Skip to content

Joint Controllers

What is Joint Controllers?

Two or more entities that jointly determine the purposes and means of processing personal data, sharing data protection responsibilities.

Privacy and Data Protection

Each of these is named in at least one of the same controls as joint controllers. The number is how many controls name both.

What the standards actually require on joint controllers

Requirements naming joint controllers across 6 standards, quoted from the control text.

GDPR2 controls

Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Uni...

GDPR-Art.26 · Joint controllers

Chapter II Section 7 establishes data security obligations. Controller and processor shall apply appropriate technical + organisational measures + procedures to protect personal data and the privacy rights of data subjects.

HU-INFOTV-Chap2-Security-Section-7-Processor-Joint-Controllers · HU Infotv Chap II - Section 7 Data Security + Processor + Joint Controllers + Breach Notification (Sections 25-25K)

Art.49 data protection by design and by default; Art.50 duty to destroy personal data at end of retention; Art.51 joint data controllers' joint and several responsibilities and transparency to data subjects.

ETH-PDPP-Art.49-51 · Data protection by design and by default; duty to destroy; joint controllers

Questions people ask about joint controllers

What is Joint Controllers?
Two or more entities that jointly determine the purposes and means of processing personal data, sharing data protection responsibilities.
Why is Joint Controllers important for compliance?
Joint Controllers is a key concept in Privacy and Data Protection. Understanding joint controllers helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Joint Controllers?
Joint Controllers appears in the requirement text of Jamaica Data Protection Act 2020, GDPR, Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act), Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018). Across these standards we have identified 12 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Joint Controllers?
Explore our compliance framework pages to see how joint controllers applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Joint Controllers applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.