Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

RoPA joint controllers diagram of two organizations sharing purposes and means with an Article 26 arrangement

RoPA and Joint Controllers Guide 2026

RoPA joint controllers entries are among the trickiest in a record of processing activities, because the law does not depend on what the parties call themselves. Two organizations that jointly decide why and how personal data is processed are joint controllers whether or not their contract says so, and each has obligations, including keeping a record. Getting this wrong means an inaccurate record, a missing arrangement and confusion over who answers to individuals.

This guide explains when controllers are joint, what Article 26 of the GDPR requires, how to record joint controllership in your Article 30 entries, what to do about common scenarios such as marketing campaigns and shared platforms, and how to keep the entries accurate over time.

When two organizations are joint controllers

Article 4(7) defines a controller as the body that, alone or jointly with others, determines the purposes and means of processing. Article 26 says that where two or more controllers jointly determine the purposes and means, they are joint controllers. The European Data Protection Board explains the concept in its Guidelines 07/2020 on the concepts of controller and processor, which you can read on the EDPB website. The guidance says joint determination can arise from a common decision or from converging decisions that complement each other and are necessary for the processing to happen.

The Court of Justice of the European Union has applied the idea broadly. In cases involving the administrator of a social media fan page and a website operator that embedded a social plugin, the court found joint responsibility for the stages of processing where those parties jointly determined purposes and means, even though their responsibility did not have to be equal. Joint control does not mean equal responsibility, and it covers only the processing operations they decide together.

Joint controller, independent controller or processor

The distinction affects what you write in the record. A processor acts on your instructions. An independent controller decides its own purposes for the data it receives, even if you give it the data. Joint controllers decide together. The table shows typical signals.

RelationshipTypical signalsExample
ProcessorActs only on your documented instructions, no own purposePayroll bureau running your payroll
Independent controllerSets its own purposes and means for the data it receivesBank that receives payment details to comply with its own duties
Joint controllersCommon purposes or complementary decisions, shared benefit and designTwo companies running a joint marketing event and sharing registrations

Our guide to controller and processor entries in the RoPA covers the other two roles in more detail.

Free ROPA template and builder

Could you hand your records of processing to a regulator tomorrow?

Check whether Article 30 applies to you, add your processing activities from a library organized by department, complete every Article 30 content, and see which activities are missing a lawful basis, a transfer safeguard, a DPIA or an LIA. Free, with a record score and findings.

Build your free ROPA →  or  View premium report sample

What Article 26 requires

Joint controllers must determine, in a transparent manner, their respective responsibilities for compliance with the GDPR, in particular for the exercise of data subjects’ rights and for providing the information required by Articles 13 and 14. They do this through an arrangement, unless their roles are already set by law. The essence of the arrangement must be made available to the data subject, and the arrangement may designate a contact point for individuals. Regardless of its terms, a data subject may exercise rights against each of the joint controllers.

The arrangement does not need to be a lengthy contract, but it needs to cover who informs individuals, who handles requests, who manages security and breaches, who selects processors and who conducts any DPIA. Record where the arrangement is held and who owns it.

Recording RoPA joint controllers under Article 30

Article 30(1)(a) requires a controller’s record to include its own name and contact details and, where applicable, those of the joint controller, the controller’s representative and the data protection officer. That is the direct hook for joint controllership in the record. Beyond that, the entry should be consistent with the rest of your fields.

  • Activity name and purpose. The shared purpose, described in specific terms.
  • Joint controller identity. Full name, contact details and role of each party.
  • Arrangement reference. Where the Article 26 arrangement is kept, its version and date, and the contact point for individuals.
  • Division of responsibility. A short summary of who does what, aligned with the arrangement.
  • Data categories and data subjects. What each party collects and receives.
  • Recipients and processors. Any processors used by either party, and who appointed them.
  • Transfers. Any transfers outside the EEA or UK by either party, and the tool used.
  • Retention and security. The periods and measures agreed for the shared processing.

