Joint Controllership Liability
Joint controllership arises when two or more organizations together decide why and how personal data is processed. When they act as joint controllers, each one can be held responsible for the entire harm caused by the processing, not just for its own share. This means an individual affected by a data protection breach may be able to seek full compensation from any one of the joint controllers.
Joint controllership liability describes the allocation of responsibility that applies when two or more parties jointly determine the purposes and means of processing personal data under the GDPR (and, in the UK, the UK GDPR). According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing unless it can prove it was not in any way responsible for the event giving rise to that damage. The EDPB indicates that a controller, including a joint controller, is liable both for its own compliance and for the compliance of any processor it chooses; recent CJEU case law addressed by commentators has further considered the extent to which controllers may be held liable for processing carried out by their processors. This entry describes the general liability principle and does not resolve how liability is apportioned internally between joint controllers, how a joint controllership arrangement should be documented, or the specific facts required to establish the exemption from liability, all of which depend on the particular processing arrangement and applicable regulatory and judicial interpretation.
Why it matters
In the context of cookie consent, joint controllership is common but easy to overlook. When a website operator and a third party (for example, an advertising technology provider or a social plugin operator) together decide why and how tracking data is collected and used, they may qualify as joint controllers under the GDPR and, in the UK, the UK GDPR. The significance for compliance teams is that liability does not necessarily follow the neat boundaries organizations draw in their contracts. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, not merely for its own contribution, unless it can prove it was not in any way responsible for the event giving rise to that damage.
This has practical consequences for how cookie and tracking arrangements are structured and documented. An affected individual may be able to pursue any single joint controller for the full harm, which means an organization can find itself exposed to claims arising in part from another party's conduct. The EDPB further indicates that a controller, including a joint controller, is liable both for its own compliance and for the compliance of any processor it chooses. Commentators have noted recent CJEU case law considering the extent to which controllers may be held liable for processing carried out by their processors, which underscores that liability can reach beyond an organization's own direct actions.
Because the internal apportionment of liability between joint controllers, and the specific facts needed to establish the exemption from liability, depend heavily on the particular arrangement and on evolving regulatory and judicial interpretation, organizations should treat joint controllership as a matter requiring careful legal assessment rather than assuming a standard contract clause resolves their exposure.
Who it's relevant to
Inside Joint Controllership Liability
Common questions
Answers to the questions practitioners most commonly ask about Joint Controllership Liability.

