Skip to main content
Praxikon

Direct answer · GDPR

When is an organisation a joint controller?

Short answer

Organisations are joint controllers where they jointly determine the purposes and means of the processing (Article 26(1)); they set out in an arrangement who fulfils which obligation. According to the Court of Justice in IAB Europe, an organisation that co-determines the purposes and means through its framework can be a joint controller, even if it has no access to the data itself.

Direct answer · GDPR

Joint controllership

Organisations are joint controllers where they jointly determine the purposes and means of the processing (Article 26(1)). They set out in an arrangement who fulfils which obligation (Article 26(1) and (2)). The Court of Justice held in IAB Europe that an organisation that co-determines the purposes and means through its framework can be a joint controller, even if it has no access to the data itself. That responsibility does not automatically extend to later processing by others whose purposes and means it does not co-determine.

For you to establish

  • Who determines why and how the data are processed?

Articles

Case law

  • IAB Europe (CJEU, C-604/22, ECLI:EU:C:2024:214, 2024-03-07)Operative part: joint controllership without own access to the data.

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist