Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Controller Obligations & Joint Controllership (Art. 24 & 26)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 25/54 Part 3 — Lawfulness & Key Actors Intermediate Reviewed 2026-08-23

Controller Obligations & Joint Controllership (Art. 24 & 26)

The Data Controller is the primary guarantor of compliance under the accountability principle (Art. 24). When two or more entities jointly determine the purposes and means of processing (Art. 26), the

Open in interactive reader
⚖️ Operational Governance 🏛️ CJEU C-210/16 Wirtschaftsakademie

Controller Obligations & Joint Controllership (Art. 24 & 26)

⚡ In 30 seconds

Under Article 24, the controller must ensure and be able to demonstrate that processing is performed in compliance with the GDPR. Under Article 26, where two or more controllers jointly determine the purposes and means of processing, they must determine their respective responsibilities by means of an arrangement between them, made available to data subjects.

Governance Area Sole Controller (Art. 24) Joint Controllers (Art. 26)
Decision Power Unilaterally determines purposes and essential processing means. Converging or coordinated decisions on why and how data is handled.
Formal Requirement Internal accountability documentation (policies, Art. 30 register). Mandatory written Article 26 arrangement dividing compliance tasks.
Data Subject Rights Direct point of contact for all right requests. Individuals may exercise their rights against each of the controllers (Art. 26.3).
⚡ Key Takeaways
  • CJEU Wirtschaftsakademie (C-210/16): administrators of Facebook fan pages are joint controllers with Meta.
  • Joint controllers are jointly and severally liable towards individuals for damages (Art. 82.4).
  • The internal allocation agreement must designate a designated contact point for individuals.
⚠️ Common Pitfall

Failing to make the essential arrangement accessible to users, leaving both entities open to regulatory fines.

🛠️ In Practice

Publish a summary of joint responsibilities in your public privacy policy whenever co-branded platforms are deployed.

⚖️ Official Sources: Art. 24, 26 GDPR · Recitals 74, 79 · CJEU C-210/16 Wirtschaftsakademie & C-40/17 Fashion ID ✓ Legal review: 23 August 2026

✓ Key takeaways

  • The controller must implement technical and organizational measures (TOMs) to demonstrate compliance.
  • Joint controllership arises from the joint determination of purposes AND essential means.
  • The essence of the Article 26 arrangement must be made transparently available to data subjects.

⚠ Common pitfall: Mischaracterizing two independent controllers sharing data for distinct secondary goals as 'joint controllers'.

→ Actionable practice: Draft an explicit Article 26 Joint Controller Agreement defining who answers subject access requests and notifies breaches.

← ePrivacy Directive, Cookies & Consent Platforms (CMPs) Subcontracting & Data Processing Agreements (Art. 28) →