Article 26: Joint controllers
Praxikon tracks Article 26 (Joint controllers) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 26 govern?
Article 26 sets out what must happen when two or more organisations jointly decide why and how personal data are processed. They are then joint controllers and must, in an arrangement between them, transparently determine who fulfils which obligation under the GDPR, in particular regarding the rights of data subjects and the information duties of Articles 13 and 14 (paragraph 1). That arrangement must clearly reflect the role of each party and its relationship with the data subjects, and the essence of the arrangement is made available to data subjects (paragraph 2). Whatever the parties agree, you as a data subject can exercise your rights against each of them (paragraph 3). The article exists because responsibilities must be clearly allocated, even when several parties share control, otherwise nobody can be held to account (recital 79).
Key term: Joint controllers: two or more organisations that together determine the purposes and means of a processing operation and are therefore jointly responsible
Directly affects:controllerdata subject
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Check whether you determine the purposes and means of a processing operation together with another organisation, because then you are joint controllers (paragraph 1). Record in an arrangement between you who informs data subjects under Articles 13 and 14, who handles data subject requests and who fulfils which other obligation, unless a legal provision already allocates this (paragraph 1). Make the essence of that arrangement available to data subjects and bear in mind that a data subject may still turn to any of the parties (paragraphs 2 and 3).
Data Subject
If several organisations are jointly responsible for your data, you are entitled to the essence of their mutual arrangement (paragraph 2). You can exercise your rights against each of those organisations, regardless of what they have agreed among themselves (paragraph 3).
Compliance checklist
Related recitals
The protection of the rights and freedoms of data subjects as well as the responsibility and liability of controllers and processors, also in relation to the monitoring by and measures of supervisory ...
(80)Where a controller or a processor not established in the Union is processing personal data of data subjects who are in the Union whose processing activities are related to the offering of goods or ser...
(81)To ensure compliance with the requirements of this Regulation in respect of the processing to be carried out by the processor on behalf of the controller, when entrusting a processor with processing a...
(82)In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be ...
Frequently asked questions
Connections
What connects to Article 26 GDPR
Case law
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België)
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)