Point of law
Joint controllership under Art. 26 GDPR
Every company in a group is a controller in its own right. Joint controllership does not arise from shared systems but from a shared determination of purposes and means. The arrangement under Art. 26 GDPR orders that role, it does not create it.
One system, three companies, no roles
Two companies in the same group use the same HR system. The parent evaluates key figures, the subsidiary keeps the personnel files, and a third company of the group operates the system. There are no contracts between the three, because after all it is the same group.
There is no group privilege
Companies within a group of undertakings are not subject to any special data protection rules merely because they belong to the same group. What matters under Art. 4(7) GDPR is, in each case, the entity that determines the purposes and means of processing. Because the group itself is not such an entity, transferring personal data between group companies also requires its own legal basis.
Recital 48 acknowledges that controllers within a group of undertakings may have a legitimate interest in transmitting personal data for internal administrative purposes. That is a possible legal basis under Art. 6(1)(f) GDPR and not a merger of roles.
Three questions to be answered separately within a group
Which company is controller for which processing
This is determined per processing activity and not per company. The same company can be controller for payroll and processor for group-wide reporting.
What the transfer between them rests on
On a condition in Art. 6(1) GDPR. Legitimate interests come into play in particular, because recital 48 expressly acknowledges transfers for internal administrative purposes. The balancing exercise has to be documented.
In what role the operating company acts
Usually as a processor under Art. 28 GDPR, because a pure operating company pursues no purpose of its own. Where it also processes for its own purposes, for instance for capacity planning, it is a controller to that extent.
Jointly is not the same as together
When mere cooperation turns into joint controllership was explained in more detail by the European Court of Justice in its judgment of 5 December 2023. According to that judgment, participation in determining purposes and means can rest on a joint decision or on coordinated decisions that complement each other and each have a concrete effect on the processing.
Two features that are often confused
| Creates joint controllership | Merkmal | Does not create it |
|---|---|---|
| Both determine itIncluding through coordinated separate decisions. | Determination of the purpose | Only one sideThe other follows and pursues no purpose of its own. |
| Not on its ownA shared system can also be run by one entity for the other. | Shared system | Operation on instructionsArt. 28 GDPR then applies. |
| Not requiredThe Court has held this expressly. | Access to the data | Nor decisiveAccess alone makes nobody a controller. |
| Not necessarily equalTo be assessed on the circumstances of the case. | Degree of responsibility | Determined separatelyEach entity answers for its own processing. |
What matters is the determination of purposes and means, not the technical system. Merely using a system that another entity designed for its own purposes does not by itself amount to joint controllership. Conversely, joint controllership can also exist without any access to the data.
The arrangement orders controllership, it does not create it
What the arrangement under Art. 26(1) GDPR achieves is overestimated in both directions. The European Court of Justice has held that it is not a precondition of the classification but an obligation imposed on joint controllers once they have been classified as such.
What the arrangement has to settle
Liste zu erledigender Punkte
- Who fulfils which obligation under the regulation, in particular regarding data subject rights
- Who complies with which information duties under Art. 13 and Art. 14 GDPR
- Where applicable, a contact point for data subjects
- The respective actual roles and relationships vis-à-vis data subjects, duly reflected
- How the essence of the arrangement is made available to data subjects
Two effects survive even a clean arrangement. Under Art. 26(3) GDPR the data subject may exercise their rights against each individual controller, regardless of the allocation. And under Art. 82(4) GDPR each participant is liable to the data subject for the entire damage.
In a consortium, whoever sets the research question decides
How a research consortium or a cooperation is classified is the same question in another guise. The yardstick remains Art. 4(7) GDPR, and setting the research question and the method is the determination of purpose and means.
Three constellations and their classification
One institution determines, the others supply
The supplying entities process on instructions. That is processing on behalf, even where the consortium presents itself as an equal partnership.
All contribute to question and method
Joint controllership for the joint analysis. Each institution remains separately responsible for its own collection.
Each institution pursues its own project
Separate controllerships. Passing data between them is a transfer and needs its own legal basis.
3 von 3
The third constellation occurs more often than a joint application suggests. A joint project on paper frequently breaks down into several collections with purposes of their own, and then an Art. 26 GDPR arrangement is the wrong answer.
How we support you with joint controllership
The allocation grows out of the record of processing activities and not out of the organisation chart. For each activity it has to be settled which entity determines the purpose, and the role follows from that. Only then is it clear whether an arrangement under Art. 26 GDPR, an agreement under Art. 28 GDPR or a legal basis for a transfer is needed.
The corporate law side lies outside data protection law. Domination agreements, intra-group powers of instruction and the allocation of recourse between joint controllers under Art. 82(5) GDPR run through the affiliated law firm.
Frequently asked questions
Is there a group privilege?
No. Art. 4(7) GDPR attaches to the individual entity, and a transfer between two companies needs a legal basis like any other. Recital 48 merely acknowledges that a legitimate interest in transmitting data for internal administrative purposes may exist.
Does everyone need access to the data?
No. The Court of Justice has held that joint controllership does not presuppose that each participating entity has access to the data. What matters is participation in determining purposes and means.
Do joint controllers carry equal liability?
Not between themselves. The Court has held that joint controllership does not entail equal responsibility, and the degree has to be assessed on the circumstances of the case. Towards the data subject, Art. 82(4) GDPR makes each of them liable for the entire damage.
What has to be communicated to the data subject?
The essence of the arrangement, Art. 26(2) sentence 2 GDPR. That is more than a note that it exists and less than the contract text. Regardless of the arrangement, the data subject may exercise their rights against each entity under paragraph 3.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.