Direct answer · GDPR
Joint controllership
Organisations are joint controllers where they jointly determine the purposes and means of the processing (Article 26(1)). They set out in an arrangement who fulfils which obligation (Article 26(1) and (2)). The Court of Justice held in IAB Europe that an organisation that co-determines the purposes and means through its framework can be a joint controller, even if it has no access to the data itself. That responsibility does not automatically extend to later processing by others whose purposes and means it does not co-determine.
For you to establish
- Who determines why and how the data are processed?
Articles
- Art. 4(7) GDPR Definition of controller.
- Art. 26(1) and (2) GDPR Joint controllership and the arrangement between the controllers.
Case law
- IAB Europe (CJEU, C-604/22, ECLI:EU:C:2024:214, 2024-03-07)Operative part: joint controllership without own access to the data.
Guidelines and decisions
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR (EDPB, v2.1, 2021-07-07)Guidelines on the concepts of controller and processor.
