Joint Controllership for Tracking Pixels (Meta, Google Ads)
Joint controllership under Article 26 GDPR applies where several parties jointly determine the purposes and means of a data processing operation, for example when a website operator embeds a Meta pixel or a Google Ads remarketing tag and the provider also processes the collected data for its own purposes. What matters is not who embedded the script but who has a say. The provision requires joint controllers to agree who fulfils which duty, and to make the essence of that arrangement available to the people concerned. Pseudonymous advertising identifiers are personal data too, as long as a person can be reidentified with reasonable effort (recital 26 GDPR). In the three-party constellation of advertiser, website operator and tracking provider, each side can therefore end up carrying responsibility, regardless of who technically obtained the consent.
In practice
Anyone embedding Meta pixels, Google Ads remarketing tags or comparable retargeting scripts should not assume that the platform provider alone is liable for GDPR compliance. Article 82 GDPR gives affected people a claim for damages, and paragraph 4 places joint controllers side by side as jointly and severally liable. How that plays out in a specific case is a legal question, and not one we assess. What follows in practice: review an agreement under Article 26 GDPR with the provider in question. Name its key elements in your own privacy policy, including who the joint controller is. Technically, the pixel may only load after granular, active consent through the CMP, ideally via Google Consent Mode or an equivalent consent gate in the tag manager. Agencies implementing tracking setups should document this (before and after checks in incognito mode) and add liability provisions for faulty implementation to client contracts, since website operators can seek recourse if damage occurs.