Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do teams get wrong about joint controllers…
Governance, Ownership & Risk

What do teams get wrong about joint controllers in GDPR implementations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating a joint controller arrangement as a way to shift responsibility away from either party. Joint controllers must transparently allocate their respective obligations in a legal arrangement, but that arrangement does not remove data subject rights against each controller. Teams also understate the need for a clear contact point and documented role split.

What joint controllers are supposed to solve

Joint controllership exists because two parties may jointly decide why and how personal data is processed. In that situation, gdpr expects the relationship to be formalised, not blurred. The core task is to define who does what, who handles which notices and requests, and how the parties coordinate so the arrangement is understandable to the data subject and workable in practice.

A useful way to think about it is that joint control is a responsibility-sharing model, not a liability-dumping model. The parties can allocate obligations between themselves, but they cannot contract away the GDPR duties that still apply to each of them under the arrangement.

The most common error is assuming that a joint controller agreement shifts accountability to the other party. It does not. The agreement is meant to organise execution, not erase the underlying controller role. That is why teams should treat the arrangement as part of operational governance, not as a paper shield that sits outside the privacy programme.

Another frequent mistake is over-focusing on internal wording and under-focusing on the external experience. If the arrangement does not clearly explain the contact point, the division of duties, and how rights requests are handled, the governance model may be technically signed but still fail the practical test.

This is where clear documentation matters. The role split should be specific enough that teams can answer, without debate, who owns notices, consent or lawful-basis communications, security coordination, retention decisions, and subject-rights handling. The EU General Data Protection Regulation (GDPR) also expects the arrangement to sit alongside core principles such as transparency, data protection by design, and security of processing.

What good looks like in a joint controller setup

A sound setup starts with a documented allocation of responsibilities that is easy to operationalise. Each party should know which notices it issues, which records it maintains, which requests it can receive directly, and which issues must be escalated to the other controller. That clarity is especially important when the processing spans multiple products, channels, or business units.

Teams also need to verify that the arrangement matches reality. If one party actually controls the processing purpose, chooses the retention logic, or determines the response workflow, the paper split should not claim otherwise. A mismatch between contractual language and operational control is a common source of compliance drift.

For teams mapping privacy obligations to control frameworks, it is often helpful to align the joint-controller model with broader privacy governance expectations such as the NIST Privacy Framework and to connect the role split to identity and access controls where staff workflows, delegated access, or shared systems affect who can do what.

Risk and Threat Considerations

Joint controller arrangements create compliance and trust risk when the division of duties is vague, inconsistent, or treated as purely contractual. The practical exposure is not just a bad document, but missed notices, misrouted rights requests, duplicate or incomplete disclosures, and disputes over who was responsible after an incident or complaint.

Failure mechanism: The parties assume the agreement alone resolves accountability, but the operating model, customer journey, and internal control ownership do not match the written split. That can leave one controller unprepared to respond when a data subject exercises rights or when a supervisory authority asks for evidence.

Impact: The result can be non-compliant handling of requests, weaker transparency, slower incident coordination, and avoidable regulatory exposure for both controllers. In larger environments, the failure tends to scale because the same ambiguity is repeated across products, vendors, or regional implementations.

Where processing chains cross organisational boundaries, the most visible failure is often not a breach of confidentiality but a breakdown in accountability. Teams may each believe the other party is the lead, and the user is left without a reliable contact path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 26 — Joint controllersDirectly governs joint-controller role allocation and transparency to data subjects.
Art. 13 — Information to be provided where personal data are collected from the data subjectJoint controllers must still deliver clear transparency notices to data subjects.
Art. 15 — Right of access by the data subjectData-subject rights still apply against each controller despite the internal split.
Recommendation — Document the respective responsibilities and ensure the arrangement is made available to data subjects. Assign who drafts and issues the notice so transparency stays consistent across controllers. Build a shared process for receiving and answering access requests within the agreed role split.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingUseful where joint controllers need evidence of who handled notices and requests.
Recommendation — Retain auditable records showing which controller performed each privacy action.
ISO/IEC 27001:2022A.5.15 — Access controlJoint-controller operations often depend on clear role-based access boundaries to shared systems.
Recommendation — Restrict shared-system access so each controller can only perform its assigned privacy tasks.

Practitioner Guidance

What to verify: Check that the documented role split matches the actual control point for each material obligation, especially notices, rights handling, retention, and escalation. If the agreement says one party owns a task but operations say another party performs it, treat that as a governance defect, not a wording issue.

Decision rule: If a control is shared, name the owner of execution, the owner of evidence, and the escalation path for exceptions. If those three are not explicit, the arrangement is not yet ready for audit or subject-access pressure.

Practitioner takeaway: Joint controller management succeeds when teams can prove who does what in practice, not just who signed the agreement. The best test is whether a rights request, notice change, or incident can be handled cleanly without internal confusion.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org