GDPR Certification Topic

Joint Controllers Under GDPR Article 26: The Facebook Fan Page Ruling

Updated: 08/2026 • Evidence-based on Article 26 GDPR and CJEU Case C-210/16
A business may be a joint controller when it configures and benefits from a platform’s processing of visitor data, even if the platform performs the underlying collection and the business receives only anonymised statistics. The Court of Justice of the EU established this in the landmark Facebook fan page ruling, and it remains the leading authority for applying GDPR Article 26 to configurable third-party analytics tools.

Key Facts

Primary Law:
Article 26 GDPR
Leading Case:
CJEU Case C-210/16 (5 June 2018)
Core Lesson:
Using a third-party platform does not exempt a business from its own controller duties

What does it mean to be a joint controller under Article 26 GDPR?

Article 26 applies where two or more controllers jointly determine the purposes and means of processing. The central question is therefore functional: who participates in deciding why personal data is processed and how that processing is carried out?

Joint controllership does not depend solely on contractual labels. Calling one organisation a service provider, platform or processor does not answer the Article 26 question. The organisations’ actual roles in determining the purposes and means must be examined.

The Facebook fan page ruling illustrates how broad that functional examination can be. Facebook Ireland primarily determined the purposes and means of the processing performed through Facebook. Nevertheless, the fan page administrator was also treated as a controller because it participated in that determination through its choice of parameters, target audience and objectives for managing or promoting its activities.

The administrator did not have to perform the cookie-based collection itself, nor did it need to receive identifiable visitor records. Its ability to request particular categories of audience statistics meant that it participated in the processing operation behind those statistics.

For exam purposes, separate two questions. First, does an organisation participate in determining purposes and means? If so, it may be a joint controller. Second, how must the resulting GDPR responsibilities be allocated? That second question is governed by the Article 26 arrangement, but the arrangement does not itself create or remove the underlying controller role.

What must joint controllers actually do under Article 26?

Article 26(1) requires joint controllers to determine their respective GDPR responsibilities transparently by means of an arrangement. This requirement applies unless, and to the extent that, their responsibilities are already determined by Union or Member State law applicable to them.

The arrangement must address compliance responsibilities, particularly the exercise of data subject rights and the duties to provide the information required by Articles 13 and 14. It may also designate a contact point for data subjects — that is optional, but transparently allocating the relevant responsibilities is not.

Article 26(2) adds two further requirements: the arrangement must duly reflect the respective roles and relationships of the joint controllers in relation to data subjects, and its essence must be made available to those data subjects. This supports the transparency objective reflected in Recital 58 and the allocation of responsibilities addressed in Recital 79.

The arrangement cannot take rights away from individuals. Under Article 26(3), a data subject may exercise GDPR rights in respect of and against each controller, irrespective of the arrangement’s terms. An internal clause saying that only one controller will deal with requests cannot prevent a person from approaching the other controller.

How did the Facebook fan page ruling establish joint controllership?

Case C-210/16 concerned Wirtschaftsakademie Schleswig-Holstein GmbH, a German education-sector company that operated a Facebook fan page to offer educational services. Administrators of fan pages could use a free function called Facebook Insights to access anonymised statistical information about visitors.

Facebook generated those statistics through cookies placed on visitors’ devices. The cookies contained a unique user code, remained active for two years and were matched with Facebook login data. On 3 November 2011, the Schleswig-Holstein supervisory authority, the ULD, ordered Wirtschaftsakademie to deactivate its fan page because neither Wirtschaftsakademie nor Facebook had informed visitors about Facebook’s collection and processing through cookies.

Wirtschaftsakademie challenged the order, arguing that Facebook’s processing could not be attributed to the company because it had neither commissioned nor controlled that processing. The German Federal Administrative Court referred questions to the CJEU.

The CJEU found that Facebook Ireland was a controller because it primarily determined the purposes and means of the processing. Crucially, however, Facebook Ireland was not the only relevant controller — the fan page administrator also had to be regarded as jointly responsible within the EU for the processing.

The administrator participated by defining parameters according to its target audience and its objectives in managing or promoting its activities. It could request anonymised demographic information, including age, sex, relationship status and occupational trends, as well as lifestyle and interest information (including purchasing habits and preferred categories of goods or services) and geographical information useful for targeting offers or events.

By asking Facebook to generate those categories of statistics, the administrator was requesting the processing necessary to produce them. The fact that the resulting statistics were anonymised for the administrator did not remove its participation in determining the underlying processing.

The Court’s practical message was direct: using a platform supplied by a third party to obtain associated services does not exempt the platform user from its own data protection obligations. A business must examine what its choices, settings and requested outputs cause the platform to do. The judgment was delivered under Directive 95/46/EC, the GDPR’s predecessor — its reasoning nevertheless provides the doctrinal basis for applying the Article 26 joint-controller concept to Facebook fan pages and configurable third-party analytics.

What did the Court say about supervisory authority powers?

The CJEU also addressed which supervisory authority could intervene. It held that the ULD in Germany could exercise its full powers against Wirtschaftsakademie, an entity established in its territory, even where infringements were committed by a third-party joint controller established in another Member State.

The German authority did not first have to call on the supervisory authority of Facebook Ireland’s Member State. Its powers included ordering the locally established fan page administrator to deactivate the page. For a business using a cross-border platform, the presence of another joint controller in a different Member State therefore did not put the local business beyond the reach of its national supervisory authority.

Practical example: how would Article 26 apply to a small business fan page?

This is an illustrative example based on the reasoning of CJEU Case C-210/16. “Nordlicht Consulting GmbH” is fictional and is not a party to the judgment.

