Guide and template

Joint controller agreement for research collaborations (GDPR Article 26), with template

Multi-partner research projects often make universities joint controllers, and Article 26 GDPR then requires a written arrangement that says who does what. This guide explains how to tell joint control from processing and independent control, what the EDPB and the Court of Justice say, what the agreement must cover, and the mistakes that cause trouble later. A free Word template is included.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. What Article 26 says
  2. When research partners are joint controllers
  3. What the Court of Justice has said
  4. Joint control, processing or separate controllers?
  5. What the agreement must cover
  6. Telling participants: the essence of the arrangement
  7. Common mistakes
  8. The template
  9. Sources
  10. About this page

1. What Article 26 says

Article 26 GDPR has three paragraphs, and each one matters for a research collaboration:

Two other provisions frame the risk. Article 82(4) says that where more than one controller is involved in the same processing and they are responsible for damage, each one is liable for the entire damage, so that the data subject is compensated. Article 82(5) then lets the controller that paid recover the share corresponding to the other controllers' part of the responsibility. A clear allocation in the agreement is what makes that recovery workable.

2. When research partners are joint controllers

The EDPB's Guidelines 07/2020 on the concepts of controller and processor treat joint control as a question of fact. Joint controllership exists where entities jointly determine the purposes and the means of the same processing, either through a common decision or through converging decisions that complement each other and without which the processing would not be possible. Three points from the guidelines matter most for research:

The EDPB's Guidelines 1/2026 on processing of personal data for scientific research purposes, adopted on 15 April 2026 as a version for public consultation, apply this to research protocols. The EDPB says that active participation in determining a research protocol "would normally qualify" an entity as a controller (paragraph 134). If several parties jointly draft a protocol that determines the purposes and essential means, that "may suffice" for all of them to be joint controllers, even if only some of them carry out the research (paragraph 141). On the other hand, providing funding or being consulted on the protocol (for example as an expert or ethics committee) is not in itself enough (paragraph 134), and merely adopting a protocol drafted by others may point to a controller and processor relationship instead (paragraph 142).

Both sets of guidelines use clinical research as an example. In Guidelines 07/2020, a healthcare provider and a university that draft a trial protocol together may be joint controllers; if the investigator only accepts a protocol drafted by the sponsor, it should be considered a processor. In Guidelines 1/2026 (Example 25), all partners in a consortium with a jointly drafted protocol and a jointly governed federated database are joint controllers for the study and the database, while the hospitals remain separate controllers for patient care and a company that later runs its own follow-on project is an independent controller for it.

National authorities take the same line. The Swedish Authority for Privacy Protection (IMY) explains that in university research the university or university college is usually the controller, not the individual researcher, and that several organisations can be joint controllers when they decide purposes and means together. The EDPB's Guidelines 1/2026 also say individual researchers are generally not controllers but act under the authority of their institution (paragraph 137).

3. What the Court of Justice has said

Three judgments, all decided under the old Data Protection Directive, shaped the concept the EDPB now applies:

CaseWhat the Court heldWhy it matters for research
Wirtschaftsakademie, C-210/16, 5 June 2018The administrator of a Facebook fan page is a controller jointly with Facebook. The Court added that joint responsibility "does not necessarily imply equal responsibility" (paragraph 43).Partners can carry very different shares of the work and still be joint controllers. The agreement should record who carries what.
Jehovan todistajat, C-25/17, 10 July 2018A religious community was a controller jointly with its members for data collected in door-to-door preaching that it organised, coordinated and encouraged, without needing access to the data or to have given written instructions.A coordinating partner (a project lead or hub) can be a joint controller for data collected at other sites even if it never sees the raw data.
Fashion ID, C-40/17, 29 July 2019A website operator embedding a social plugin can be a controller jointly with the plugin provider, but only for the operations whose purposes and means it actually determines: the collection and disclosure of the data.Joint control has edges. Define the jointly controlled operations precisely and say where each partner's own processing begins.

4. Joint control, processing or separate controllers?

Getting the role right decides which document you need. The EDPB says that "not all kind of partnerships, cooperation or collaboration" imply joint controllership (Guidelines 07/2020, paragraph 69), and that a party that "does not pursue any purpose(s) of its own" and is merely paid for a service is a processor (paragraph 62).

