Joint controller agreement for research collaborations (GDPR Article 26), with template
Multi-partner research projects often make universities joint controllers, and Article 26 GDPR then requires a written arrangement that says who does what. This guide explains how to tell joint control from processing and independent control, what the EDPB and the Court of Justice say, what the agreement must cover, and the mistakes that cause trouble later. A free Word template is included.
The short version
- Partners are joint controllers when they jointly determine the purposes and essential means of the processing. In research, jointly drafting the protocol is often enough, even if only one partner actually touches the data.
- Article 26 GDPR then requires an arrangement setting out who does what, in particular on information to participants and on data subject rights. The EDPB recommends a binding contract.
- Responsibility does not have to be equal, but every obligation must land with someone. Participants can still exercise their rights against any partner, and Article 82(4) makes each controller involved liable for the entire damage.
- Joint control usually covers only part of a project. Each partner remains a separate controller for what it does on its own, before and after the joint processing.
- Download the free joint controller agreement template for research (Word), with a responsibility matrix and an "essence of the arrangement" text for privacy notices.
Contents
1. What Article 26 says
Article 26 GDPR has three paragraphs, and each one matters for a research collaboration:
- Article 26(1) defines joint controllers as two or more controllers who "jointly determine the purposes and means of processing". They must determine their respective responsibilities "in a transparent manner", in particular for data subject rights and for the information duties in Articles 13 and 14, by means of an arrangement between them. Where EU or national law already allocates the responsibilities, the arrangement is not needed to that extent. The arrangement may designate a contact point for data subjects.
- Article 26(2) requires the arrangement to "duly reflect" the joint controllers' roles and relationships towards data subjects, and the essence of the arrangement must be made available to the data subject.
- Article 26(3) lets the data subject exercise his or her rights against each of the controllers, irrespective of the terms of the arrangement.
Two other provisions frame the risk. Article 82(4) says that where more than one controller is involved in the same processing and they are responsible for damage, each one is liable for the entire damage, so that the data subject is compensated. Article 82(5) then lets the controller that paid recover the share corresponding to the other controllers' part of the responsibility. A clear allocation in the agreement is what makes that recovery workable.
2. When research partners are joint controllers
The EDPB's Guidelines 07/2020 on the concepts of controller and processor treat joint control as a question of fact. Joint controllership exists where entities jointly determine the purposes and the means of the same processing, either through a common decision or through converging decisions that complement each other and without which the processing would not be possible. Three points from the guidelines matter most for research:
- Access to the data is not required. The fact that a party does not have access to the personal data is not sufficient to exclude joint controllership (paragraph 56).
- Joint control is limited to the operations decided together. If one party alone decides operations that come before or after the joint part of the chain, it is the sole controller for those operations (paragraph 57).
- A shared platform can create joint control. The guidelines give a research example: several institutes use the existing platform of one institute for a joint project, each feeding in data and using the others' data. All are joint controllers for the storage and disclosure through the platform, and each remains a separate controller for its own processing outside it.
The EDPB's Guidelines 1/2026 on processing of personal data for scientific research purposes, adopted on 15 April 2026 as a version for public consultation, apply this to research protocols. The EDPB says that active participation in determining a research protocol "would normally qualify" an entity as a controller (paragraph 134). If several parties jointly draft a protocol that determines the purposes and essential means, that "may suffice" for all of them to be joint controllers, even if only some of them carry out the research (paragraph 141). On the other hand, providing funding or being consulted on the protocol (for example as an expert or ethics committee) is not in itself enough (paragraph 134), and merely adopting a protocol drafted by others may point to a controller and processor relationship instead (paragraph 142).
Both sets of guidelines use clinical research as an example. In Guidelines 07/2020, a healthcare provider and a university that draft a trial protocol together may be joint controllers; if the investigator only accepts a protocol drafted by the sponsor, it should be considered a processor. In Guidelines 1/2026 (Example 25), all partners in a consortium with a jointly drafted protocol and a jointly governed federated database are joint controllers for the study and the database, while the hospitals remain separate controllers for patient care and a company that later runs its own follow-on project is an independent controller for it.