Step 1: Nordlicht operates a Facebook page

Nordlicht Consulting GmbH is a small German consultancy. It operates a Facebook page to promote seminars and consulting services. Facebook Insights is enabled, and Nordlicht uses the page’s available settings to request visitor statistics suited to its target audience and promotional objectives.

Step 2: Facebook performs the underlying collection

Facebook carries out the technical processing used to generate the Insights statistics. Following the facts examined in C-210/16, that processing includes information collected through cookies and matched with Facebook login data. Facebook Ireland primarily determines the purposes and means of that platform processing and is therefore a controller.

Step 3: Nordlicht selects useful audience parameters

Nordlicht asks for statistical information about the age, geographical location, interests and purchasing preferences of the audience it wants to reach, and uses the resulting anonymised information to decide which seminars to promote and where to advertise events.

Under the CJEU’s reasoning, Nordlicht is not merely a passive recipient of a general platform service. Its selected parameters, target audience and promotional objectives participate in determining the purposes and means of the processing. Requesting the analytics also requests the processing needed to produce them — Nordlicht would therefore be a joint controller with Facebook Ireland for that processing.

Step 4: Nordlicht must ensure that an Article 26 arrangement exists

Nordlicht and Facebook Ireland need an arrangement that transparently determines their respective responsibilities, reflecting their actual roles and relationship towards Facebook page visitors: Facebook Ireland’s role in the platform processing, and Nordlicht’s role in selecting parameters and using Insights for its own promotional objectives.

The arrangement must allocate responsibilities concerning data subject rights and the information required by Articles 13 and 14. It may designate a contact point. Its essence must be made available to page visitors, so the allocation cannot remain entirely hidden within the controllers’ internal relationship.

Step 5: A visitor sends an Article 15 request to Nordlicht

Suppose a visitor directs an Article 15 access request to Nordlicht rather than to Facebook Ireland. Article 26(3) means that the visitor may exercise GDPR rights in respect of and against each joint controller, irrespective of the arrangement’s internal terms.

Nordlicht therefore cannot reject the request merely by saying that Facebook performs the technical processing, or that the arrangement assigns request handling to Facebook Ireland. The arrangement should provide a workable allocation for dealing with rights requests, but that allocation does not remove the visitor’s right to approach Nordlicht directly. The distinction between internal responsibility and the individual’s external rights is a key Article 26 exam point.

How is joint controllership different from a controller-processor relationship?

The decisive Article 26 feature is joint participation in determining purposes and means. In the fan page case, the administrator argued that it had not commissioned or controlled Facebook’s processing — that argument did not prevent controller status because its definition of parameters and its own audience and promotional objectives connected it to the determination of the processing.

When distinguishing Article 26 from a controller-processor relationship under Article 28, do not begin and end with the parties’ chosen label. Ask what each organisation actually determines. If both participate in determining the purposes and means of the relevant processing, Article 26’s joint-controller framework applies to that processing.

The analysis must also be tied to the specific operation in question. The CJEU’s conclusion concerned the processing of fan page visitor data used to produce the requested Insights statistics — the case supports a functional assessment of roles rather than a blanket assumption based simply on the fact that one party owns the platform.

What happens if joint controllers do not agree on an Article 26 arrangement?

If organisations jointly determine purposes and means, Article 26 says that they shall determine their respective responsibilities transparently by means of an arrangement, unless applicable Union or Member State law already determines those responsibilities. Failing to put the required arrangement in place does not change the factual role of either controller.

Nor does the absence of an arrangement suspend data subject rights. Article 26(3) continues to allow a person to exercise GDPR rights against each controller. An incomplete or missing allocation therefore cannot be used to send the individual away, or to argue that responsibility rests exclusively with the other organisation.

C-210/16 also shows the practical importance of identifying responsibility correctly: a supervisory authority was permitted to intervene against the fan page administrator established in its territory, including by ordering deactivation, without first having to call on the supervisory authority responsible for the platform controller in another Member State.

Frequently Asked Questions

Is every business with a Facebook page automatically a joint controller?
The ruling concerned an administrator that participated through its selection of parameters, target audience and objectives and requested Facebook Insights statistics. The relevant question is whether the business participates in determining the purposes and means of the processing, not merely whether it has an account on a platform.
Does receiving only anonymised Insights data prevent joint-controller status?
No. In C-210/16, the administrator received anonymised statistical data but was still treated as jointly responsible because requesting the statistics meant requesting the processing used to generate them.
Can an Article 26 arrangement require visitors to contact only Facebook?
The arrangement may designate a contact point and allocate responsibility for handling rights requests. However, Article 26(3) allows a data subject to exercise GDPR rights in respect of and against each controller, irrespective of the arrangement’s terms.
Can a local supervisory authority act against the fan page administrator?
Yes. In C-210/16, the German supervisory authority could exercise its full powers against Wirtschaftsakademie, which was established in its territory, without first calling on the supervisory authority of Facebook Ireland’s Member State.

Master GDPR Controller & Processor Rules for Your DPO Exam

Test your knowledge on Article 26, joint controllers, and all GDPR requirements with our realistic mock exams.

Start Free Practice Test

Primary Sources & Verification

  • Regulation (EU) 2016/679 (GDPR), Article 26 (Joint controllers) - EUR-Lex
  • Court of Justice of the European Union, Case C-210/16, Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v Wirtschaftsakademie Schleswig-Holstein GmbH, judgment of 5 June 2018 (Press Release No 81/18) - curia.europa.eu

Note: the judgment was delivered under Directive 95/46/EC (the GDPR’s predecessor), because the underlying facts pre-date the GDPR’s 25 May 2018 application date. It remains the leading EU authority applied to Article 26 joint-controller questions for platform analytics tools such as Facebook fan pages.