← GDPR · Controller obligations

Art.26 — Joint controllers

medium vendor-managementroles-responsibilities

Requirement

Where two or more controllers jointly determine the purposes and means of processing, they must set out their respective responsibilities — in particular for data subject rights and transparency — in an arrangement whose essence is made available to data subjects.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
joint controllerjoint controllersjointly determinejoint controllership
Required element 2 — any one of
arrangementagreementresponsibilit…allocat…
Supporting terms — specificity signals
article 26essencemade availablepoint of contactdata subject rights

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA 1798.100(d) Contracts with service providers, contractors and third parties vendor-management
SOC 2 CC1.3 Organisational structure and reporting lines roles-responsibilities
SOC 2 CC1.5 Accountability for control responsibilities roles-responsibilities
SOC 2 CC2.3 External communication vendor-management
SOC 2 CC9.2 Vendor and business partner risk management vendor-management
ISO 27001 A.5.2 Information security roles and responsibilities roles-responsibilities
ISO 27001 A.5.19 Information security in supplier relationships vendor-management
ISO 27001 A.5.23 Information security for use of cloud services vendor-management