Skip to main content
The state of ai impact assessment
Category: Enforcement and Compliance

Joint Controllership Liability

Also known as: Joint Controller Liability, Liability of Joint Controllers
Simply put

Joint controllership arises when two or more organizations together decide why and how personal data is processed. When they act as joint controllers, each one can be held responsible for the entire harm caused by the processing, not just for its own share. This means an individual affected by a data protection breach may be able to seek full compensation from any one of the joint controllers.

Formal definition

Joint controllership liability describes the allocation of responsibility that applies when two or more parties jointly determine the purposes and means of processing personal data under the GDPR (and, in the UK, the UK GDPR). According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing unless it can prove it was not in any way responsible for the event giving rise to that damage. The EDPB indicates that a controller, including a joint controller, is liable both for its own compliance and for the compliance of any processor it chooses; recent CJEU case law addressed by commentators has further considered the extent to which controllers may be held liable for processing carried out by their processors. This entry describes the general liability principle and does not resolve how liability is apportioned internally between joint controllers, how a joint controllership arrangement should be documented, or the specific facts required to establish the exemption from liability, all of which depend on the particular processing arrangement and applicable regulatory and judicial interpretation.

Why it matters

In the context of cookie consent, joint controllership is common but easy to overlook. When a website operator and a third party (for example, an advertising technology provider or a social plugin operator) together decide why and how tracking data is collected and used, they may qualify as joint controllers under the GDPR and, in the UK, the UK GDPR. The significance for compliance teams is that liability does not necessarily follow the neat boundaries organizations draw in their contracts. According to ICO guidance, each joint controller may be liable for the entire damage caused by the processing, not merely for its own contribution, unless it can prove it was not in any way responsible for the event giving rise to that damage.

This has practical consequences for how cookie and tracking arrangements are structured and documented. An affected individual may be able to pursue any single joint controller for the full harm, which means an organization can find itself exposed to claims arising in part from another party's conduct. The EDPB further indicates that a controller, including a joint controller, is liable both for its own compliance and for the compliance of any processor it chooses. Commentators have noted recent CJEU case law considering the extent to which controllers may be held liable for processing carried out by their processors, which underscores that liability can reach beyond an organization's own direct actions.

Because the internal apportionment of liability between joint controllers, and the specific facts needed to establish the exemption from liability, depend heavily on the particular arrangement and on evolving regulatory and judicial interpretation, organizations should treat joint controllership as a matter requiring careful legal assessment rather than assuming a standard contract clause resolves their exposure.

Who it's relevant to

Privacy officers and data protection professionals
Those mapping data flows for cookies, pixels, SDKs, and similar tracking technologies need to identify where the organization may be acting as a joint controller with a third party. This assessment shapes exposure, because a joint controller may be liable for the entire damage caused by the processing unless it can prove it was not in any way responsible.
Legal counsel and compliance teams
Counsel advising on advertising technology, social plugins, and analytics arrangements should consider how liability is allocated when parties jointly determine purposes and means of processing. Given evolving CJEU case law on controller liability for processors and the fact-specific nature of the exemption from liability, this generally requires case-by-case legal judgment rather than reliance on standard contract language alone.
Web developers and integration teams
Teams integrating third-party tags, plugins, and trackers should recognize that technical implementation choices can contribute to a joint controllership relationship. Understanding this helps them flag arrangements that may need legal review before deployment, particularly where a third party helps decide how tracking data is collected and used.
Marketing compliance teams
Marketing functions that rely on advertising and analytics technologies from external vendors should be aware that shared decision-making over tracking can create joint controllership, and with it the risk of being pursued for the full harm arising from the processing. Coordination with privacy and legal teams supports appropriate documentation and risk assessment.

Inside Joint Controllership Liability

Joint Controller Determination
Under the GDPR, joint controllership arises where two or more parties jointly determine the purposes and means of processing personal data. In the cookie context, this can occur where a website operator and a third-party technology provider (for example an analytics or advertising vendor) together shape why and how data collected via cookies, pixels, or similar technologies is processed. The determination is fact-specific and does not depend on the parties labelling themselves as joint controllers.
Arrangement Between Joint Controllers (Article 26 GDPR)
Joint controllers are generally required under the GDPR to establish a transparent arrangement setting out their respective responsibilities for compliance, in particular regarding the exercise of data subject rights and the provision of information to individuals. The essence of this arrangement should be made available to data subjects.
Scope of Shared Responsibility
Joint controllership does not necessarily mean equal responsibility. Under the GDPR, the allocation of obligations reflects each party's actual involvement in the processing. Joint controllership typically extends only to the specific operations for which the parties jointly determine purposes and means, not to every stage of the data lifecycle.
Data Subject Rights Against Any Controller
A key consequence of joint controllership under the GDPR is that data subjects may generally exercise their rights against, and in respect of, each of the joint controllers, regardless of the internal allocation of responsibilities agreed between the parties.
Interaction With the ePrivacy Regime
The lawfulness of placing or accessing cookies and similar technologies is governed by the ePrivacy Directive and its national implementations, which is distinct from the GDPR analysis of who acts as controller for any resulting processing of personal data. Joint controllership addresses the GDPR processing layer and does not by itself resolve who is responsible for obtaining consent to store or access information on the device.
Liability Exposure
Because joint controllers share responsibility for jointly determined processing, each may face exposure in respect of that processing. The precise nature and extent of liability, including how it is apportioned in any given case, depends on facts, applicable national implementations, and evolving guidance and enforcement positions of data protection authorities.

