Two separate apps jointly decide the purposes and means of processing for a shared login identity service. Which accountability step is required under GDPR joint-controller rules?
Select an answer to reveal the explanation.
Short Explanation
If two shops co-write the rules for a shared membership card, they both own the privacy homework and must post who does what. That is the joint-controller arrangement idea. Pretending only the bigger logo counts, or calling everyone a processor, ducks the duty.
Full Explanation
Article 26 requires joint controllers that jointly determine purposes and means to determine their respective responsibilities for compliance in a transparent manner, including as regards rights and information duties. Ignoring a co-deciding partner or mislabelling joint controllers as processors does not erase joint accountability. Data subjects may exercise rights against each joint controller.