Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · GDPR

Article 26Joint controllers

CELEX 32016R0679 · Read on 2026-08-18 · Chapter IV

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.

2. The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.

3. Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.

Open the article on EUR-Lex

Other articles in this chapter

Decisions applying this article

Court, citation and the paragraphs of the reasons where the article is dealt with.

  • Court of Justice of the European Union

    Whether a site that embeds a third-party button is a joint controller for the collection of the data.

    Paragraphs 84, 85

Judgments of the Court of Justice

2 decisions

  • C-604/22Court of Justice of the European Union

    IAB Europe v Gegevensbeschermingsautoriteit

    Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Standard-setting sectoral organisation proposing to its members rules on the processing of users’ consent – Article 4(1) – Concept of ‘personal data’ – String of letters and characters capturing, in a structured and machine-readable manner, the preferences of an internet user relating to the consent of that user to the processing of his or her personal data – Article 4(7) – Concept of ‘controller’ – Article 26(1) – Concept of ‘joint controllers’ – Organisation which does not itself have access to the personal data processed by its members – Responsibility of the organisation extending to the subsequent processing of data carried out by third parties.

  • C-683/21Court of Justice of the European Union

    Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija

    Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(2) and (7) – Concepts of ‘processing’ and ‘controller’ – Development of a mobile IT application – Article 26 – Joint control – Article 83 – Imposition of administrative fines – Conditions – Requirement that the infringement be intentional or negligent – Responsibility and liability of the controller for the processing of personal data carried out by a processor.

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit