Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 26 Joint controllers


Summary What does Article 26 of the GDPR regulation say?

This article addresses the concept of "joint controllers" — a scenario where two or more controllers together decide the purposes and means of processing personal data.

It establishes that in such cases, those controllers must agree amongst themselves on how to divide their respective compliance responsibilities, particularly regarding data subject rights and the transparency obligations found elsewhere in the regulation.

Crucially, regardless of any internal arrangement, data subjects retain the ability to exercise their rights against any one of the joint controllers.

Important points:

  • Where two or more controllers jointly determine how and why personal data is processed, establish a transparent arrangement defining each party's compliance responsibilities.
  • The essence of that internal arrangement must be made available to data subjects.
  • Data subjects can exercise their rights against any of the joint controllers, irrespective of the terms of the arrangement between them.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.

    1. The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.

    1. Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod