Joint Controller Agreement – English Template (Article 26 GDPR)
Zweck / Purpose
English-language template for a joint controller agreement under Article 26 GDPR, allocating responsibilities and publishing the essence under Article 26 (2) GDPR. Purpose (DE): Englischsprachige Mustervorlage für eine Joint-Controller-Vereinbarung nach Art. 26 DSGVO.
Wann dieses Modul hilft
- Two or more parties jointly determine the purposes and means of processing.
- Cross-border setup with English working language.
- CJEU patterns: C-498/16 (Fanpages), C-40/17 (Fashion ID), C-25/17 (Jehovah's Witnesses) – verified case numbers.
- A short version of the agreement must be made publicly available (Article 26 (2) GDPR).
Rechtlicher Rahmen
- Article 26 (1) GDPR – Determination of respective responsibilities in a transparent manner.
- Article 26 (2) GDPR – Essence of the arrangement must be made available to the data subjects.
- Article 26 (3) GDPR – Data subjects may exercise their rights vis-a-vis each controller.
- Article 82 (4) GDPR – Joint and several liability.
- EDPB Guidelines 07/2020 on controller / processor concepts (final 07 July 2021).
Ablauf / Checkliste
- Confirm joint determination of purposes and means.
- Map data flows and the contribution of each party.
- Allocate information duties (Articles 13 and 14 GDPR).
- Define single point of contact and request routing.
- Allocate Article 32 / 33 / 34 / 35 / 36 GDPR responsibilities.
- Draft the essence-clause for publication under Article 26 (2) GDPR.
- Internal indemnity and recourse provisions.
Mustertext / Template
JOINT CONTROLLER AGREEMENT (Article 26 GDPR)
This Joint Controller Agreement ("JCA") is entered into between:
(1) [Party A Legal Name], a company organised under the laws of [jurisdiction]
("Party A"); and
(2) [Party B Legal Name], a company organised under the laws of [jurisdiction]
("Party B").
Recital A. The Parties jointly determine the purposes and means of the processing
described in Annex I and therefore qualify as joint controllers within the meaning
of Article 26 GDPR.
Recital B. This JCA sets out the respective responsibilities of the Parties in a
transparent manner.
1. SCOPE
1.1 The joint processing covers the processing activities described in Annex I,
including the categories of personal data, categories of data subjects and
purposes.
2. ALLOCATION OF RESPONSIBILITIES
2.1 Party A is responsible for:
(a) provision of the processing infrastructure;
(b) compliance with information duties under Articles 13 and 14 GDPR towards
data subjects reached via Party A;
(c) handling of data subject requests under Articles 15 to 22 GDPR received
through Party A;
(d) notification of personal data breaches under Articles 33 and 34 GDPR in
respect of processing components controlled by Party A.
2.2 Party B is responsible for:
(a) collection and initial transfer of personal data to Party A;
(b) compliance with information duties under Articles 13 and 14 GDPR towards
data subjects reached via Party B;
(c) handling of data subject requests under Articles 15 to 22 GDPR received
through Party B;
(d) notification of personal data breaches under Articles 33 and 34 GDPR in
respect of processing components controlled by Party B.
2.3 The Parties shall jointly carry out:
(a) a data protection impact assessment under Article 35 GDPR where required;
(b) the definition of retention periods;
(c) the definition of technical and organisational measures under Article 32
GDPR.
3. SINGLE POINT OF CONTACT
3.1 The single point of contact for data subjects pursuant to Article 26 (1) GDPR
is Party A. Party A shall forward without undue delay any request that falls
within the responsibility of Party B.
3.2 Article 26 (3) GDPR remains unaffected: data subjects may exercise their
rights against each Party.
4. TRANSPARENCY TOWARDS DATA SUBJECTS (Art. 26 (2) GDPR)
4.1 The Parties shall make available to data subjects the essence of this JCA in
their respective privacy notices. Annex II contains the agreed essence-text
for publication.
5. SECURITY AND BREACH NOTIFICATION
5.1 The Parties shall coordinate without undue delay, and in any event within
twenty-four (24) hours of becoming aware of a personal data breach, on
notification obligations.
5.2 The Party in whose area of responsibility the breach occurs shall lead the
notification. Where the breach affects the joint area, Party A shall lead.
6. LIABILITY AND RECOURSE
6.1 The Parties are jointly and severally liable to data subjects pursuant to
Article 82 (4) GDPR.
