黑料视频

Joint Controller Agreement Template for Germany

A Joint Controller Agreement governed by German law is a legally binding document that establishes the framework for shared data protection responsibilities between two or more controllers who jointly determine the purposes and means of processing personal data. The agreement complies with Article 26 of the GDPR and the German Federal Data Protection Act (BDSG), defining each party's obligations regarding data subject rights, transparency requirements, security measures, and breach notifications. It includes specific provisions required under German law and addresses the allocation of responsibilities and liabilities between the controllers.

Typically:
i
This cost is based on prices provided by
6 legal services in your market.
With GenieAI:
拢0
i
Generate and export your first
document completely free.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Get template free

Your data doesn't train Genie's AI

You keep IP ownership聽of your docs

4.6 / 5
4.6 / 5
4.8 / 5
Alternatively...

What is a Joint Controller Agreement?

The Joint Controller Agreement is essential when multiple organizations jointly determine how personal data is processed, as required by Article 26 of the GDPR and German data protection law. This document becomes necessary in scenarios such as shared platforms, joint ventures, collaborative research projects, or any situation where multiple entities have decisive influence over data processing purposes and means. The agreement must comply with both EU-level requirements and specific German legal provisions, including the Federal Data Protection Act (BDSG). It outlines the respective responsibilities of each controller, establishes procedures for ensuring data subject rights, defines security measures, and creates clear protocols for incident response and regulatory compliance. The document is particularly crucial in the German legal context, where data protection requirements are strictly enforced and supervisory authorities maintain high compliance standards.

What sections should be included in a Joint Controller Agreement?

1. Parties: Identification of the joint controllers entering into the agreement

2. Background: Context of the joint processing activities and relationship between the parties

3. Definitions: Key terms used in the agreement, including GDPR-specific terminology

4. Scope and Purpose: Definition of the joint processing activities covered by the agreement

5. Roles and Responsibilities: Division of data protection responsibilities between the joint controllers

6. Data Subject Rights: Procedures for handling data subject requests and designated contact points

7. Transparency: Requirements for informing data subjects about the arrangement between controllers

8. Security Measures: Technical and organizational measures required for data protection

9. Data Breach Notification: Procedures for handling and reporting personal data breaches

10. Cooperation with Supervisory Authorities: Process for responding to regulatory inquiries and investigations

11. Liability and Indemnification: Allocation of liability between controllers and indemnification provisions

12. Term and Termination: Duration of the agreement and termination provisions

13. Governing Law and Jurisdiction: Specification of German law as governing law and jurisdiction

What sections are optional to include in a Joint Controller Agreement?

1. International Data Transfers: Required when personal data is transferred outside the EEA

2. Sub-processing: Include when either controller may engage sub-processors

3. Industry-Specific Compliance: Required for regulated industries like healthcare or finance

4. Joint Marketing Activities: Include when controllers collaborate on marketing initiatives

5. Audit Rights: Optional provisions for mutual auditing of compliance

6. Insurance Requirements: Specific insurance obligations for high-risk processing

7. Cost Allocation: Include when there are shared costs for compliance measures

8. Data Retention: Specific retention periods and deletion procedures if not covered in main sections

What schedules should be included in a Joint Controller Agreement?

1. Schedule 1 - Processing Activities: Detailed description of joint processing activities, including categories of data and purposes

2. Schedule 2 - Technical and Organizational Measures: Detailed security measures implemented by each controller

3. Schedule 3 - Data Subject Rights Procedure: Detailed procedures for handling data subject requests

4. Schedule 4 - Data Breach Response Plan: Detailed protocol for responding to data breaches

5. Schedule 5 - Contact Points: List of key contacts for each controller for various purposes

6. Appendix A - Standard Forms: Templates for data subject requests, breach notifications, and other standard communications

7. Appendix B - Information Notice: Template for informing data subjects about the joint controller arrangement

Authors

Alex Denne

Head of Growth (Open Source Law) @ 黑料视频 | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents

Jurisdiction

Germany

Publisher

黑料视频

Cost

Free to use

Find the document you need

Data Processing Contract

A German law-governed agreement establishing terms for GDPR-compliant personal data processing between controller and processor.

Download

Controller To Controller Agreement

A German law-governed agreement establishing joint processing arrangements between two or more data controllers under GDPR and BDSG requirements.

Download

Joint Controller Agreement

A German law-governed agreement establishing shared data protection responsibilities between joint controllers under GDPR Article 26 and BDSG requirements.

Download

Standard Data Processing Agreement

A German law-governed Data Processing Agreement ensuring GDPR compliance for personal data processing between controller and processor.

Download

Data Processing Addendum

A German law-compliant Data Processing Addendum that establishes terms for personal data processing under GDPR and BDSG requirements.

Download

Intra Group Data Transfer Agreement

German law-governed agreement regulating personal data transfers between group companies, ensuring GDPR and BDSG compliance.

Download

Intercompany Data Processing Agreement

German law-governed data processing agreement between group companies, compliant with GDPR and BDSG requirements.

Download

Data Transfer Addendum

German law-governed Data Transfer Addendum ensuring GDPR compliance and German BDSG requirements for secure personal data transfers between organizations.

Download

Personal Data Transfer Agreement

A German law-governed agreement for compliant transfer of personal data between parties, ensuring GDPR and BDSG compliance.

Download
See more related templates

骋别苍颈别鈥檚 Security Promise

Genie is the safest place to draft. Here鈥檚 how we prioritise your privacy and security.

Your data is private:

We do not train on your data; 骋别苍颈别鈥檚 AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it