Joint controller data sharing agreement: what it is and what to include

A joint controller data sharing agreement is a contract between two or more organizations that together decide why and how a defined set of personal data is processed, setting out who is responsible for each privacy obligation. It exists so that individuals know which party to approach about their data and so each organization can demonstrate that it met its legal duties.

What a joint controller data sharing agreement is

Under the EU General Data Protection Regulation (GDPR), and the mirrored UK GDPR, two or more organizations become “joint controllers” when they jointly determine the purposes and means of processing personal data. Article 26 of the GDPR requires joint controllers to allocate their respective responsibilities through a transparent arrangement, and to make the essence of that arrangement available to the people whose data is processed. The joint controller data sharing agreement is the document that records this allocation and turns a shared intention into an accountable, auditable commitment.

It helps to place this instrument in the US context. US federal law does not use the “controller” or “joint controller” vocabulary; instead, sector rules (such as HIPAA, GLBA, and the FCRA) and state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) and the Colorado, Connecticut, Texas, and Virginia statutes rely on terms like “business,” “third party,” “service provider,” “contractor,” “controller,” and “processor.” None of these state laws establishes a formal joint controller regime identical to GDPR Article 26. In practice, a US company most often needs a joint controller data sharing agreement when it processes the personal data of people located in the EU or UK, or when it co-determines processing purposes with an EU or UK partner, because the GDPR can apply to US organizations extraterritorially.

It is worth distinguishing this agreement from two close neighbors. A controller-to-processor data processing agreement (DPA) governs a one-way relationship in which one party only acts on the other’s documented instructions. A controller-to-controller data sharing agreement covers independent controllers who each decide their own purposes separately and simply exchange data. A joint controller arrangement is different in kind: the parties share the decision-making itself, which is why their obligations are intertwined rather than sequential.

Key terms and clauses to include

A robust joint controller data sharing agreement should address the following:

  • Parties and roles. Identify each organization, confirm that they act as joint controllers for the described activity, and state plainly which processing operations are jointly determined.
  • Purpose and scope. Describe the jointly determined purposes, the categories of personal data, the categories of data subjects, and the sources of the data. Vague scope is a frequent source of later disputes.
  • Allocation of responsibilities. Set out who is accountable for each core duty: providing transparency information, establishing and documenting a lawful basis, maintaining records of processing, and conducting a data protection impact assessment (DPIA) where required.
  • Single point of contact. Designate a contact point for individuals. The GDPR allows data subjects to exercise their rights against each controller regardless of the internal split, so the contact point is a practical convenience, not a limit on those rights.
  • Data subject rights. Define the workflow, timelines, and responsible party for access, rectification, erasure, restriction, objection, and portability requests, including how the parties will assist each other.
  • Transparency and notices. Specify who drafts and issues the privacy notice, and how the essence of the arrangement will be made available to data subjects, as Article 26 requires.
  • Security measures. Describe the technical and organizational measures each party will maintain, such as encryption, access controls, and logging.
  • Personal data breach. Set notification duties and timelines between the parties, and clarify who notifies the relevant supervisory authority and affected individuals.
  • International transfers. If personal data crosses borders, identify the transfer mechanism, such as Standard Contractual Clauses, an adequacy decision, or the EU-US Data Privacy Framework.
  • Sub-processing and onward sharing. State whether either party may engage sub-processors or share data onward, and on what conditions.
  • Liability and indemnity. Allocate liability between the parties, keeping in mind that joint controllers may face joint and several liability toward data subjects under the GDPR.
  • Cooperation and audit. Provide for mutual assistance with regulator inquiries, audits, and evidence requests.
  • Term, termination, and data handling on exit. Define duration, termination triggers, and what happens to shared data (return, deletion, or continued lawful use) when the arrangement ends.
  • Governing law and disputes. Name the governing law and the forum or process for resolving disagreements between the parties.

When you need one

You likely need a joint controller data sharing agreement whenever you and a partner jointly decide both the “why” and the “how” of processing personal data. Common triggers include co-branded services or shared platforms where two brands operate one customer experience, joint marketing or events where both parties determine the campaign purposes, shared referral or CRM arrangements, research collaborations, and analytics or advertising setups where the parties co-determine how data is used. Group companies that pool HR or customer data for a shared purpose can also fall into joint controllership. A useful signal test: if neither party could unilaterally change the purpose without consulting the other, joint controllership is probably in play, and a written agreement should follow before data begins to flow.

Common pitfalls

The most damaging mistake is mislabeling the relationship, for example calling a partner a processor when the parties genuinely share decision-making, because that misstates everyone’s duties. Others include leaving the allocation of data subject rights silent, so requests fall through the cracks; failing to make the essence of the arrangement available to individuals; and adopting a generic template that does not match how data actually moves. Teams frequently overlook international transfer mechanisms, underestimate joint and several liability, and forget to revisit the agreement when the processing changes. Finally, poor version control, with the signed agreement scattered across inboxes and shared drives, undermines the accountability the document is meant to provide.

Disciplined contract management closes these gaps. Storing each executed joint controller data sharing agreement in a single repository, routing it through structured approval workflows, signing it with eIDAS electronic signature, and setting renewal and deadline alerts keeps the arrangement current and auditable. Pactolane provides that repository, workflow, signature, alerting, and audit trail, and PactAI can support review with compliance playbooks, risk scoring, conflict detection, and exposure analysis so your team spots issues early. PactAI prepares the analysis; your people and your counsel make the decisions. This page offers general legal information, not legal advice, and any jurisdiction-specific question should be confirmed with qualified counsel.

Key clauses in this agreement

The clauses that carry the risk in this contract type.

Frequently asked questions

What is a joint controller data sharing agreement?

A joint controller data sharing agreement is a contract between two or more organizations that jointly decide the purposes and means of processing a set of personal data. It allocates who handles each privacy obligation, such as answering data subject requests, providing the privacy notice, and reporting breaches. Under GDPR Article 26, the essence of this arrangement must also be made available to the individuals whose data is shared.

How is it different from a data processing agreement (DPA)?

A data processing agreement governs a one-way relationship in which a processor acts only on a controller's documented instructions. A joint controller data sharing agreement applies when the parties share the decision-making about why and how data is processed, so neither party is merely following orders. Choosing the wrong instrument is a common compliance error, because the legal duties and liability differ significantly.

Do US companies need a joint controller data sharing agreement?

The joint controller label comes from the EU and UK GDPR, not from US federal or state privacy law. A US company typically needs one when it processes the personal data of people in the EU or UK, or when it co-determines processing purposes with an EU or UK partner, because the GDPR can reach US organizations on an extraterritorial basis. US state privacy laws use different terminology, so counsel should confirm which framework governs your arrangement.

What must a joint controller data sharing agreement contain?

At a minimum it should identify the parties and confirm their joint controller status, describe the shared purposes and data categories, and allocate responsibility for transparency, security, and data subject rights. It should name a contact point for individuals, set breach notification duties, address international transfers, and allocate liability between the parties. GDPR Article 26 also requires that the essence of the arrangement be communicated to data subjects.

Who is liable if joint controllers mishandle personal data?

Under the GDPR, joint controllers can face joint and several liability toward data subjects, meaning an individual may seek full compensation from any one of them regardless of the internal split. The agreement's internal liability and indemnity clauses then govern how the parties recover from each other. This is why a clear, written allocation of responsibilities matters so much.

In the same family

On the same topic

Other pages closely related to this one.

This page provides general legal information, not legal advice. Every situation is specific: for a binding contract, consult a qualified legal professional.

Manage my cookies