← GDPR · Controller obligations
Art.26 — Joint controllers
Requirement
Where two or more controllers jointly determine the purposes and means of processing, they must set out their respective responsibilities — in particular for data subject rights and transparency — in an arrangement whose essence is made available to data subjects.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| CCPA/CPRA | 1798.100(d) | Contracts with service providers, contractors and third parties | vendor-management |
| SOC 2 | CC1.3 | Organisational structure and reporting lines | roles-responsibilities |
| SOC 2 | CC1.5 | Accountability for control responsibilities | roles-responsibilities |
| SOC 2 | CC2.3 | External communication | vendor-management |
| SOC 2 | CC9.2 | Vendor and business partner risk management | vendor-management |
| ISO 27001 | A.5.2 | Information security roles and responsibilities | roles-responsibilities |
| ISO 27001 | A.5.19 | Information security in supplier relationships | vendor-management |
| ISO 27001 | A.5.23 | Information security for use of cloud services | vendor-management |