Joint Controller Data Processing Agreement Template for Germany

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Controller Data Processing Agreement?

A Joint Controller Data Processing Agreement is required when two or more organizations jointly determine the purposes and means of processing personal data under German law and GDPR. This document is essential for compliance with Article 26 GDPR and the German Federal Data Protection Act (BDSG), particularly in scenarios such as shared platforms, joint ventures, or collaborative projects involving personal data processing. The agreement must clearly delineate each controller's responsibilities for ensuring GDPR compliance, handling data subject requests, implementing security measures, and managing breach notifications. It should reflect the specific arrangements between the parties while ensuring transparency towards data subjects about their respective roles and responsibilities.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Germany

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Controller Data Processing Agreement

When two or more organizations work together to process personal data, you need a Joint Controller Data Processing Agreement to comply with German data protection laws. This legal document is essential under GDPR Article 26 and the German Federal Data Protection Act (BDSG), ensuring that all parties understand their responsibilities and obligations when jointly determining the purposes and means of data processing.

When do you need this document?

You must establish a joint controller agreement whenever your organization shares control over personal data processing with another entity. Common scenarios include joint marketing campaigns where companies share customer databases, collaborative research projects involving participant data, shared customer service platforms, and business partnerships where both parties access and use the same personal data for their respective purposes. The agreement is also required for merger and acquisition activities during due diligence processes, joint venture operations, and any situation where multiple organizations make decisions about what personal data to collect, how to use it, and how long to retain it.

Key legal considerations

Your joint controller agreement must clearly define each party's specific responsibilities and liabilities under GDPR. Critical elements include designating which controller handles data subject requests, establishing procedures for breach notifications, defining security standards and technical measures, and outlining data retention and deletion schedules. The agreement should specify how you'll handle data subject rights such as access, rectification, and erasure requests, including which controller serves as the primary contact point. You must also address liability allocation for potential GDPR violations, ensuring that data subjects can exercise their rights against either controller regardless of internal arrangements. Consider including provisions for regular compliance audits, staff training requirements, and procedures for updating the agreement when processing activities change.

Legal requirements in Germany

German law under the BDSG requires additional considerations beyond standard GDPR compliance. You must ensure the agreement complies with German contract law principles under the Bürgerliches Gesetzbuch (BGB), particularly regarding contract formation and performance obligations. If your joint processing involves online services or electronic communications, you may need to address requirements under the Telemediengesetz (TMG). The agreement must be transparent and accessible to data subjects, with clear information about how they can contact either controller. German supervisory authorities expect detailed documentation of your joint processing arrangements, including risk assessments and impact analyses where required. Consider appointing a joint Data Protection Officer if your processing activities meet the threshold requirements, and ensure your agreement addresses cross-border data transfers if one controller is located outside the EU, potentially requiring Standard Contractual Clauses or other appropriate safeguards.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it