This clause applies when two or more organizations share responsibility for deciding how personal data is used—neither one is fully in charge. For example, two companies running a joint marketing campaign might both decide what customer data to collect and how to use it. Under GDPR, joint controllers must have a written agreement explaining to individuals and regulators how they've divided responsibility between them. If there's no clear agreement, both companies can be held fully liable for violations, even if only one caused the problem. This is a high-risk situation because liability is shared and unclear.
Avoid joint controller arrangements unless absolutely necessary—they create shared legal risk and are difficult to manage. If you must enter one, insist on a detailed written agreement that specifies exactly which company is responsible for each data protection obligation (security, breach notification, responding to individual requests, etc.). Make sure the agreement clearly states how you will communicate with each other and who pays for compliance costs. ---
Frequently Asked Questions
What does this clause mean in simple terms?
This clause applies when two or more organizations share responsibility for deciding how personal data is used—neither one is fully in charge.
Why should I care about this clause?
For example, two companies running a joint marketing campaign might both decide what customer data to collect and how to use it.
What are my options?
Under GDPR, joint controllers must have a written agreement explaining to individuals and regulators how they've divided responsibility between them.
How does this affect small businesses?
If there's no clear agreement, both companies can be held fully liable for violations, even if only one caused the problem.
