Who is legally responsible
Under the UK GDPR and the Data Protection Act 2018, responsibility depends on who determines the “purposes and means” of processing your personal data, not on whose logo is on your certificate or who teaches the classes. The organisation (or organisations) that decides why and how your data is processed is a “controller”. A body that only processes data on another’s instructions is a “processor”. Where two or more organisations jointly decide the purposes and means, they are “joint controllers”.
In a jointly delivered course there are three common patterns, and which one applies to you determines who is responsible.
The likely structures
Separate controllers. The university and the college may each be an independent controller for the data they hold for their own purposes. For example, the college controls your day-to-day attendance, teaching and pastoral records, while the university controls your enrolment as its student, your assessment ratification and the award of the degree. In that case each is responsible for the data it decides on, and you exercise your rights against whichever body holds and controls that particular data.
Joint controllers. If the university and college genuinely decide together why and how your data is processed (for instance a shared admissions process, a jointly run programme with shared student records), they are joint controllers under Article 26 UK GDPR. They must have a transparent arrangement setting out their agreed roles, and the main points of that arrangement must be made available to you, normally in the privacy notice. Importantly, each joint controller remains responsible for complying with all controller obligations, and you can exercise your rights against either of them regardless of any internal division of duties between them.
Controller and processor. Sometimes the partner college processes data purely on the university’s instructions (a “validated” or “franchised” arrangement where the university is the awarding and controlling body). Here the university is the controller and the college is its processor, bound by a written contract under Article 28. The university carries primary legal responsibility, though the processor has its own direct obligations for security and for acting only on instructions.
How to find out which applies to you
The answer is a factual question that turns on documents you can obtain rather than on labels:
1. Read the privacy notice(s) you were given at enrolment. These should identify the controller(s), and if it is a joint arrangement they should say so and summarise how responsibilities are split.
2. Check the student contract, the partnership or franchise agreement wording, and any data protection or data sharing notice on both institutions’ websites.
3. Ask each institution’s Data Protection Officer directly who the controller is for your records. Universities and most large colleges must have a DPO, and their contact details should be published.
What this means in practice for your rights
If you want to exercise a data right, for example a subject access request, correction, erasure, or a complaint about misuse, you do not need to work out the internal split first. If they are joint controllers you may direct your request to either body and it must be honoured. If they are separate controllers, direct the request to the body that actually holds and controls the specific data you want. A sensible practical step is to send your request to both DPOs at the same time and ask them to confirm who is the controller for the data in question, so that neither can simply pass you back and forth.
If something goes wrong
If your data is mishandled, both joint controllers can in principle be held responsible, and you can pursue either. You can also complain to the Information Commissioner’s Office, which can investigate either or both organisations. Before escalating, it usually helps to raise the matter first with the relevant DPO in writing, giving them the statutory time to respond (normally one month for a subject access request), because early informal resolution is faster and cheaper than a formal complaint.
Key information to pin down
To give you a definitive answer on responsibility I would need to know how the course is described formally, in particular whether the university is the awarding body and the college teaches under a franchise or validation agreement, whether you enrolled with the university, the college, or both, and what the privacy notice you received actually says about controllers. Those documents will settle whether you are dealing with separate controllers, joint controllers, or a controller and processor arrangement.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
What does it mean if you are joint controllers? | ICOico.org.ukA guide to controllers and processors | ICOico.org.ukData sharing agreements | ICOico.org.ukControllers and processors | ICOico.org.ukKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.