Each party keeps its own record

Joint controllership does not make a single shared record. Each controller must maintain its own record of processing under its responsibility, and each entry should show the joint controller. The two records should agree on the shared purposes and the data involved, so exchange the relevant entries when the arrangement is agreed and compare them when it is reviewed.

Common scenarios for RoPA joint controllers

Look for joint controllership in places where two organizations collaborate on data. Typical examples include co-marketing events and joint promotions, shared customer loyalty schemes, collaborative research projects, group companies using a shared platform for their own purposes, franchise arrangements that share a customer database, social media pages where the page owner and the platform decide together on insights, and embedded third-party tools that collect data for the tool provider’s own purposes and for yours. For embedded tools, the analysis often turns on the stage of processing: the website operator and the provider may be joint controllers for collection and transmission but not for what the provider later does for unrelated purposes.

Telling data subjects about RoPA joint controllers

Because the essence of the arrangement must be available to individuals, your privacy notice should name the joint controller, describe each party’s role in plain language and explain how to exercise rights and whom to contact. Check that the notice, the arrangement and the RoPA agree. A mismatch between them is easy for a regulator to spot. See our GDPR data mapping guide for how to trace the flows that reveal shared control.

Shared processing also touches other parts of the record. Employee data shared within a corporate group often raises the same questions, as our guide to RoPA for HR processing explains, and shared platforms hosted abroad need the transfer fields described in international transfers in the RoPA.

A short worked example

Two companies run a joint webinar and share registrations. Both decide who is invited, what data is collected and how follow-up is done, and both use the list for their own marketing to attendees. The compliance teams conclude they are joint controllers for the collection and initial use. They sign an arrangement that says company A hosts the registration form and issues the privacy notice, company B answers access requests received by email, and both are responsible for honoring opt-outs and notifying each other of breaches. Each RoPA now records an entry for the webinar that names the other company, points to the arrangement, and summarizes the split of roles. They record separately that later use of the list for unrelated purposes is independent controllership.

Keeping RoPA joint controllers entries current

Review them when the arrangement changes, when a party changes its systems or suppliers, and at least annually as part of the general cycle. Our guide to the RoPA review process shows how to set owners and dates. Ask business teams to notify the privacy team before they start any collaboration that involves sharing personal data, so that joint control is identified early, not discovered later.

Common mistakes with RoPA joint controllers

Organizations sign a controller-to-processor agreement for what is really joint control, rely on contract labels instead of the facts, leave out the arrangement entirely, fail to tell individuals, forget that each party must keep its own record and assume that joint means equal liability. Another mistake is not noticing joint controllership at all, because nobody asked what a partner does with the data. A standard question in project intake, asking who else decides why and how the data will be used, catches most cases.

Using a ready structure

If you would rather begin with a finished structure than a blank sheet, the RoPA Report and Workbook provides a structured report and working register with fields for controller role, joint controller and arrangement reference. You can also see completed entries in our RoPA example. However you record it, RoPA joint controllers entries should show who decides what, and where the agreement is kept.

RoPA joint controllers FAQ

Do joint controllers share one record of processing?

No. Each controller keeps its own record. Each entry should show the joint controller and be consistent with the other party’s record for the shared processing.

Do we need a written arrangement?

Article 26 requires joint controllers to set out their responsibilities in an arrangement, unless the roles are fixed by law, and the essence of it must be available to individuals.

Are joint controllers equally liable?

Not necessarily. Responsibility can be shared unequally and depends on their involvement in each stage, but individuals can exercise their rights against any of the joint controllers.

How do I know if a partner is a joint controller?

Ask who decides why and how the data is used. If both decide, or make complementary decisions that are necessary for the processing, joint controllership is likely, whatever the contract says.

What goes in the RoPA about a joint controller?

The joint controller’s identity and contact details, the shared purpose, the location of the arrangement and a summary of who does what, alongside the usual Article 30 fields.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.