SituationLikely roleDocument
Two universities co-design a study, agree the protocol, data and methods, and analyse togetherJoint controllersArticle 26 arrangement (joint controller agreement)
A university hires a survey company or transcription service that works only on its instructionsController and processorArticle 28 data processing agreement
A university gives an existing dataset to another institution that runs its own separate studySeparate (independent) controllersData sharing or data transfer agreement (see our data sharing agreement guide)
A funder finances the project and receives reports, but does not decide on the processingNot a controller for the research dataGrant agreement terms; no Article 26 arrangement for that party

The University of Groningen's research guidance draws the same lines: a joint controller agreement is "mandatory when you work together with another data controller" with common purposes and means, a processing agreement when a third party acts as processor, and a data transfer agreement when data goes to a third party for its own reuse. It also notes that researchers are normally not mandated to sign these agreements; the university signs.

Validemic's analysis In practice one project often needs all three. Partners are joint controllers for the shared study, each partner signs processing agreements with its own vendors (cloud storage, survey tools, transcription), and a later reuse by one partner for a different study is a separate controller disclosure. Drawing a simple data flow diagram with the roles marked on each arrow saves a lot of drafting time.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

5. What the agreement must cover

Article 26 names only two topics expressly: data subject rights and the information duties. The EDPB reads the words "in particular" as non-exhaustive and lists further obligations the partners should allocate (Guidelines 07/2020, paragraph 166). Together with the research-specific points in Guidelines 1/2026, a workable research agreement covers:

  1. Scope. The jointly controlled processing operations, the project and protocol they belong to, and what each party does on its own outside the agreement. The EDPB recommends including the subject matter, purposes, types of data and categories of data subjects (paragraph 175).
  2. Legal basis and Article 9 condition. Joint controllers "can generally rely on the same legal basis", although different bases are not precluded (Guidelines 1/2026, paragraph 143). For special category data, record the Article 9(2) condition and any national law relied on, for example research under Article 9(2)(j) with the safeguards required by Article 89(1).
  3. Ethics approval. Who applies and who holds the approval. IMY, for example, describes ethics approval under the Swedish Ethical Review Act as one possible safeguard for sensitive data in research.
  4. Information to participants. Which partner provides the Article 13 or 14 information and how the essence of the agreement is included.
  5. Data subject requests. Who handles which requests, a contact point, how fast partners forward requests and help each other. The EDPB warns that requiring participants to use only the designated contact point would be an "excessive burden".
  6. Security. The measures each partner applies under Article 32, including where data is stored and who may access it. The EDPB notes that partners using shared tools must both ensure security of the data in them.
  7. Breaches. Who notifies the supervisory authority and participants under Articles 33 and 34, and how quickly partners tell each other.
  8. DPIA. Whether one is needed, who leads it and how prior consultation under Article 36 is handled.
  9. Processors. On what conditions a partner may engage a processor. Guidelines 1/2026 say procurement should follow the conditions in the joint controller agreement (paragraph 145).
  10. Transfers outside the EEA. Whether any partner or processor is outside the EEA and which Chapter V tool is used. Our transfer mechanism tool and transfer impact assessment template help here.
  11. Purpose limitation and further use. The EDPB notes that joint control does not automatically allow the receiving partner to use the data for other purposes (Guidelines 07/2020, footnote 76). State what reuse, if any, is allowed.
  12. Pseudonymisation and key management. Who holds the key that links codes to identities, and the duty to help with requests concerning pseudonymised data (Guidelines 1/2026, paragraph 163).
  13. Retention, archiving and the end of the project. What happens to the data when the project ends, including national archiving rules for public universities.
  14. Supervisory authorities. How partners communicate with authorities. The EDPB stresses that authorities are not bound by the agreement (paragraph 191).
  15. Liability and changes. Internal allocation of liability within the limits of Article 82, how new partners join, and how the agreement is updated when the protocol changes.

The EDPB also recommends documenting why responsibilities were allocated as they were, as part of accountability (paragraph 168), and that the allocation be written "in a clear and plain language" (paragraph 174).

Published models exist. ERA-LEARN, the European platform for research partnerships, offers a model joint controller agreement (published 3 December 2021) for joint calls and European Partnerships, and Lund University publishes a joint data controller agreement template that sits alongside a primary research agreement. Use them for comparison; your own legal office will usually have a preferred version.

6. Telling participants: the essence of the arrangement

Article 26(2) does not define "essence". The EDPB recommends that it cover at least all the information in Articles 13 and 14, which partner is responsible for each element, and the contact point if one is designated (Guidelines 07/2020, paragraph 180). The partners decide how to make it available, for example in the participant information sheet or privacy notice, or on request to the contact point (paragraph 181).

Guidelines 1/2026 add that if responsibility differs between partners, this must be reflected in the agreement and "transparently communicated" to data subjects (paragraph 144). The template includes a short essence text you can adapt for the participant information sheet, and our guide on research participant privacy notices covers the rest of the notice.

