Joint controllership arrangement between lessees, country entities and PNO Holding
Joint Data Controllership Arrangement
Between
Data controller 1
[Insert name of lessee]
Company Registration Number.: [Insert]
[Insert address of lessee]
[Insert address line 2 (zip code and city) of lessee]
[Insert country of lessee]
and
Data controller 2
[Name of PNO entity party to the leasing agreement]
Company Registration Number.: [Insert]
[Insert address of PNO entity]
[Insert address line 2 (zip code and city) of PNO entity]
[Insert country of PNO entity]
and
Data controller 3
PNO Holding A/S
Company Registration Number 26 10 14 09
Århusgade 118
2150 Nordhavn
Denmark
Each a “party” and collectively, the “parties”
January 2026
1 Joint Controllership
This arrangement sets out the division of responsibilities between Data controller 1, Data controller 2 and Data controller 3 in relation to the processing of personal data in the context the PNO platform for equipment management (“the Platform”) and related processing, such as analysis of data derived from the platform.
1.1
According to Article 26 of the General Data Protection Regulation, joint Data controllership exists when two or more Data controllers jointly determine the purposes and means of the processing.
In the case of joint Data controllership, the joint Data controllers shall determine in a transparent manner their respective responsibilities for compliance with the obligations under the General Data protection Regulation, in particular to exercise the data subject’s rights and their respective obligations to provide the information referred to in Articles 13 and 14, by means of an arrangement between them, unless and to the extent that the respective responsibilities of the Data controllers are laid down in Union or Member States’ national law to which the Data controllers are subject.
The arrangement shall, in accordance with Article 26(2) of the General Data Protection Regulation, duly reflect the respective roles of the joint data controllers and their relationship with the data subjects. The main content of the arrangement must also be made available to data subjects.
However, regardless of the terms of the arrangement, the data subject may exercise their rights under the General Data Protection Regulation with regard to and against the individual data controller.
Similarly, the “internal” division of responsibilities in the joint data controller arrangement does not prevent the supervisory authority from exercising its powers in relation to any of the three data controllers.
1.2
Data controller 1, Data controller 2 and Data controller 3 agree that they are joint data controllers in the context of processing of telematics information related to equipment leased by Data controller 1 from Data controller 2. In assessing this, account has been taken, inter alia, to the following factual circumstances:
- Data controller 1 is leasing trailers from Data controller 2.
- Data controller 2 is the counterparty of Data controller 1 in the leasing agreement, which includes an agreement on access to the Platform, through which both Data controller 1 and Data controller 2 may access telematics information regarding the leased trailers, as collected by Data controller 3.
- Data controller 3 is providing the common platform for management of equipment (“the Platform”) referred to above
- Data controller 1 is reasonably likely to be able to determine the identity of the natural person driving the truck pulling a specific trailer at a given point in time, and therefore, telematics data related to the trailer will constitute personal data about the driver in accordance with the principles laid down by recital 26 of the General Data Protection Regulation.
- The access of Data controller 1 and Data controller 2 to telematics data stored on the Platform is inextricably linked to the collection of this information carried out by Data controller 3, as the collection carried out by Data controller 3 is a prerequisite of the processing carried out by Data controller 1 and Data controller 2. Furthermore, since all three parties are using the telematics data for own purposes, they must all be considered data controllers, and as a consequence, they are considered joint controllers for the personal data stored on the Platform.
1.3
This arrangement is designed to enable Data controller 1, Data controller 2 and Data controller 3 to comply with the joint liability requirements of Article 26 of the General Data Protection Regulation. The arrangement sets out the respective responsibilities of Data controller 1, Data controller 2 and Data controller 3 to comply with the obligations of the General Data protection Regulation, in particular to exercise the data subject’s rights and the obligation to provide the information referred to in Articles 13 and 14.
1.4
With respect to all processing activities not defined in clause 2.2 below, each Party is an independent controller within the meaning of Article 4 No. 7 of the General Data Protection Regulation.
