Joint Control Addendum Template for England and Wales
Generate a bespoke document
What is a Joint Control Addendum?
The Joint Control Addendum is essential when two or more organizations jointly determine the purposes and means of processing personal data under UK GDPR and Data Protection Act 2018. This document should be implemented when organizations share decision-making authority over data processing activities, requiring clear allocation of responsibilities and compliance obligations. It serves as a mandatory requirement under Article 26 of the UK GDPR, ensuring transparency and proper accountability in joint control arrangements.
About the Joint Control Addendum
When your organisation processes personal data jointly with other entities, you need a Joint Control Addendum to comply with UK GDPR and Data Protection Act 2018 requirements. This legal document creates a binding framework that defines each party's responsibilities, ensures regulatory compliance, and protects data subjects' rights in joint processing arrangements.
When do you need this document?
You require a Joint Control Addendum whenever two or more organisations jointly determine the purposes and means of processing personal data. Common scenarios include marketing partnerships where companies share customer databases, research collaborations between universities and private companies, joint ventures processing employee or customer data, and technology partnerships where multiple parties access shared data platforms. The arrangement must involve shared decision-making rather than simple data sharing, where one party acts as a processor for another. If you're unsure whether your arrangement constitutes joint control, consider whether both parties have meaningful input into how and why personal data is processed.
Key legal considerations
The addendum must clearly allocate responsibilities between joint controllers for each aspect of GDPR compliance, including lawful basis determination, data subject rights fulfilment, breach notification procedures, and Data Protection Impact Assessment completion. You need to designate a single point of contact for data subjects, even though both parties remain jointly liable for compliance failures. The document should specify which controller handles specific obligations, such as responding to access requests or managing consent withdrawal. Consider including provisions for indemnification between parties, data sharing protocols, security standards, and procedures for handling regulatory investigations. Remember that joint controllers share liability, meaning each party can be held responsible for the entire arrangement's compliance failures.
Legal requirements in England and Wales
Under UK GDPR Article 26 and Data Protection Act 2018, joint controllers must have a written arrangement that transparently determines each party's responsibilities for GDPR compliance. This agreement must be available to data subjects upon request, requiring clear, accessible language rather than complex legal terminology. The ICO's Joint Controller Guidance emphasises that arrangements must reflect the actual decision-making relationship, not merely contractual convenience. You must ensure the addendum covers all processing activities within the joint control scope, including any subsequent data transfers or third-party involvement. The document should align with PECR 2003 requirements if electronic communications are involved. English courts will interpret joint controller obligations strictly, making precise responsibility allocation crucial for avoiding disputes and regulatory penalties.
GOVERNING LAW
Applicable law
This Joint Control Addendum is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it