6.2 In the internal relationship between the Parties, each Party shall bear the
damage in proportion to its share of responsibility pursuant to Article 82
(5) GDPR.
6.3 The internal liability of each Party is capped at [AMOUNT] EUR per claim and
[AMOUNT] EUR per calendar year. The cap shall not apply in case of wilful
misconduct, gross negligence, or for damage arising from injury to life,
body or health.
7. SUPERVISORY AUTHORITY
7.1 The Parties shall cooperate in good faith in respect of inquiries and
investigations by supervisory authorities.
8. TERM AND TERMINATION
8.1 This JCA is concluded for an indefinite period and may be terminated by
either Party with six (6) months' written notice to the end of a calendar
quarter.
9. GOVERNING LAW AND JURISDICTION
9.1 This JCA shall be governed by the laws of [jurisdiction]. The courts of
[court venue] shall have exclusive jurisdiction.
Annex I Description of the joint processing
Annex II Essence-text for publication (Article 26 (2) GDPR)
Signed on behalf of Party A: Signed on behalf of Party B:
__________________________________ __________________________________
Name: Name:
Title: Title:
Date: Date:
Typische Drafting-Fehler
- A DPA is signed where joint controllership applies.
- Responsibilities allocated as "both jointly" without granularity.
- No single point of contact defined.
- No essence-text published as required by Article 26 (2) GDPR.
- Internal recourse cap exceeds GDPR statutory liability or excludes wilful misconduct.
- Web tracking scenarios where the initial collection (Fashion ID) is forgotten.
Quellen Stand 06/2026
- GDPR Articles 13, 14, 26, 32, 33, 34, 35, 36, 82.
- EDPB Guidelines 07/2020 (final 07 July 2021), edpb.europa.eu.
- CJEU C-25/17 (Jehovah's Witnesses) – verified.
- CJEU C-498/16 (Wirtschaftsakademie / Fanpages) – verified.
- CJEU C-40/17 (Fashion ID) – verified.
- Full texts available via curia.europa.eu.
- Citation rules:
../../../references/zitierweise.md.
1---2name: joint-controllership-en-template3description: Für Joint Controller Agreement – English Template (Article 26 GDPR): ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt.4---56# Joint Controller Agreement – English Template (Article 26 GDPR)78## Zweck / Purpose910English-language template for a joint controller agreement under Article 26 GDPR, allocating responsibilities and publishing the essence under Article 26 (2) GDPR. Purpose (DE): Englischsprachige Mustervorlage für eine Joint-Controller-Vereinbarung nach Art. 26 DSGVO.1112## Wann dieses Modul hilft1314- Two or more parties jointly determine the purposes and means of processing.15- Cross-border setup with English working language.16- CJEU patterns: C-498/16 (Fanpages), C-40/17 (Fashion ID), C-25/17 (Jehovah's Witnesses) – verified case numbers.17- A short version of the agreement must be made publicly available (Article 26 (2) GDPR).1819## Rechtlicher Rahmen2021- Article 26 (1) GDPR – Determination of respective responsibilities in a transparent manner.22- Article 26 (2) GDPR – Essence of the arrangement must be made available to the data subjects.23- Article 26 (3) GDPR – Data subjects may exercise their rights vis-a-vis each controller.24- Article 82 (4) GDPR – Joint and several liability.25- EDPB Guidelines 07/2020 on controller / processor concepts (final 07 July 2021).2627## Ablauf / Checkliste28291. Confirm joint determination of purposes and means.302. Map data flows and the contribution of each party.313. Allocate information duties (Articles 13 and 14 GDPR).324. Define single point of contact and request routing.335. Allocate Article 32 / 33 / 34 / 35 / 36 GDPR responsibilities.346. Draft the essence-clause for publication under Article 26 (2) GDPR.357. Internal indemnity and recourse provisions.3637## Mustertext / Template3839```40JOINT CONTROLLER AGREEMENT (Article 26 GDPR)4142This Joint Controller Agreement ("JCA") is entered into between:4344 (1) [Party A Legal Name], a company organised under the laws of [jurisdiction]45 ("Party A"); and4647 (2) [Party B Legal Name], a company organised under the laws of [jurisdiction]48 ("Party B").4950Recital A. The Parties jointly determine the purposes and means of the processing51described in Annex I and therefore qualify as joint controllers within the meaning52of Article 26 GDPR.53Recital B. This JCA sets out the respective responsibilities of the Parties in a54transparent manner.55561. SCOPE571.1 The joint processing covers the processing