2 Overall allocation of responsibilities
2.1
Each Party acknowledges and confirms that they will observe all applicable requirements of data protection laws including the General Data Protection Regulation, particularly with regard to the lawfulness of the joint processing operations, and the terms of this Arrangement and irrelevant of the allocation of responsibilities agreed on in this arrangement.
2.2
The Parties have determined the following processing activities as further described in their respective privacy notices:
|
Processing activity |
Purpose of processing |
Categories of processed data |
|
Storage of data |
Having telematics data about leased trailers available on the Platform |
|
2.3
The Parties shall store the personal data in a structured common and machine-readable format.
2.4
The Parties safeguard that only personal data is collected that is necessary for the legitimate handling of the respective process.
3 Principles and legal basis
3.1
Data controller 3 is responsible for ensuring that all processing activities taking place under the joint controllership are in compliance with the fundamental principles as set out in article 5 of the General Data Protection Regulation, and that there is a valid legal basis for any and all processing activities.
3.2
Data controller 1, Data controller 2 and Data controller 3 are all responsible for complying with the Principles for the Processing of Personal Data to the extent that the rules apply to the Data controller’s responsibilities under this arrangement.
4 Rights of data subjects
4.1
Data controller 1 fulfils the information obligations towards the data subjects pursuant to Articles 13, 14 of the General Data Protection Regulation for the joint processing operations and takes the appropriate and necessary measures for this purpose. This includes reference to the applicable privacy notices of Data controller 2 and Data controller 3, containing information on each of these Data controllers’ processing of personal data subject to this arrangement, including information on transfers to data processors and other third parties.
4.2
Data controller 1 fulfils the information and notification obligations under Articles 15 to 22 of the General Data Protection Regulation for the joint processing operations and takes the appropriate and necessary measures to ensure compliance with the following rules of the General Data Protection Regulation:
- the obligation to provide information when collecting personal data from the data subject,
- the obligation to provide further information if personal data have not been collected from the data subject,
- the data subject’s right of access,
- the data subject’s right of rectification,
- the right to erasure (right to be forgotten),
- the data subject’s right to restriction of processing,
- the obligation to provide information in relation to the rectification or erasure of personal data or the restriction of processing,
- the data subject’s right to data portability (except for public authorities);
- the data subject’s right to object to processing; and
- the data subject’s right to withdraw consent.
4.3
All practical handling of requests from data subjects shall be taken care of by Data controller 1.
4.4
If Data controller 2 or Data controller 3 receives a request or an enquiry from a data subject, it shall be transmitted to Data controller 1 as soon as possible in order for Data controller 1 to handle the further processing of the request.
4.5
All Parties shall be responsible for assisting each other to the extent appropriate and necessary for each of the Parties to comply with their obligations towards data subjects.
5 Security of processing and documentation of compliance with the General Data Protection Regulation
5.1
Data controller 3 will be responsible to implement appropriate technical and organisational measures to ensure and demonstrate that the processing is in compliance with the General Data Protection Regulation; taking into account the nature, scope, context and purposes of the processing involved, as well as the risks of varying degrees of likelihood and severity for the rights and freedoms of natural persons. The measures shall be documented, reviewed and updated as necessary (Article 24(1) sentence 2 of the General Data Protection Regulation).
5.2
The measures shall include, where proportionate to the processing activities, the implementation of appropriate data protection policies.
5.3
The Data controller 3 shall be responsible for compliance with the data protection by design and data protection by default rule of Article 25 of the General Data Protection Regulation.
5.4
Data controller 3 is responsible for complying with the requirement of Article 32 of the General Data Protection Regulation on security of processing. This implies that Data controller 3, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing operation concerned, as well as the risks of varying probability and severity to the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure an appropriate level of security appropriate to those risks.
