Unbenanntes Dokument

Joint Control


Intro: What is a joint control agreement, what is its function and what needs to be considered when implementing it?

To-Dos: What is the specific procedure for concluding a JCA agreement and the associated obligations?

Statements: What have the data protection supervisory authorities published on the subject of data portability?






Processing personal data under joint responsibility





What is a joint control agreement, what is its function and what needs to be considered when implementing it?

Data processing in the form of a so-called “joint control” is characterized by two or more companies who process personal data on the basis of co-defined purposes and co-defined processing measures.

An example for such a joint control processing is the usage of a common storage infrastructure. The controllers might store different data categories on this server and pursue different purposes with the data. However, as long as they together define the purposes and means of the processing, a joint control processing prevails and a contract between the parties must be concluded.

The requirement’s purpose is to ensure that the segregation of modern business solutions does not lead to a state in which it becomes unclear who is in charge of a certain processing activity. The contract establishes clarity between the responsible parties and allows for an allocation of legally defined tasks with respect to the fulfillment of data subject rights (e.g. right to access personal information). The disclosure of essential elements of this agreement to the data subject enables the latter to identity the responsible parties and address their concerns accordingly.

In particular, the JCA agreement must regulate which party assumes which data protection obligations (e.g. carrying out a data protection impact assessment). In addition, a so-called contact point for the data subject can be defined. In other words, a point to which data subjects can turn in order to exercise their data protection rights vis-à-vis the controller.

The essential contents of the JCA contract must be made available to the data subjects, which can be done via a website, for example. The data protection notices must also specify the controller responsible for the respective processing (name, address, contact details).



What is the specific procedure for concluding a JCA agreement and the associated obligations?

1

Definition of processing operations for which joint controllership exists


2

Definition of spheres of responsibility within the defined joint processing.


3

Agreement on the duties of the individual responsible parties


4

Definition of a data subject rights contact point, if applicable


5

Mutual support in the implementation of data protection obligations related to joint responsibility.




What have the data protection supervisory authorities published on the subject of data portability?


>> Find out which other data protection obligations have to be considered with respect to European data protection law.



Unbenanntes Dokument


Appoint a cost-effective data protection officer now

Do you need support with the implementation of data protection requirements? about our data protection packages.
Unbenanntes Dokument

We are

familiar with the characteristics of small and large companies

experienced in communicating with data protection authorities

active in data protection for over 10 years.