activities described in Annex I,58 including the categories of personal data, categories of data subjects and59 purposes.60612. ALLOCATION OF RESPONSIBILITIES622.1 Party A is responsible for:63 (a) provision of the processing infrastructure;64 (b) compliance with information duties under Articles 13 and 14 GDPR towards65 data subjects reached via Party A;66 (c) handling of data subject requests under Articles 15 to 22 GDPR received67 through Party A;68 (d) notification of personal data breaches under Articles 33 and 34 GDPR in69 respect of processing components controlled by Party A.702.2 Party B is responsible for:71 (a) collection and initial transfer of personal data to Party A;72 (b) compliance with information duties under Articles 13 and 14 GDPR towards73 data subjects reached via Party B;74 (c) handling of data subject requests under Articles 15 to 22 GDPR received75 through Party B;76 (d) notification of personal data breaches under Articles 33 and 34 GDPR in77 respect of processing components controlled by Party B.782.3 The Parties shall jointly carry out:79 (a) a data protection impact assessment under Article 35 GDPR where required;80 (b) the definition of retention periods;81 (c) the definition of technical and organisational measures under Article 3282 GDPR.83843. SINGLE POINT OF CONTACT853.1 The single point of contact for data subjects pursuant to Article 26 (1) GDPR86 is Party A. Party A shall forward without undue delay any request that falls87 within the responsibility of Party B.883.2 Article 26 (3) GDPR remains unaffected: data subjects may exercise their89 rights against each Party.90914. TRANSPARENCY TOWARDS DATA SUBJECTS (Art. 26 (2) GDPR)924.1 The Parties shall make available to data subjects the essence of this JCA in93 their respective privacy notices. Annex II contains the agreed essence-text94 for publication.95965. SECURITY AND BREACH NOTIFICATION975.1 The Parties shall coordinate without undue delay, and in any event within98 twenty-four (24) hours of becoming aware of a personal data breach, on99 notification obligations.1005.2 The Party in whose area of responsibility the breach occurs shall lead the101 notification. Where the breach affects the joint area, Party A shall lead.1021036. LIABILITY AND RECOURSE1046.1 The Parties are jointly and severally liable to data subjects pursuant to105 Article 82 (4) GDPR.1066.2 In the internal relationship between the Parties, each Party shall bear the107 damage in proportion to its share of responsibility pursuant to Article 82108 (5) GDPR.1096.3 The internal liability of each Party is capped at [AMOUNT] EUR per claim and110 [AMOUNT] EUR per calendar year. The cap shall not apply in case of wilful111 misconduct, gross negligence, or for damage arising from injury to life,112 body or health.1131147. SUPERVISORY AUTHORITY1157.1 The Parties shall cooperate in good faith in respect of inquiries and116 investigations by supervisory authorities.1171188. TERM AND TERMINATION1198.1 This JCA is concluded for an indefinite period and may be terminated by120 either Party with six (6) months' written notice to the end of a calendar121 quarter.1221239. GOVERNING LAW AND JURISDICTION1249.1 This JCA shall be governed by the laws of [jurisdiction]. The courts of125 [court venue] shall have exclusive jurisdiction.126127Annex I Description of the joint processing128Annex II Essence-text for publication (Article 26 (2) GDPR)129130Signed on behalf of Party A: Signed on behalf of Party B:131__________________________________ __________________________________132Name: Name:133Title: Title:134Date: Date:135```136137## Typische Drafting-Fehler138139- A DPA is signed where joint controllership applies.140- Responsibilities allocated as "both jointly" without granularity.141- No single point of contact defined.142- No essence-text published as required by Article 26 (2) GDPR.143- Internal recourse cap exceeds GDPR statutory liability or excludes wilful misconduct.144- Web tracking scenarios where the initial collection (Fashion ID) is forgotten.145146## Quellen Stand 06/2026147148- GDPR Articles 13, 14, 26, 32, 33, 34, 35, 36, 82.149- EDPB Guidelines 07/2020 (final 07 July 2021), edpb.europa.eu.150- CJEU C-25/17 (Jehovah's Witnesses) – verified.151- CJEU C-498/16 (Wirtschaftsakademie / Fanpages) – verified.152- CJEU C-40/17 (Fashion ID) – verified.153- Full texts available via curia.europa.eu.154- Citation rules: `../../../references/zitierweise.md`.