Data controller 3 shall carry out and document a risk assessment and then implement measures to mitigate the identified risks.
6 Use of data processors and sub-processors
6.1
Data controller 3 is entitled to use data processors and sub-processors in connection with the joint processing operation.
6.2
In the event of the use of processors and/or sub-processors, Data controller 3 shall be responsible for complying with the requirements of Article 28 of the General Data Protection Regulation. Accordingly, Data controller 3 shall, inter alia:
- use only processors that can provide the necessary guarantees that they implement appropriate technical and organizational measures in such a way as to ensure that processing complies with the requirements of this Regulation and safeguards the rights of the data subject,
- ensure that a valid data processing arrangement is in place between Data controller 3 and the processor; and
- ensure that there is a valid sub-processor arrangement between the processor and any sub-processor.
6.3
Data controller 1 and Data controller 2 shall be informed, upon request, whether the personal data is processed by processors and, where applicable, sub-processors of Data controller 3.
6.4
If personal data is processed by data processors and, where applicable, sub-processors, Data controller 1 and Data controller 2 shall be informed, upon request, of the content of the arrangements between Data controller 3 and the processor/sub-processor.
7 Records of processing activities
7.1
Data controller 3 shall be responsible for complying with the requirement of Article 30 of the General Data Protection Regulation on records of processing activities. This implies that Data controller 3 shall establish a record of the processing activities for which the Parties are joint controllers in respect of the associated processing of personal data.
7.2
Data controller 3 shall inform Data controller 1 and Data controller 2 of the content of the above record. The content of the above record as of the time of entering into this arrangement is included in Annex 1.
7.3
Data controller 1 and Data controller 2 shall establish – based on the contents of the Data controller 3 record – their own record of the processing activities covered by the arrangement.
8 Notification of personal data breaches to the supervisory authority
8.1
Data controller 3 shall be responsible for compliance with Article 33 of the General Data Protection Regulation on the notification of personal data breaches to the supervisory authority for all data breaches, regardless of where they appear.
9 Communication of personal data breaches to the data subject
9.1
Data controller 3 shall be responsible for compliance with Article 34 of the General Data Protection Regulation regarding the communication of personal data breaches to the data subject.
10 Data protection impact assessment and prior consultation
10.1
Data controller 3 shall be responsible for compliance with the requirement of Article 35 of the General Data Protection Regulation on data protection impact assessments. This implies that, where a type of processing, in particular using new technologies and by virtue of its nature, scope, context and purposes, is likely to result in a high risk to the rights and freedoms of natural persons, Data controller 2 shall, prior to the processing, carry out an analysis of the implications of the envisaged processing activities for the protection of personal data.
10.2
Data controller 3 shall also comply with the requirement of Article 36 of the General Data Protection Regulation to consult the supervisory authority in advance, where appropriate, including provision of the necessary information to the authority under Article 36(3) of the General Data Protection Regulation.
11 Transfer of personal data to third countries or international organizations
11.1
Data controller 3 may decide that personal data may be transferred to third countries or international organizations.
11.2
Data controller 3 shall be responsible for compliance with the requirements of Chapter V of the General Data Protection Regulation in the event of transfers of personal data to third countries or international organizations.
12 Complaints
12.1
The Parties shall each be responsible for handling any complaints from data subjects, if the complaints relate to a breach of the provisions of the General Data Protection Regulation, for which the Party is responsible under this arrangement.
12.2
If one of the Parties receives a complaint, which should rightly be dealt with by the other Party, the complaint shall be forwarded to that controller as soon as possible.
12.3
If one of the Parties receives a complaint, part of which should rightly be dealt with by the other Party, that part shall be forwarded to the Party for reply as soon as possible.
12.4
The data subject shall be informed of the essential content of this arrangement when one Party forwards a complaint or part thereof to the other Party.
13 Informing the other Party
13.1
The Parties shall inform and liaise with each other of any material facts affecting the joint processing operation and this arrangement.