National authorities take the same line. The Swedish Authority for Privacy Protection (IMY) explains that in university research the university or university college is usually the controller, not the individual researcher, and that several organisations can be joint controllers when they decide purposes and means together. The EDPB's Guidelines 1/2026 also say individual researchers are generally not controllers but act under the authority of their institution (paragraph 137).
3. What the Court of Justice has said
Three judgments, all decided under the old Data Protection Directive, shaped the concept the EDPB now applies:
| Case | What the Court held | Why it matters for research |
|---|---|---|
| Wirtschaftsakademie, C-210/16, 5 June 2018 | The administrator of a Facebook fan page is a controller jointly with Facebook. The Court added that joint responsibility "does not necessarily imply equal responsibility" (paragraph 43). | Partners can carry very different shares of the work and still be joint controllers. The agreement should record who carries what. |
| Jehovan todistajat, C-25/17, 10 July 2018 | A religious community was a controller jointly with its members for data collected in door-to-door preaching that it organised, coordinated and encouraged, without needing access to the data or to have given written instructions. | A coordinating partner (a project lead or hub) can be a joint controller for data collected at other sites even if it never sees the raw data. |
| Fashion ID, C-40/17, 29 July 2019 | A website operator embedding a social plugin can be a controller jointly with the plugin provider, but only for the operations whose purposes and means it actually determines: the collection and disclosure of the data. | Joint control has edges. Define the jointly controlled operations precisely and say where each partner's own processing begins. |
4. Joint control, processing or separate controllers?
Getting the role right decides which document you need. The EDPB says that "not all kind of partnerships, cooperation or collaboration" imply joint controllership (Guidelines 07/2020, paragraph 69), and that a party that "does not pursue any purpose(s) of its own" and is merely paid for a service is a processor (paragraph 62).
| Situation | Likely role | Document |
|---|---|---|
| Two universities co-design a study, agree the protocol, data and methods, and analyse together | Joint controllers | Article 26 arrangement (joint controller agreement) |
| A university hires a survey company or transcription service that works only on its instructions | Controller and processor | Article 28 data processing agreement |
| A university gives an existing dataset to another institution that runs its own separate study | Separate (independent) controllers | Data sharing or data transfer agreement (see our data sharing agreement guide) |
| A funder finances the project and receives reports, but does not decide on the processing | Not a controller for the research data | Grant agreement terms; no Article 26 arrangement for that party |
The University of Groningen's research guidance draws the same lines: a joint controller agreement is "mandatory when you work together with another data controller" with common purposes and means, a processing agreement when a third party acts as processor, and a data transfer agreement when data goes to a third party for its own reuse. It also notes that researchers are normally not mandated to sign these agreements; the university signs.
Validemic's analysis In practice one project often needs all three. Partners are joint controllers for the shared study, each partner signs processing agreements with its own vendors (cloud storage, survey tools, transcription), and a later reuse by one partner for a different study is a separate controller disclosure. Drawing a simple data flow diagram with the roles marked on each arrow saves a lot of drafting time.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
5. What the agreement must cover
Article 26 names only two topics expressly: data subject rights and the information duties. The EDPB reads the words "in particular" as non-exhaustive and lists further obligations the partners should allocate (Guidelines 07/2020, paragraph 166). Together with the research-specific points in Guidelines 1/2026, a workable research agreement covers:
- Scope. The jointly controlled processing operations, the project and protocol they belong to, and what each party does on its own outside the agreement. The EDPB recommends including the subject matter, purposes, types of data and categories of data subjects (paragraph 175).
- Legal basis and Article 9 condition. Joint controllers "can generally rely on the same legal basis", although different bases are not precluded (Guidelines 1/2026, paragraph 143). For special category data, record the Article 9(2) condition and any national law relied on, for example research under Article 9(2)(j) with the safeguards required by Article 89(1).
