A joint controller is one of two or more organisations that together decide why and how personal data is processed. Article 26 of the General Data Protection Regulation (GDPR) attaches consequences to that status. The parties must divide their compliance duties in a transparent arrangement, make its essence available, and accept that an affected individual can pursue any one of them over the processing they share. The concept exists because data processing rarely has a single author. A website places a tag, a platform writes the code, and personal data moves because both acted.
In advertising, the label decides who answers for pixels, software development kits, social plug-ins, consent frameworks and co-marketing data deals. It is also where case law has most widened responsibility beyond the company that ends up holding the data.
The test for joint control
Article 4(7) of the GDPR defines a controller as the body that, "alone or jointly with others", determines the purposes and means of processing. Joint control arises when that determination is shared. The European Data Protection Board (EDPB), in Guidelines 07/2020, describes two routes: a common decision taken together, or converging decisions that complement each other so that the processing "would not be possible without both parties' participation".
Three clarifications from the Court of Justice of the European Union (CJEU) set the reach of that test. Access to the data is not required, so a party can be a joint controller without ever seeing a record. Responsibility need not be equal, since operators "may be involved at different stages of that processing and to different degrees". And control is assessed operation by operation: a company can be a joint controller for collection and transmission, and a stranger to everything that happens afterwards.
No contract is needed to trigger the status. On December 5, 2023, in a Lithuanian case about a Covid-19 contact-tracing app (C-683/21), the court held that joint controllership does not depend on a formal arrangement between the parties. The Article 26 arrangement is a duty that follows from the status, not a precondition for it.
What the arrangement must cover
Article 26(1) requires joint controllers to set out "in a transparent manner" their respective responsibilities, in particular for handling data subject rights and for the information notices required by Articles 13 and 14. Article 26(2) requires the arrangement to reflect the parties' real roles and makes its "essence" available to the people whose data is processed. Article 26(3) then limits what the paperwork can achieve: individuals may exercise their rights against each controller, whatever the division of duties says.
On form, the EDPB recommends a binding contract that also covers legal basis, security, breach notification, impact assessments, processors and international transfers. Liability sits in Article 82(4), which holds each party involved in the same processing liable "for the entire damage", with Article 82(5) letting the party that paid recover a share from the others. Regulators may choose their target: Germany's Federal Administrative Court confirmed on September 11, 2019 that an authority could order a Facebook page operator, rather than Facebook, to deactivate the page.
Where it appears in advertising
Tags and pixels. Decided on July 29, 2019, the Fashion ID judgment (C-40/17) held that an online clothing retailer embedding Facebook's Like button was a joint controller with Facebook for collecting visitors' data and disclosing it by transmission. The button sent data whether or not visitors clicked it or held an account. Responsibility for what Facebook did next stayed with Facebook. Meta's Business Tools Terms now include a controller addendum reflecting that split, and advertisers using the Conversions API carry joint controller responsibility under Article 26 for the lawful basis of what they send.
Brand pages. In Wirtschaftsakademie (C-210/16), decided on June 5, 2018, the court held that a Facebook page administrator was jointly responsible with Facebook for visitor statistics, because it set audience parameters for the Insights service.
Consent frameworks. On March 7, 2024 the CJEU ruled in IAB Europe (C-604/22) that the Transparency and Consent String (TC String) generated by consent management platforms is personal data. A standard-setter whose mandatory rules shape how that string is processed can be a joint controller for it, though not automatically for what bidders later do in real-time bidding. The framework had 953 registered vendors and 181 consent platforms at the end of 2025.
Retargeting. France's data protection authority, the CNIL, fined Criteo 40 million euros on June 15, 2023. Among other failings, its agreement with partner websites left rights requests, breach notification and impact assessments unallocated. The Conseil d'Etat upheld the fine on March 4, 2026, ruling that partner contracts could not substitute for Criteo's own proof of consent.
From directive to regulation
The idea predates the GDPR. Article 2(d) of the 1995 Data Protection Directive already defined the controller as the body deciding "alone or jointly with others", and the Article 29 Working Party's Opinion 1/2010, adopted on February 16, 2010, described how shared control could arise. What the directive lacked was any rule on how joint controllers should split their duties.
The GDPR, adopted on April 27, 2016 and applicable from May 25, 2018, added Article 26 to fill that gap. The court then widened the concept in quick succession: Wirtschaftsakademie in June 2018, Jehovan todistajat on July 10, 2018, which held a religious community jointly responsible for notes taken by members preaching door to door, and Fashion ID a year later. The EDPB adopted Guidelines 07/2020 for consultation on September 2, 2020 and in final form on July 7, 2021, replacing the 2010 opinion. On December 2, 2025, in Russmedia (C-492/23), the Grand Chamber found an online marketplace jointly responsible with an anonymous user for personal data in an advertisement, partly because its terms reserved a right to reuse ad content.
