What does GDPR Article 26 require of joint controllers?
GDPR Article 26(1) makes two or more controllers joint controllers where they jointly determine the purposes and means of processing. They must set out their respective responsibilities in an arrangement, make its essence available to data subjects under Article 26(2), and remain individually answerable under Article 26(3).
Applies to: Organisations that run processing together with another organisation, including co-branded campaigns, shared analytics or advertising pixels, joint research, and platform integrations where both sides decide why the data is used.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanArticle 26 is short, and it is regularly applied to relationships the parties had labelled something else. The label does not decide it. The decision-making does.
The test in Article 26(1)
The opening words are the whole test: "Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers."
Nothing about a contract, a payment, or a hierarchy. Two organisations that both have a say in why personal data is being processed, and broadly how, are joint controllers whether or not they have ever used the phrase.
Article 26(1) then imposes the duty. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under the Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them.
Two named priorities there: data subject rights, and the privacy notice duties in Articles 13 and 14. Those are the things the arrangement has to allocate first.
When you do not need the arrangement
The same sentence carries an exception that is easy to miss: the arrangement is required "unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject".
So where the law already allocates the responsibilities, the arrangement is unnecessary to that extent. This tends to matter for public sector and regulated processing rather than commercial partnerships, where nothing allocates anything and the arrangement is always needed.
Article 26(1) closes by permitting, not requiring, a contact point: "The arrangement may designate a contact point for data subjects."
The essence has to be published
Article 26(2) has two requirements in two sentences. First, the arrangement shall duly reflect the respective roles and relationships of the joint controllers vis-a-vis the data subjects. Second, the essence of the arrangement shall be made available to the data subject.
"Duly reflect" is an accuracy standard. An arrangement that assigns rights handling to a partner who has no ability to answer requests does not reflect the real relationship, and papering over that does not fix it.
"The essence" is not the full contract. It is enough for a data subject to understand who does what and where to go. In practice this belongs in the privacy notice, written plainly, alongside the Article 13 information.
Article 26(3) is the part people negotiate against and cannot change
"Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers."
Irrespective of the terms. A data subject who wants erasure can come to either joint controller, and being told to ask the other one is not a lawful response. The arrangement governs how the two of you settle it between yourselves. It does not govern the data subject.
That is why the operational question matters more than the drafting question. If your arrangement says the other party handles access requests, you still need a route to satisfy one that arrives at your door within the Article 12(3) month.
Where this comes up
The recurring cases are co-branded campaigns and events where both parties use the sign-up list for their own purposes, advertising and analytics integrations where the platform uses the data for its own ends as well as yours, joint research projects, and platform or marketplace arrangements where both sides shape the processing.
The tell is simple. If the other organisation would keep using the data for its own reasons after your instructions stopped, it is not acting only as your processor under Article 28.
Compliance checklist
- Decide honestly whether you jointly determine purposes and means, because Article 26(1) turns on the substance of who decides rather than on what the contract is called.
- Put an arrangement in place that determines your respective responsibilities for compliance, in particular for data subject rights and for the Article 13 and 14 information duties.
- Check whether Union or Member State law already determines those responsibilities, since Article 26(1) makes the arrangement unnecessary to that extent.
- Make the essence of the arrangement available to data subjects, as Article 26(2) requires, which normally means a plain summary in the privacy notice rather than the full contract.
- Ensure the arrangement duly reflects the respective roles and relationships of the joint controllers vis-a-vis the data subjects, which is the accuracy test in Article 26(2).
- Consider designating a contact point for data subjects, which Article 26(1) permits, while remembering it does not restrict where a data subject may go.
Sources
Last verified: 2026-09-04
Informational, not legal advice.