Joint Controllership for Tracking Pixels (Meta, Google Ads)
Joint controllership under Article 26 GDPR applies where several parties jointly determine the purposes and means of a data processing operation, for example when a website operator embeds a Meta pixel or a Google Ads remarketing tag and the provider also processes the collected data for its own purposes. The CJEU set out this principle back in 2019 in the Fashion ID ruling (C-40/17) on the Facebook Like button. On 15 June 2023 the French data protection authority CNIL imposed a fine of €40 million on the ad tech provider Criteo (SAN-2023-009), criticising among other things that the agreements with its partners did not sufficiently regulate the allocation of roles under Article 26 GDPR. The French Conseil d'État upheld that sanction on 4 March 2026 (No. 482872), clarifying that pseudonymous advertising identifiers are personal data as well. In this three-party constellation (advertiser – website operator – tracking provider), each party can be liable directly towards the users affected, regardless of who technically obtained the consent.
In practice
Anyone embedding Meta pixels, Google Ads remarketing tags or comparable retargeting scripts should not assume that the platform provider alone is liable for GDPR compliance. On 3 February 2026 the Higher Regional Court of Dresden ordered Meta, in four final judgments (including 4 U 196/25), to pay €1,500 each in non-material damages under Article 82 GDPR for the data processing carried out through the Meta Business Tools. No comparable judgment has so far been handed down against a website operator; in the professional debate, however, joint liability arising from joint controllership and the joint and several liability under Article 82(4) GDPR is considered possible. In concrete terms: review or conclude a joint controller agreement under Article 26 GDPR with the provider in question and name its key elements in your own privacy policy (including the name of the joint controller, for example "Meta Platforms Ireland Limited"). Technically, the pixel may only load after granular, active consent through the CMP – ideally via Google Consent Mode or an equivalent consent gate in the tag manager. Agencies implementing tracking setups should document this (before and after checks in incognito mode) and add liability provisions for faulty implementation to client contracts, since website operators can seek recourse if damage occurs.