Why the status carries weight
For advertisers and publishers, installing third-party code can create exposure for processing they never see. In Dresden, the Higher Regional Court held on February 3, 2026 that website operators embedding Meta's tools share responsibility with Meta and, citing Fashion ID, that each joint controller must obtain consent for its own purposes. It awarded 1,500 euros to each of four plaintiffs. A court in Jena awarded 3,000 euros on March 2, 2026, with about 10,000 claims then pending against Meta in German courts.
A publisher's banner has to cover the purposes of every partner sharing control of collection, which is how single clicks come to authorise hundreds of companies. A noyb complaint against the online dictionary dict.cc, filed on July 30, 2026, counted 1,741 named partners behind one button.
Limits and disputes
The breadth of the doctrine remains contested. Advocate General Michal Bobek proposed on December 19, 2018 confining the website operator's responsibility to the stage it co-determines, a limit the court adopted in Fashion ID, yet the operator still carries consent and notice duties for a flow it cannot inspect.
IAB Europe disputed a factual premise of the 2024 ruling, arguing that several of its members do not implement the framework at all. Belgium's Market Court confined its joint controllership to TC String processing on May 14, 2025, excluding downstream OpenRTB activity, and on January 7, 2026 annulled the regulator's validation of its action plan. "We welcome this ruling by the Market Court and its clear confirmation of IAB Europe's limited role in the TCF," said Townsend Feehan, its chief executive. The 250,000 euro fine imposed by the Belgian authority on February 2, 2022 stands.
National courts diverge too. On July 17, 2025 the Administrative Court of Cologne rejected joint controllership for the German federal government's Facebook page, reasoning that only Meta accessed visitors' devices and that the Insights feature had been withdrawn. The Federal Commissioner for Data Protection, who ordered the page shut on February 17, 2023, has appealed. Arrangements draw criticism too: platform addenda are standard-form documents, and Berlin's data protection authority questioned in November 2018 whether Facebook's disclosures let page operators meet their accountability duties.
Not the same as
Processor. A processor acts on a controller's documented instructions under an Article 28 contract and sets no purposes of its own. Straying outside those instructions carries its own risk: the CNIL fined Optimove 1 million euros on December 11, 2025 for copying a client's user data for internal use.
Independent controller. Two parties can both be controllers without jointly controlling anything. Google states that it and Ad Manager publishers "operate as independent controllers of personal data", while acting as a processor for certain features.
Joint and several liability. Article 82(4) makes each party liable for the entire damage whenever several are involved in the same processing, including a controller and its processor. Liability can be shared without control being shared.
Recent developments
Dusseldorf's Higher Regional Court has asked the CJEU whether the essence of an Article 26 arrangement must be published on the website itself or merely supplied on request, in case C-287/26, lodged on April 4, 2026. Dresden's court again found Meta jointly responsible with sites embedding its Business Tools on April 13, 2026, in a case brought by an Instagram user.
Regulators keep extending the concept. The CNIL's March 12, 2026 recommendation on email tracking pixels says delivery and pixel providers can become joint controllers when they reuse open data for their own purposes. The EDPB's Guidelines 03/2026 on web scraping, adopted on July 7, 2026, treat companies that jointly set scraping criteria for a model as joint controllers. Hamburg's data protection commissioner concluded on September 10, 2026 that Ray-Ban Meta wearers and Meta become joint controllers for bystander data once AI training is enabled.
