Two companies act as joint controllers but never tell data subjects which party handles access requests or how responsibilities are split. What transparency duty are they most clearly missing?
Select an answer to reveal the explanation.
Short Explanation
Joint controllers are like two co-owners of a shop—customers still need a clear door to knock on. GDPR expects the essence of who does what, and a contact point, to be available to people—not a black box.
Full Explanation
Article 26 requires joint controllers to determine their respective responsibilities and to make the essence of the arrangement available to data subjects, including designating a contact point. Failing to explain who handles rights requests frustrates transparency and access. Renaming roles or flooding the public with employee directories does not meet that duty.