Joint Controller Agreement Template for Germany

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Agreement?

The Joint Controller Agreement is essential when multiple organizations jointly determine how personal data is processed, as required by Article 26 of the GDPR and German data protection law. This document becomes necessary in scenarios such as shared platforms, joint ventures, collaborative research projects, or any situation where multiple entities have decisive influence over data processing purposes and means. The agreement must comply with both EU-level requirements and specific German legal provisions, including the Federal Data Protection Act (BDSG). It outlines the respective responsibilities of each controller, establishes procedures for ensuring data subject rights, defines security measures, and creates clear protocols for incident response and regulatory compliance. The document is particularly crucial in the German legal context, where data protection requirements are strictly enforced and supervisory authorities maintain high compliance standards.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Germany

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Agreement

A Joint Controller Agreement is a legally binding document that governs the relationship between multiple organizations when they jointly determine the purposes and means of personal data processing. Under German law, this agreement is not optional but a mandatory requirement under Article 26 of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). You need this document whenever your organization shares control over data processing decisions with other entities, ensuring clear accountability and regulatory compliance in Germany's stringent data protection landscape.

When do you need this document?

You require a Joint Controller Agreement when your organization collaborates with other entities in ways that involve shared decision-making over personal data processing. Common scenarios include joint ventures where companies pool customer data for shared services, collaborative research projects between universities and corporations, shared technology platforms where multiple companies access the same user data, and marketing partnerships where organizations jointly process customer information. The agreement becomes essential when multiple parties have meaningful input into how personal data is collected, used, or shared, rather than one organization simply processing data on behalf of another.

Key legal considerations

Your Joint Controller Agreement must clearly define each party's specific responsibilities and liabilities under data protection law. The document should establish who handles data subject requests, manages security breaches, conducts data protection impact assessments, and maintains records of processing activities. You must ensure the agreement covers data retention periods, cross-border data transfers, and procedures for when the joint processing relationship ends. The contract should also specify how costs and liabilities are shared between controllers, particularly regarding potential regulatory fines and compensation claims. Clear communication protocols and decision-making procedures are essential to prevent conflicts and ensure swift responses to data protection issues.

Legal requirements in Germany

Under German law, your Joint Controller Agreement must comply with both European and national data protection requirements. The GDPR's Article 26 mandates that the agreement must be transparent and accurately reflect each controller's responsibilities toward data subjects. The Federal Data Protection Act (BDSG) adds specific German requirements, particularly regarding employee data protection and the role of data protection officers. You must ensure the agreement addresses the Telecommunications Telemedia Data Protection Act (TTDSG) if your joint processing involves electronic communications or online services. German supervisory authorities require that the agreement enables data subjects to exercise their rights effectively against either controller. The document must also comply with German contract law principles under the Civil Code (BGB), ensuring proper formation, validity, and enforceability of the contractual obligations between the joint controllers.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it