Timeline
- October 24, 1995: Data Protection Directive defines the controller as deciding "alone or jointly with others"
- February 16, 2010: Article 29 Working Party adopts Opinion 1/2010 on controllers and processors
- November 3, 2011: Schleswig-Holstein regulator orders Wirtschaftsakademie to deactivate its Facebook page
- April 27, 2016: GDPR adopted, introducing Article 26 on joint controllers
- May 25, 2018: GDPR becomes applicable
- June 5, 2018: CJEU rules in Wirtschaftsakademie (C-210/16) that page administrators are joint controllers with Facebook
- July 10, 2018: CJEU rules in Jehovan todistajat (C-25/17)
- September 2018: Facebook publishes its Page Insights controller addendum
- December 19, 2018: Advocate General Bobek delivers his opinion in Fashion ID
- July 29, 2019: CJEU rules in Fashion ID (C-40/17) that sites embedding the Like button are joint controllers for collection and transmission
- September 11, 2019: German Federal Administrative Court upholds the Wirtschaftsakademie deactivation order
- September 2, 2020: EDPB adopts draft Guidelines 07/2020 for consultation
- July 7, 2021: EDPB adopts final Guidelines 07/2020
- February 2, 2022: Belgian data protection authority fines IAB Europe 250,000 euros
- February 17, 2023: German Federal Commissioner orders the federal government's Facebook page shut
- June 15, 2023: CNIL fines Criteo 40 million euros, citing an incomplete Article 26 arrangement among other breaches
- December 5, 2023: CJEU rules in C-683/21 that joint control requires no formal arrangement
- March 7, 2024: CJEU rules in IAB Europe (C-604/22) that the TC String is personal data and IAB Europe can be a joint controller
- May 14, 2025: Belgian Market Court confines IAB Europe's joint controllership to TC String processing
- July 17, 2025: Administrative Court of Cologne rejects joint controllership for the federal government's Facebook page
- December 2, 2025: CJEU Grand Chamber rules in Russmedia (C-492/23)
- January 7, 2026: Belgian Market Court annuls validation of IAB Europe's action plan
- February 3, 2026: Dresden Higher Regional Court holds website operators and Meta jointly responsible for Business Tools data
- March 4, 2026: Conseil d'Etat upholds the Criteo fine
- March 12, 2026: CNIL adopts its email tracking pixel recommendation
- April 4, 2026: Dusseldorf referral on publishing the arrangement's essence lodged as C-287/26
- April 13, 2026: Dresden Higher Regional Court rules again against Meta in an Instagram case
- July 7, 2026: EDPB adopts Guidelines 03/2026 on web scraping
- September 10, 2026: Hamburg regulator publishes its Ray-Ban Meta report
Related PPC Land coverage
- Explaining GDPR - The regulation's controller and processor roles, Article 26 and the enforcement record.
- Explaining consent management platform - How consent platforms encode choices into the TC String read by vendors.
- Explaining real-time bidding - The auction mechanics downstream of consent signals and the limits of IAB Europe's controllership.
- Meta's free one-click Conversions API is now live - no developer needed - Why server-side setup leaves advertisers' Article 26 obligations unchanged.
- TCF enforcement more than doubled in 2025, IAB Europe report shows - Vendor and platform counts alongside the court rulings on joint controllership.
- France's top court upholds Criteo's €40M GDPR fine - but the legal logic is contested - The Conseil d'Etat ruling on proof of consent collected by partners.
- German court blocks Meta's appeal, awards €1,500 for Business Tools tracking - Dresden's February 2026 finding that website operators and Meta share responsibility.
- Thuringia's court hits Meta with €3,000 damages for tracking without consent - The Jena ruling and the volume of pending claims in Germany.
- dict.cc faces GDPR complaint over 1,741-partner consent click - noyb's challenge to one consent click covering hundreds of vendors.
- Belgian court limits IAB Europe's role in TCF framework - The May 2025 ruling confining joint controllership to the TC String.
- Belgian court hands IAB Europe a major TCF win - The January 2026 annulment of the action plan validation.
- French regulator fines Israeli marketing platform €1M for processor violations - What happens when a processor uses client data beyond instructions.
- German court asks CJEU: must platforms publish GDPR joint controller details? - The pending referral on how the arrangement's essence reaches data subjects.
- Dresden court hits Meta with €1,500 GDPR fine over Instagram tracking - The April 2026 ruling treating Meta and embedding sites as joint controllers.
- Meta faces up to 250,000 euro fine per fake Finanzfluss ad after court loss - A Frankfurt ruling that left the Russmedia question open.
- CNIL's final rules on email tracking pixels are here - what changes - When email service and pixel providers become joint controllers.
- Consent collapses on three fronts as Zeta faces investor suit - EDPB scraping guidance separating processors, joint controllers and separate controllers.
- Hamburg regulator finds Ray-Ban Meta glasses expose bystanders without consent - Joint controllership between wearers and Meta for AI training data.
- One LG TV mapped 38 devices on the network it was plugged into - LG's own designation of joint controllers for television profiling.
Summary
Who. Any two or more organisations that jointly determine the purposes and means of processing: advertisers and publishers embedding platform tags, page administrators and social networks, standard-setters and framework participants, marketplaces and the users who post on them. The CJEU, the EDPB and national regulators and courts define where the line falls.
What. A legal status under Article 26 of the GDPR requiring the parties to allocate compliance duties in a transparent arrangement, make its essence available to data subjects, and answer individually for rights requests and, under Article 82(4), for the entire damage.
When. The concept appeared in the 1995 Data Protection Directive, gained its own article when the GDPR applied on May 25, 2018, and was widened by CJEU rulings from 2018 to 2025, with a referral on publishing the arrangement pending since April 2026.
Where. Across the European Economic Area and in the UK's retained GDPR, wherever data flows through embedded code, shared consent signals, co-branded campaigns or platform pages that more than one party helped design.
Why. Shared decisions produce shared accountability. The status stops platforms and their customers from each pointing to the other, and it is the reason a pixel, plug-in or consent banner can leave an advertiser or publisher answerable for data it never holds.
Discussion