Common questions

Answers to the questions practitioners most commonly ask about Joint Controllership Liability.

Does joint controllership mean each party shares equal responsibility for compliance?
No. Joint controllership means two or more controllers jointly determine the purposes and means of processing, but this does not imply equal or identical responsibility. Under the GDPR, joint controllers are expected to allocate their respective responsibilities through an arrangement, and liability may fall differently depending on which party's activities gave rise to a given infringement. That said, a data subject can generally exercise their rights against, and seek a remedy from, any of the joint controllers regardless of the internal allocation, so the arrangement between the parties does not necessarily limit external exposure. The precise interpretation continues to be shaped by regulatory guidance and case law and can vary by jurisdiction.
If a cookie or tracking tool provider sets a technology on my site, are they automatically the sole controller for that processing?
Not necessarily. Where a website operator and a third party (for example, a tag, pixel, or SDK provider) jointly determine the purposes and means of processing personal data collected through the technology, they may be treated as joint controllers for that stage of processing, even if only one of them carries out later processing on its own. A provider is not automatically the sole controller simply because it supplies the technology, nor is the website operator automatically absolved. The characterization depends on the facts of who decides why and how data is processed, and it can differ across the ePrivacy rules on placing or accessing information on a device and the GDPR rules on the subsequent processing of any personal data. This is a fact-specific assessment rather than a fixed status.
How should joint controllers document their arrangement in a cookie or tracking context?
Joint controllers are generally expected to have an arrangement that transparently sets out their respective responsibilities, particularly for exercising data subject rights and providing required information. In a cookie or tracking context this may address who is responsible for obtaining and recording consent, who responds to access or erasure requests, and how the essence of the arrangement is made available to individuals. The specific form is not prescribed in detail, and organizations should treat documentation as supporting compliance rather than guaranteeing it. Legal advice on the particular processing activities and applicable jurisdiction is advisable, as expectations may differ between EU member states, the UK, and other regimes.
Which joint controller should handle data subject requests relating to consent-based tracking?
The arrangement between joint controllers should typically designate how data subject rights are handled, and it is common to identify a contact point. However, under the GDPR a data subject may generally exercise their rights in respect of and against each joint controller, so a single designated contact does not by itself prevent an individual from approaching another party. Practically, joint controllers should coordinate so that requests concerning consent records, withdrawal of consent, or access to tracking data can be actioned reliably. The internal allocation governs the relationship between the parties but does not necessarily restrict the individual's ability to choose whom to contact.
How does joint controllership interact with consent management and consent records?
Where consent is the legal basis for non-essential cookies or similar technologies under EU and UK rules, joint controllers should be clear on who is responsible for obtaining, evidencing, and honoring that consent, and for maintaining records demonstrating it. A consent management platform can support these tasks, but it does not by itself resolve which party bears responsibility, nor does it substitute for a documented allocation. The interaction between ePrivacy consent for placing or accessing information on a device and the GDPR basis for subsequent processing should be considered separately, and responsibilities may be split across those stages depending on the facts.
Can a contract between joint controllers limit their exposure to regulators or data subjects?
An arrangement can allocate responsibilities and may govern indemnities and cost-sharing between the parties, but it generally does not limit the ability of a data subject to seek a remedy against any joint controller, nor does it necessarily bind a supervisory authority's assessment of responsibility. In other words, internal contractual allocation operates primarily between the parties rather than as a shield against external claims or enforcement. The exact effect depends on applicable law and the facts, and organizations should not assume that a contract alone caps their liability. This entry does not address the specific enforcement positions of individual authorities, which may evolve.

Common misconceptions

A contract stating that one party is a processor, or that the parties are not joint controllers, conclusively determines the relationship.
Under the GDPR, controllership is assessed on the factual reality of who determines the purposes and means of processing, not on the labels the parties choose. A written arrangement is generally required, but it cannot override the actual roles the parties play in the processing.
Joint controllership means each party is equally liable for the entire processing operation.
Joint controllership does not generally imply equal or identical responsibility. The GDPR contemplates that obligations reflect each party's actual involvement, and joint responsibility typically attaches only to the operations for which the parties jointly determine purposes and means. How liability is ultimately apportioned depends on the facts and applicable guidance.
Establishing joint controllership resolves whether valid consent was obtained for cookies.
Joint controllership is a GDPR concept concerning responsibility for processing personal data. The requirement for prior consent to place or access cookies and similar technologies stems from the ePrivacy Directive and its national implementations. Identifying who is a controller does not by itself satisfy or resolve the separate consent obligation, and the two questions should not be conflated.

Best practices

Assess the factual roles of each party involved in cookie-related processing to determine whether a joint controllership, controller-processor, or independent controller relationship exists, rather than relying on how the parties describe themselves.
Where joint controllership applies, put in place a transparent Article 26 arrangement allocating responsibilities, particularly for handling data subject rights requests and providing information to individuals, and make the essence of that arrangement available to users.
Keep the ePrivacy consent analysis (placing and accessing information on a device) separate from the GDPR controllership analysis, and document how each obligation is being met for the relevant jurisdictions.
Map which processing operations are actually jointly determined, and avoid assuming joint responsibility extends to the entire data lifecycle when it may only cover specific stages.
Prepare for data subjects to exercise their rights against any joint controller by establishing internal procedures and points of contact, since individuals are generally not bound by the internal allocation of responsibilities.
Treat any consent management platform or contractual arrangement as support for, not a substitute for, legal judgment, and revisit allocations of responsibility as data protection authority guidance and enforcement positions evolve across the EU, UK, and other applicable regimes.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.