14 Regulation of other matters
14.1
Data controller 3 shall handle all practical matters in relation to processing of personal data subject to this Joint Data Controllership Arrangement, whether specifically described in the above clauses or not.
14.2
Data controller 3 shall be responsible for ensuring that all processing activities carried out under this Joint Data Controllership Arrangement are carried out in a manner that is compliant with the General Data Protection Regulation, including that documentation necessary to ensure compliance with the General Data Protection Regulation is produced.
15 Entry into force and termination
15.1
This Joint Data Controllership Arrangement shall enter into force upon being signed by all three Parties.
15.2
The Joint Data Controllership Arrangement shall remain in force for as long as the personal data concerned are processed or until it is replaced by a new arrangement laying down the division of responsibilities in relation to the processing.
15.3
Signature
|
On behalf of [Data controller 1] ___________________________ Name:______________________ Position:____________________ Date: ______________________ |
On behalf of [Data controller 2] ___________________________ Name:______________________ Position:____________________ Date: ______________________ |
On behalf of [Data controller 3] ___________________________ Name:______________________ Position:____________________ Date: ______________________ |
Annex 1
Information contained in the records of processing held by Data controller 3 in accordance with article 30 of the General Data Protection Regulation
|
Identity of the joint controllers |
Data controller 1, Data controller 2 and Data controller 3 as defined on the cover page of this agreement |
|
Purpose of the processing |
Collection and storage of telematics information from trailers leased by Data controller 1 from Data controller 2 for the purpose of providing each of the joint Data controllers with the basis for further analysis. For the avoidance of doubt, the further analysis of telematics data as carried out by each of the Data controllers, who are parties to this agreement, is not scope to this agreement, and will be carried out by each of the parties in a role as individual data controllers. |
|
Categories of data subjects |
Drivers of trucks pulling the trailer, for which telematics information is collected |
|
Categories of personal data |
Identification of the trailer Telematics information as made available through the Platform from time to time. (Each Data controller shall maintain their records based on what information is available through the platform from time to time) |
|
Categories of recipients |
Garages providing services for the trailers Data processors, of which the primary is Amazon Web Services and any sub-processors utilized by Amazon Web Services |
|
Transfers of personal data to third countries |
Data contained in the Platform will – in terms of the General Data Protection Regulation – be transferred to any country in which Amazon Web Services or any of their sub-processors are established. The transfer is made on the basis of the EU Standard Contractual Clauses. Furthermore, as information on the driver using the trailer at a given point in time is not contained in the platform, but processed locally by Data controller 1, and the recipients of data from the platform will therefore not be in a position to identify the data subjects, no further measures to protect the rights and freedoms of the data subjects have been deemed necessary. |
|
Retention of personal data |
Data that can identify the driver pulling a given trailer at any time is anonymized after 24 months, after which the remaining data about equipment and generated by equipment (telematics) is anonymous data and not in scope for GDPR. |
|
Technical and organizational measures implemented pursuant to article 32 of the General Data Protection Regulation |
Given that the Platform does not contain information on the identity of the data subjects, and since telematics data is an extra service, the lack of which will have no adverse consequences for the data subjects, the need to protect the confidentiality and availability of telematics is limited. Therefore, with the addition of a requirement for user ID and password to access the Platform, the protection of confidentiality and availability relies on the security provided by Amazon Web Services. With regards to the integrity of information, Data controller 3 will identify and investigate indications of data being incorrect, based on comparison with similar data from the more than 1,000 PNO trailers, for which telematics data is collected. Data controller 2 and Data controller 3 will not know the identity of the data subjects and will not make any decisions adversely affecting the rights and freedoms of the data subjects based on the data contained in the Platform. Data controller 1 should consider the need for further measures to verify the integrity of data from the Platform, if the data is used by Data controller 1 for processing activities, which may adversely affect the rights and freedoms of the data subjects. |

