Joint Controller Agreement Template for Germany
Generate a bespoke document
What is a Joint Controller Agreement?
The Joint Controller Agreement is essential when multiple organizations jointly determine how personal data is processed, as required by Article 26 of the GDPR and German data protection law. This document becomes necessary in scenarios such as shared platforms, joint ventures, collaborative research projects, or any situation where multiple entities have decisive influence over data processing purposes and means. The agreement must comply with both EU-level requirements and specific German legal provisions, including the Federal Data Protection Act (BDSG). It outlines the respective responsibilities of each controller, establishes procedures for ensuring data subject rights, defines security measures, and creates clear protocols for incident response and regulatory compliance. The document is particularly crucial in the German legal context, where data protection requirements are strictly enforced and supervisory authorities maintain high compliance standards.
About the Joint Controller Agreement
A Joint Controller Agreement is a legally binding document that governs the relationship between multiple organizations when they jointly determine the purposes and means of personal data processing. Under German law, this agreement is not optional but a mandatory requirement under Article 26 of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). You need this document whenever your organization shares control over data processing decisions with other entities, ensuring clear accountability and regulatory compliance in Germany's stringent data protection landscape.
When do you need this document?
You require a Joint Controller Agreement when your organization collaborates with other entities in ways that involve shared decision-making over personal data processing. Common scenarios include joint ventures where companies pool customer data for shared services, collaborative research projects between universities and corporations, shared technology platforms where multiple companies access the same user data, and marketing partnerships where organizations jointly process customer information. The agreement becomes essential when multiple parties have meaningful input into how personal data is collected, used, or shared, rather than one organization simply processing data on behalf of another.
Key legal considerations
Your Joint Controller Agreement must clearly define each party's specific responsibilities and liabilities under data protection law. The document should establish who handles data subject requests, manages security breaches, conducts data protection impact assessments, and maintains records of processing activities. You must ensure the agreement covers data retention periods, cross-border data transfers, and procedures for when the joint processing relationship ends. The contract should also specify how costs and liabilities are shared between controllers, particularly regarding potential regulatory fines and compensation claims. Clear communication protocols and decision-making procedures are essential to prevent conflicts and ensure swift responses to data protection issues.
Legal requirements in Germany
Under German law, your Joint Controller Agreement must comply with both European and national data protection requirements. The GDPR's Article 26 mandates that the agreement must be transparent and accurately reflect each controller's responsibilities toward data subjects. The Federal Data Protection Act (BDSG) adds specific German requirements, particularly regarding employee data protection and the role of data protection officers. You must ensure the agreement addresses the Telecommunications Telemedia Data Protection Act (TTDSG) if your joint processing involves electronic communications or online services. German supervisory authorities require that the agreement enables data subjects to exercise their rights effectively against either controller. The document must also comply with German contract law principles under the Civil Code (BGB), ensuring proper formation, validity, and enforceability of the contractual obligations between the joint controllers.
GOVERNING LAW
Applicable law
This Joint Controller Agreement is drafted to comply with Germany law. Key legislation includes:
Federal Data Protection Act (BDSG): German Federal Data Protection Act (Bundesdatenschutzgesetz) - The national law implementing and supplementing the GDPR in Germany
German Civil Code (BGB): Bürgerliches Gesetzbuch - Provides the legal framework for contracts and obligations under German law, particularly sections dealing with contract formation and validity
Telecommunications Telemedia Data Protection Act (TTDSG): Telekommunikation-Telemedien-Datenschutz-Gesetz - Regulates data protection in telecommunications and electronic media services
State Data Protection Laws: Various German state (Länder) data protection laws that might apply depending on the location and scope of data processing activities
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it