Establishment of Transparent Joint Controller Arrangements, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 26(1).

Assessment Step

1
Establishment of Transparent Joint Controller Arrangements (EstablishmentofTransparentJointControllerArrangements)
Where the entity jointly determines the purposes and means of processing with one or more other controllers, does it establish a transparent arrangement that defines each controller's responsibilities for GDPR compliance, including the exercise of data subject rights and information duties, and does the arrangement reflect the roles and relationships of the joint controllers?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Establishment of Transparent Joint Controller Arrangements
Where two or more controllers jointly determine the purposes and means of processing, they must determine their respective responsibilities for compliance with GDPR obligations in a transparent manner by means of an arrangement. This arrangement must address the exercise of the data subject's rights and the controllers' respective duties to provide information, and must duly reflect the respective roles and relationships of the joint controllers.
Citation
GDPR
Art. 26(1), Recital 79