7. Common mistakes

  1. Calling a partner a processor to avoid an Article 26 agreement. If the partner helped design the study, a processing agreement will not match the facts, and the EDPB says roles follow the facts, not the labels.
  2. Making every consortium member a joint controller of everything. Joint control covers the operations decided together. Partners' own analyses, publications and follow-on studies are usually separate.
  3. Leaving the information duty unassigned. When each site recruits its own participants, each site usually informs them, but the text must be the same and must include the essence of the agreement.
  4. No route for requests that arrive at the "wrong" partner. Article 26(3) lets participants choose. Set a forwarding deadline.
  5. Forgetting the vendors. Cloud storage, survey tools and transcription services used by one partner process data for the joint study. Agree conditions for them and check each partner's processing agreements.
  6. Ignoring transfers. A partner outside the EEA, or a vendor with non-EEA subprocessors or support access, raises Chapter V questions. The EDPB counts remote access from a third country as a transfer when its criteria are met.
  7. Signing at the wrong level. The controller is normally the institution, so the institution, not the principal investigator personally, should sign.
  8. No end-of-project plan. Decide in advance who keeps what, in which form (identifiable, pseudonymised or anonymised) and for how long.

8. The template

The joint controller agreement template for research collaborations is a Word document containing:

The template follows Article 26 GDPR and the EDPB guidance as read on 7 October 2026. EDPB Guidelines 1/2026 were a version for public consultation on that date and may change when finalised. National law may add requirements, for example on ethics review or archiving. The template is not legal advice: have it reviewed by your legal office or data protection officer.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Articles 4, 9, 13, 14, 26, 28, 32 to 36, 82 and 89, Official Journal text (retrieved 7 October 2026).
  2. EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, Part I section 3 and Part II section 2 (retrieved 7 October 2026).
  3. EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, version for public consultation adopted 15 April 2026, section 7 (retrieved 7 October 2026).
  4. CJEU, C-210/16, Wirtschaftsakademie Schleswig-Holstein, judgment of 5 June 2018 (retrieved 7 October 2026).
  5. CJEU, C-25/17, Tietosuojavaltuutettu v Jehovan todistajat, judgment of 10 July 2018 (retrieved 7 October 2026).
  6. CJEU, C-40/17, Fashion ID, judgment of 29 July 2019 (retrieved 7 October 2026).
  7. IMY (Swedish Authority for Privacy Protection): Forskning (retrieved 7 October 2026).
  8. University of Groningen Digital Competence Centre: Protocols and agreements (retrieved 7 October 2026).
  9. ERA-LEARN: IPR and GDPR, including the Model Joint Controller Agreement (retrieved 7 October 2026).
  10. Lund University: Joint Data Controller Agreement template (2022-02-28) (retrieved 7 October 2026).
  11. EDPB Guidelines 05/2021 on the interplay between Article 3 and Chapter V, version 2.0 (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. The GDPR and the three judgments were read in their Official Journal and Court versions, and the EDPB guidelines in the PDFs published on the EDPB website. University examples come from the institutions' own published pages. The tables and statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error, or guidance cited here has been updated, please contact us and we will correct it.

Frequently asked questions

Is a joint controller agreement mandatory?

Article 26(1) GDPR requires joint controllers to determine their respective responsibilities by means of an arrangement between them, unless EU or national law already does so. The GDPR does not prescribe the form, but the EDPB recommends a binding document such as a contract.

Are all partners in a research consortium joint controllers?

Not automatically. The EDPB says joint control requires participation in determining the purposes and essential means. Jointly drafting the research protocol may be enough; merely funding a project, being consulted or adopting a protocol drafted by others is not in itself sufficient.

Do joint controllers need equal responsibility?

No. The Court of Justice held in Wirtschaftsakademie (C-210/16) that joint responsibility does not necessarily imply equal responsibility. Partners may be involved at different stages and to different degrees, and the agreement should reflect that.

What must research participants be told?

Article 26(2) requires the essence of the arrangement to be made available to data subjects. The EDPB recommends that it cover at least the Article 13 and 14 information, which partner is responsible for each element, and the contact point if one is designated.

Can a participant ignore the contact point we agreed?

Yes. Under Article 26(3), data subjects may exercise their rights against each joint controller, whatever the agreement says. The agreement should therefore say how partners forward and handle requests received by any of them.

Is a joint controller agreement the same as a consortium agreement?

No. A consortium or collaboration agreement covers the project as a whole (funding, IP, publication). The Article 26 arrangement covers data protection responsibilities. Many institutions attach the joint controller agreement to the consortium agreement as a separate document.