How to distinguish between joint controllership and data processing?

07 May 2019

Before the entry into force of the GDPR, the concept of joint administration did not exist. All joint ventures and data sharing were considered in terms of data processing agreements.

Many organizations are still uncertain about the circumstances under which entering into a particular type of agreement would be appropriate and when it would be incorrect. In this article, we outline the criteria that can assist in providing the correct answer. If you would like to learn how to distinguish data processing from data sharing, we discuss this here.

Joint Administration vs. Data Processing

Joint administration means that at least two data controllers jointly determine the purposes and means of processing personal data (Article 26(1) GDPR). A classic example of joint administration is a situation where several entities organize a joint venture or share a specific resource, such as an IT system, clearly defining how it will be secured and the purposes for which it will be used.

On the other hand, data processing occurs when a data processor (natural person, legal entity, public authority, or unit) processes personal data on behalf of the data controller (Article 4(8) and Article 28 GDPR). A simple example of data processing is utilizing the services of an external company that specializes in data storage (e.g., archives, cloud services) or data destruction (a document and media disposal company).

There is no joint determination of purposes or means here—the purposes belong to the data controller, and the data processor merely provides a service that the data controller can use for its own purposes.

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
In both cases, there is an obligation to conclude appropriate agreements (Article 26 and 28 GDPR). The identification of joint controllership is also associated with the requirement to indicate the joint controllers in the records of processing activities (Article 30(1)(a) GDPR), as well as in the privacy notices (Articles 13 and 14 GDPR), where it is easiest to fulfill the obligation to inform about the essential content of the arrangements between the joint controllers (Article 26(2) GDPR). In turn, in the case of entrusting processing, the data controller should be able to demonstrate why they believe that the data processor guarantees compliance with the requirements of the GDPR (Article 28(1) GDPR).

What are the functions of joint controllership and what are those of entrusted processing?

The best way to acquire the skill of distinguishing joint controllership from entrusted processing is to understand the different functions that these two legal constructs serve.

Entrusting processing protects the interests of the data controller, who, in order to achieve their goals, decides to use the services of external entities. In this case, the data controller usually does not have physical control over the personal data – they do not configure the resources, do not know the employees, and often do not even know the exact location where the personal data is stored – unlike the situation when the data is processed by their internal employees. A data processing agreement is then necessary for the data controller to be able to seek potential liability for actions not in accordance with their instructions from the external entity.

Example:
An organization established fifty years ago has no space to store the personal files of former employees. Therefore, it entrusts this task to an archiving company. Thanks to the data processing agreement, the employer retains control over the data and can seek contractual liability from the archiving company if necessary.

Joint controllership protects the interests of each of the controllers, as the agreement on the division of responsibilities among the joint controllers clearly indicates the scope for which each of them is responsible. For example, the joint controllers may determine that the responsibility for fulfilling the requirements of the GDPR rests with this joint controller:

  • in terms of determining the purpose, scope, and recipients of the processed data – on whose behalf a given agreement is concluded or serviced,
  • in terms of ensuring technical and organizational security measures – which include resources processing personal data,
  • in terms of fulfilling the rights of data subjects – which is capable of fulfilling such a request,
  • in terms of collecting consents for data processing and meeting the information obligation – which is the first to obtain personal data.

Despite various definitions and functions of data processing entrustment and joint administration, the boundary between these concepts may become blurred – especially within a capital group, where there are numerous data flows, shared services, or systems. Determining whether we are dealing with data processing entrustment or joint administration depends on the fulfillment of the criteria explained below.

FREE

Entrustment or Sharing? That is the Question

Watch the webinar

Criterion 1: Actual Control over Determining the Purposes and Means of Processing

Both data processing entrustment and joint administration occur when the conditions of their definitions are met. It is possible to have a situation where an incorrect agreement has been made – i.e., despite entering into a data processing entrustment agreement, in practice, joint administration occurs or vice versa.

If two or more data controllers jointly determine the purposes and means of processing, they are joint controllers regardless of whether a relevant agreement has been concluded. Similarly, when one entity processes data on behalf of another, it is a data processor regardless of whether a relevant agreement has been concluded. The absence of such agreements constitutes non-compliance with the GDPR.

