Your GDPR contract label means nothing if the facts say otherwise.

Your GDPR contract label means nothing if the facts say otherwise.

Your GDPR contract label means nothing if the facts say otherwise.

Two organisations sharing control over personal data need more than a label, they need a joint controller agreement that reflects reality and protects both sides

Joint Controller Agreements Under GDPR: Clarity Creates Confidence

When two organisations jointly decide how and why personal data is processed, they may be joint controllers under the GDPR. In that case, a clear agreement is not optional; it is essential. It should spell out who handles privacy notices, consent, data subject requests, security, breach response and contact with regulators.

GDPR Liability: What Is Really at Stake

The risks go beyond paperwork. Regulators can impose fines up to €10 million (or 2% of global turnover), rising to €20 million (or 4%) for serious infringements. Individuals can also claim compensation for material or non-material damage under Article 82 GDPR. Where several controllers share responsibility for the same processing, each can be held liable for the full amount, so the affected person is compensated without delay. The party that pays can later seek contribution from the others, based on their share of responsibility.

This is exactly why a joint controller agreement matters for internal risk allocation. It should cover:

1.     How liability is divided.

2.     Who pays compensation.

3.     How legal costs are shared.

4.     How regulatory investigations are managed.

5.     Whether indemnities apply.

6.     Insurance requirements.

7.     Cooperation in litigation.

8.     Access to evidence.

9.     Settlement authority.

10.  Contribution and recovery claims.

The agreement cannot remove an individual's rights, but it can remove uncertainty between the parties.

Controller vs Processor: A Label Does Not Decide the Role

A common mistake is assuming a contract can settle GDPR roles simply by naming one party “controller” and the other “service provider.” The real test is who actually decides the purpose and means of processing, assessed activity by activity. Dutch case law confirms this twice over. In DPS v Facebook (ECLI:NL:RBAMS:2023:1407), the court held that the concept of controller is functional, not contractual. In ECLI:NL:RBROT:2025:14138, the court confirmed that depending on a partner contractually does not erase a controller's own responsibility.

In short, the agreement should reflect what actually happens, not the label the parties prefer.

The Bottom Line

A joint controller agreement is not just paperwork. It is a governance tool that protects organisations, clarifies accountability and builds trust. Clear roles today prevent costly disputes tomorrow.

Search