Joint controllership is one of those areas of data protection law that can sound more complicated than it really is.
The basic question is simple:
Are two or more organisations making important decisions together about why personal data is being processed and how that processing will work?
If they are, there is a strong likelihood that they are joint controllers.
Under both the UK GDPR (General Data Protection Regulation) and EU GDPR, organisations are joint controllers where they jointly determine the purposes and means of processing. The important point is that this is about what happens in practice, not based in what the contract says.
Organisations cannot avoid joint controllership by describing themselves as separate, independent controllers if, in reality, they are making the material decisions together. Both organisations don’t even have to have the same level of control over shared personal data or direct access to all of the personal data. The question is whether they have participated in deciding the relevant purpose and the important features of the processing.
How to work out if you are a joint controller
A useful way to test whether joint controllership may exist is to ask:
- Did both organisations decide why the processing should take place?
- Did both have a say in designing how the processing would work?
- Did they jointly decide what personal data would be used, whose data would be involved or who would receive it?
- Are they using the same personal data for the same or closely connected purpose?
- Have they created common rules around how the data will be handled?
- Does the processing depend on both organisations taking part?
- Would the processing look materially different if one of them was not involved?
- Are the decisions of the two organisations so closely connected that the processing effectively works as one combined activity?
The more of these questions you answer yes to, the stronger the indication that joint controllership may exist.
That does not mean that every organisation working with the same data is a joint controller.
Two organisations can share personal data and still act as separate controllers where each independently decides what it will do with that information. Using the same system, database or supplier does not itself create a joint controllership either. The key question is still who is actually making the decisions about the processing.
For example, two businesses might decide to run a joint prize draw. Together they decide what information entrants must provide, how the draw will work, who can access the information and how winners will be contacted. That strongly points towards joint controllership.
But those same businesses may still act as separate controllers for their own customer databases, marketing activities or internal records.
This is why one of the most useful questions is “Joint controllers for what?”
Joint controllership does not automatically apply to the whole relationship. It applies to the parts of the processing where the parties actually make the relevant decisions together. The courts have confirmed that joint control is limited to the areas in which joint decisions are actually made.
Where organisations are joint controllers, Article 26 requires them to have a transparent arrangement setting out who is responsible for what. In practice, this should cover matters such as privacy information, lawful basis, data subject rights, security, personal data breaches and the use of processors. The essence of that arrangement must also be made available to individuals.
The responsibilities do not need to be divided equally. They should be allocated sensibly according to which organisation is best placed to deal with each obligation.
So, when deciding whether you are a joint controller, start with the facts rather than the label.
Ask who decided why the processing is happening, who shaped the important parts of how it works, and whether those decisions were made together. If they were, joint controllership should be considered seriously and where, necessary assessed by your DPO and/or Privacy team.