes. Changes in product design, data use or decision authority can alter roles and should trigger reassessment.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.