Meaning
Legal principle establishing that multiple organizations determining the purposes and means of processing personal information are collectively responsible for any violations of the law. Joint controller liability is a key feature of the Personal Information Protection Law, ensuring that individuals can seek a remedy from any of the parties involved in the processing of their data. This prevents companies from avoiding accountability by shifting the blame to their partners or service providers in a complex data ecosystem.
When two or more entities decide together why and how data is handled, they are considered joint controllers and must have a formal agreement defining their respective roles. This rule applies regardless of whether the entities are in the same corporate group or are independent business partners. The boundary of this liability is reached when one party acts entirely outside the scope of the joint instructions provided by the group.
Liability Allocation
Statutory rules dictate that joint controllers are jointly and severally liable for any harm caused to a data subject by their processing activities. Joint controller liability means that an individual can sue any one of the controllers for the full amount of the damages, and that controller then has the right to seek contribution from the other parties based on their share of the fault. This approach prioritizes the compensation of the victim and places the burden of internal allocation on the companies themselves.
To manage this risk, organizations must include detailed indemnity and contribution clauses in their partnership agreements. These contracts should clearly outline which party is responsible for specific tasks such as obtaining consent, providing access, and ensuring data security. Without a clear agreement, the state authorities will treat all parties as equally responsible for any failure.
Compliance Obligation
Administrative requirements for joint controllers include a shared duty to implement the necessary technical and organizational measures to protect the data. Joint controller liability extends to the failure of any one party to maintain the security of the shared dataset, such as a leak caused by a weak password policy at one of the partners. All controllers must ensure that the data is processed according to the agreed purposes and that any third-party transfers are properly authorized.
They are also collectively responsible for responding to requests from the data subjects and for notifying the authorities in the event of a breach. This requires a high level of coordination and a shared governance framework that is reviewed and tested regularly. The use of a central compliance office or a joint data protection officer is a common way to manage these shared responsibilities.
Contractual Indemnity
Operational strategy for mitigating the risks of joint processing involves the use of strong legal protections in the commercial agreement. Joint controller liability is often managed through a master services agreement that specifies the insurance requirements and the financial limits of liability between the parties. Each controller should perform a thorough security audit of the other before entering into the relationship to ensure that their partner’s systems are up to the required standard.
The agreement should also include provisions for the termination of the partnership and the safe return or destruction of the shared data. If one party is found to be grossly negligent, the indemnity clause should allow the other parties to recover all their losses, including legal fees and administrative fines. This legal structure creates a strong incentive for all parties to maintain a high level of compliance.
It ensures that the collective responsibility translates into individual vigilance.