This clause means both parties share legal responsibility for how personal data is used and protected under data protection laws. Under UK GDPR, a "controller" is the person or company that decides what happens to data; if you're a joint controller, you're equally liable for compliance failures. For example, if you and another company jointly decide to collect customer emails and one of you loses that data, both of you can be fined by regulators. This matters because regulators can pursue either party for the full penalty, not split it between you. You could end up paying for someone else's mistakes.

💡
Key Recommendation

Avoid joint controller arrangements if possible—ask to be a "processor" instead, which means you just follow the other party's instructions and have less legal responsibility. If you must be a joint controller, get a written agreement that clearly divides which party is responsible for which data protection tasks (collection, storage, deletion, etc.), and require the other party to have strong insurance. Also insist on a clause requiring the other party to indemnify you for their share of any fines or claims. ---

Frequently Asked Questions

What does this clause mean in simple terms?

This clause means both parties share legal responsibility for how personal data is used and protected under data protection laws.

Why should I care about this clause?

Under UK GDPR, a "controller" is the person or company that decides what happens to data; if you're a joint controller, you're equally liable for compliance failures.

What are my options?

For example, if you and another company jointly decide to collect customer emails and one of you loses that data, both of you can be fined by regulators.

How does this affect small businesses?

This matters because regulators can pursue either party for the full penalty, not split it between you.

✅ Action Checklist