- Ethics approval. Who applies and who holds the approval. IMY, for example, describes ethics approval under the Swedish Ethical Review Act as one possible safeguard for sensitive data in research.
- Information to participants. Which partner provides the Article 13 or 14 information and how the essence of the agreement is included.
- Data subject requests. Who handles which requests, a contact point, how fast partners forward requests and help each other. The EDPB warns that requiring participants to use only the designated contact point would be an "excessive burden".
- Security. The measures each partner applies under Article 32, including where data is stored and who may access it. The EDPB notes that partners using shared tools must both ensure security of the data in them.
- Breaches. Who notifies the supervisory authority and participants under Articles 33 and 34, and how quickly partners tell each other.
- DPIA. Whether one is needed, who leads it and how prior consultation under Article 36 is handled.
- Processors. On what conditions a partner may engage a processor. Guidelines 1/2026 say procurement should follow the conditions in the joint controller agreement (paragraph 145).
- Transfers outside the EEA. Whether any partner or processor is outside the EEA and which Chapter V tool is used. Our transfer mechanism tool and transfer impact assessment template help here.
- Purpose limitation and further use. The EDPB notes that joint control does not automatically allow the receiving partner to use the data for other purposes (Guidelines 07/2020, footnote 76). State what reuse, if any, is allowed.
- Pseudonymisation and key management. Who holds the key that links codes to identities, and the duty to help with requests concerning pseudonymised data (Guidelines 1/2026, paragraph 163).
- Retention, archiving and the end of the project. What happens to the data when the project ends, including national archiving rules for public universities.
- Supervisory authorities. How partners communicate with authorities. The EDPB stresses that authorities are not bound by the agreement (paragraph 191).
- Liability and changes. Internal allocation of liability within the limits of Article 82, how new partners join, and how the agreement is updated when the protocol changes.
The EDPB also recommends documenting why responsibilities were allocated as they were, as part of accountability (paragraph 168), and that the allocation be written "in a clear and plain language" (paragraph 174).
Published models exist. ERA-LEARN, the European platform for research partnerships, offers a model joint controller agreement (published 3 December 2021) for joint calls and European Partnerships, and Lund University publishes a joint data controller agreement template that sits alongside a primary research agreement. Use them for comparison; your own legal office will usually have a preferred version.
6. Telling participants: the essence of the arrangement
Article 26(2) does not define "essence". The EDPB recommends that it cover at least all the information in Articles 13 and 14, which partner is responsible for each element, and the contact point if one is designated (Guidelines 07/2020, paragraph 180). The partners decide how to make it available, for example in the participant information sheet or privacy notice, or on request to the contact point (paragraph 181).
Guidelines 1/2026 add that if responsibility differs between partners, this must be reflected in the agreement and "transparently communicated" to data subjects (paragraph 144). The template includes a short essence text you can adapt for the participant information sheet, and our guide on research participant privacy notices covers the rest of the notice.
7. Common mistakes
- Calling a partner a processor to avoid an Article 26 agreement. If the partner helped design the study, a processing agreement will not match the facts, and the EDPB says roles follow the facts, not the labels.
- Making every consortium member a joint controller of everything. Joint control covers the operations decided together. Partners' own analyses, publications and follow-on studies are usually separate.
- Leaving the information duty unassigned. When each site recruits its own participants, each site usually informs them, but the text must be the same and must include the essence of the agreement.
- No route for requests that arrive at the "wrong" partner. Article 26(3) lets participants choose. Set a forwarding deadline.
- Forgetting the vendors. Cloud storage, survey tools and transcription services used by one partner process data for the joint study. Agree conditions for them and check each partner's processing agreements.
- Ignoring transfers. A partner outside the EEA, or a vendor with non-EEA subprocessors or support access, raises Chapter V questions. The EDPB counts remote access from a third country as a transfer when its criteria are met.
- Signing at the wrong level. The controller is normally the institution, so the institution, not the principal investigator personally, should sign.