It follows from the above – and this is also the prevailing view – that the existence of data processing entrustment or joint administration is determined based on the answer to the question of who actually decides on the purposes and means of data processing (who has actual control and can issue instructions).

The Article 29 Working Party on data protection (replaced by the European Data Protection Board) included the following examples of joint controllership and data processing delegation in its Opinion 1/2010 on the concepts of "data controller" and "data processor" (00264/10/PL WP169).

Example
of joint controllership:
A recruitment agency provides a global matching service for an employer, searching for candidates across its entire database – not only among CVs submitted to the employer.
data processing delegation: The recruitment agency posts a job advertisement and conducts recruitment on behalf of the employer – solely based on responses to that specific advertisement.

As evidenced by the above examples, even if the recruitment agency conducts recruitment for the employer (i.e., for the employer's purposes), if a broad database of the recruitment agency is utilized in the recruitment process, we are dealing with joint controllership. This is due to the fact that the recruitment agency also effectively decides on the purposes and means of processing (in relation to its own pool of candidates).

GDPR Compliance Diagnosis - Do it yourself!

Criterion 2: joint venture

When there are doubts about who actually decides on the purposes and means of data processing, it is useful to ask a supplementary question: whose purposes will be pursued? If the purposes are shared or at least coexist within a single venture, it is most likely that we are dealing with joint controllership. The following examples illustrate this.

Example
of joint administration:
“Through the online platform, your organization offers childcare services. At the same time, your organization has an agreement with another company that allows you to offer additional services. These services enable parents not only to choose a caregiver but also to rent games or DVDs that the caregiver will bring along. Both companies participate in the technical configuration of the website. In this example, both companies have decided to use the platform for two purposes (childcare services and renting games or DVDs), and they will often share customer names. The companies are joint controllers because they have not only agreed on a combined offering but also design and utilize a shared online platform.”
data processing: “The brewery employs many workers. It signs a contract with a payroll company to disburse salaries. The brewery informs the payroll company when salaries should be paid, when an employee leaves, when they receive a raise, and also provides all other details for the payslip and payment. The payroll company provides the IT system and stores employee data. The brewery is the data controller, while the payroll company is the data processor.” In this case, the payroll company fulfills the employer's objectives, as that is the nature of its service. Source of examples: European Commission website.

Criterion 3: resource sharing

The greatest certainty in identifying joint administration is achieved when at least two entities jointly decide on both the purposes and the means of processing data. As stated in Opinion 1/2010 of the Article 29 Working Party: “In the context of joint control, the involvement of the parties in jointly determining the purposes and means may take various forms and does not have to be evenly distributed. In the case of multiple entities, they may be very closely linked (having, for example, all common purposes and means of processing) or remain in looser relationships (for example, having only common purposes or common means of processing or part of them).” According to the reasoning presented, the following situations can be distinguished.

Example
co-administration
: Two entities maintain a joint database, the security of which they jointly decide upon, but which each of them uses for their own purposes.
data processing: Company A decides to use an IT system provided by another company from the same capital group – Company B – to serve its clients. Personal data is stored on Company B's servers, with Company B not interfering with its content or using it for its own purposes. In this situation, Company B is a data processor.

Summary

Understanding the definitions and functions of data processing and co-administration is crucial for determining which legal construct we are dealing with. In case of doubt, we should examine who has actual control over the data, for whose purposes the data is being processed, and whether there is any data processing on shared resources. If in any of the cases at least two entities are making decisions, it is most likely that we are dealing with co-administration.

A precise distinction between co-administration and data processing would be facilitated by additional guidelines and case law from courts and supervisory authorities. Nevertheless, for the supervisory authority investigating compliance with the GDPR, the most important aspect will be to determine who is formally responsible for the data processing operations, as well as whether the data was processed and shared on a valid legal basis. The absence of any analysis and agreement will be a much greater non-compliance than an incorrect interpretation of the regulations and the conclusion of the wrong type of agreement.

Still unsure how to distinguish data processing from co-administration? Contact Marcin Kuźniak, our data protection advisor. He will explain the difference to you and point out the appropriate solutions.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.