Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 26 Joint controllers
Summary What does Article 26 of the GDPR regulation say?
This article addresses the concept of "joint controllers" — a scenario where two or more controllers together decide the purposes and means of processing personal data.
It establishes that in such cases, those controllers must agree amongst themselves on how to divide their respective compliance responsibilities, particularly regarding data subject rights and the transparency obligations found elsewhere in the regulation.
Crucially, regardless of any internal arrangement, data subjects retain the ability to exercise their rights against any one of the joint controllers.
Important points:
- Where two or more controllers jointly determine how and why personal data is processed, establish a transparent arrangement defining each party's compliance responsibilities.
- The essence of that internal arrangement must be made available to data subjects.
- Data subjects can exercise their rights against any of the joint controllers, irrespective of the terms of the arrangement between them.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.
The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.
Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.
Relevant recitals
Recital 79 Allocating responsibility among joint controllers
The protection of the rights and freedoms of data subjects as well as the responsibility and liability of controllers and processors, also in relation to the monitoring by and measures of supervisory authorities, requires a clear allocation of the responsibilities under this Regulation, including where a controller determines the purposes and means of the processing jointly with other controllers or where a processing operation is carried out on behalf of a controller.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
supervisory authority
Definition
personal data