{"answer_id":"praxikon:eu:gdpr:answer:gezamenlijke-verantwoordelijkheid","canonical_page":"https://www.praxikon.com/en/antwoord/avg/gezamenlijke-verantwoordelijkheid","query":"When is an organisation a joint controller?","lang":"en","view":"full","mode":"gdpr","regime":"gdpr","topic":"gezamenlijke-verantwoordelijkheid","question":"When is an organisation a joint controller?","label":"Joint controllership","answer":"Organisations are joint controllers where they jointly determine the purposes and means of the processing (Article 26(1)). They set out in an arrangement who fulfils which obligation (Article 26(1) and (2)). The Court of Justice held in IAB Europe that an organisation that co-determines the purposes and means through its framework can be a joint controller, even if it has no access to the data itself. That responsibility does not automatically extend to later processing by others whose purposes and means it does not co-determine.","applied_to_question":null,"matched_terms":[],"articles":[{"article":4,"source_locator":"Art. 4(7) GDPR","point":"Definition of controller.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/4"},{"article":26,"source_locator":"Art. 26(1) and (2) GDPR","point":"Joint controllership and the arrangement between the controllers.","source_title":"GDPR (Regulation (EU) 2016/679)","source_url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","human_page":"https://www.praxikon.com/en/avg/artikel/26"}],"case_law":[{"id":"c-604-22","kind":"judgment","title":"IAB Europe","issuer":"CJEU","reference":"C-604/22","ecli":"ECLI:EU:C:2024:214","date":"2024-03-07","status":null,"point":"Operative part: joint controllership without own access to the data.","source_url":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0604","human_page":null}],"guidance":[{"id":"edpb-gl-07-2020","kind":"guidance","title":"Guidelines 07/2020 on the concepts of controller and processor in the GDPR","issuer":"EDPB","reference":"v2.1","ecli":null,"date":"2021-07-07","status":"final","point":"Guidelines on the concepts of controller and processor.","source_url":"https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en","human_page":null}],"enforcement":[],"open_questions":["Who determines why and how the data are processed?"],"human_page":"https://www.praxikon.com/en/avg/artikel/4","dataset":{"id":"praxikon-gdpr","source":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","known_at":"2026-09-15"},"casus_check":"https://www.praxikon.com/en/casus-check","disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}