- No end-of-project plan. Decide in advance who keeps what, in which form (identifiable, pseudonymised or anonymised) and for how long.
8. The template
The joint controller agreement template for research collaborations is a Word document containing:
- Instructions and a short role check (joint controller, processor or separate controller).
- Clauses on scope, legal basis, information, data subject rights, security, breaches, DPIA, processors, transfers, further use, pseudonymisation, retention, supervisory authorities, liability, term and changes.
- Annex 1: description of the joint processing.
- Annex 2: a responsibility matrix covering each obligation, with a lead party and a supporting role.
- Annex 3: security measures per party.
- Annex 4: an "essence of the arrangement" text for participant information.
- Annex 5: contact points.
The template follows Article 26 GDPR and the EDPB guidance as read on 7 October 2026. EDPB Guidelines 1/2026 were a version for public consultation on that date and may change when finalised. National law may add requirements, for example on ethics review or archiving. The template is not legal advice: have it reviewed by your legal office or data protection officer.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 4, 9, 13, 14, 26, 28, 32 to 36, 82 and 89, Official Journal text (retrieved 7 October 2026).
- EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, Part I section 3 and Part II section 2 (retrieved 7 October 2026).
- EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes, version for public consultation adopted 15 April 2026, section 7 (retrieved 7 October 2026).
- CJEU, C-210/16, Wirtschaftsakademie Schleswig-Holstein, judgment of 5 June 2018 (retrieved 7 October 2026).
- CJEU, C-25/17, Tietosuojavaltuutettu v Jehovan todistajat, judgment of 10 July 2018 (retrieved 7 October 2026).
- CJEU, C-40/17, Fashion ID, judgment of 29 July 2019 (retrieved 7 October 2026).
- IMY (Swedish Authority for Privacy Protection): Forskning (retrieved 7 October 2026).
- University of Groningen Digital Competence Centre: Protocols and agreements (retrieved 7 October 2026).
- ERA-LEARN: IPR and GDPR, including the Model Joint Controller Agreement (retrieved 7 October 2026).
- Lund University: Joint Data Controller Agreement template (2022-02-28) (retrieved 7 October 2026).
- EDPB Guidelines 05/2021 on the interplay between Article 3 and Chapter V, version 2.0 (retrieved 7 October 2026).
About this page
Sources checked on 7 October 2026. The GDPR and the three judgments were read in their Official Journal and Court versions, and the EDPB guidelines in the PDFs published on the EDPB website. University examples come from the institutions' own published pages. The tables and statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error, or guidance cited here has been updated, please contact us and we will correct it.
Frequently asked questions
Is a joint controller agreement mandatory?
Article 26(1) GDPR requires joint controllers to determine their respective responsibilities by means of an arrangement between them, unless EU or national law already does so. The GDPR does not prescribe the form, but the EDPB recommends a binding document such as a contract.
Are all partners in a research consortium joint controllers?
Not automatically. The EDPB says joint control requires participation in determining the purposes and essential means. Jointly drafting the research protocol may be enough; merely funding a project, being consulted or adopting a protocol drafted by others is not in itself sufficient.
Do joint controllers need equal responsibility?
No. The Court of Justice held in Wirtschaftsakademie (C-210/16) that joint responsibility does not necessarily imply equal responsibility. Partners may be involved at different stages and to different degrees, and the agreement should reflect that.
What must research participants be told?
Article 26(2) requires the essence of the arrangement to be made available to data subjects. The EDPB recommends that it cover at least the Article 13 and 14 information, which partner is responsible for each element, and the contact point if one is designated.
Can a participant ignore the contact point we agreed?
Yes. Under Article 26(3), data subjects may exercise their rights against each joint controller, whatever the agreement says. The agreement should therefore say how partners forward and handle requests received by any of them.
Is a joint controller agreement the same as a consortium agreement?
No. A consortium or collaboration agreement covers the project as a whole (funding, IP, publication). The Article 26 arrangement covers data protection responsibilities. Many institutions attach the joint controller agreement to the consortium agreement as a separate document.