The intra-group privilege refers to a simplified sharing of personal data within a group of undertakings, which the GDPR does not, however, provide for as such.
No general intra-group privilege
Each group company is a separate entity under data protection law. If one company passes data to another, this is a transfer that requires its own legal basis.
The GDPR does, however, recognise that there may be a legitimate interest in transmitting data within a group of undertakings for internal administrative purposes, for example customer or employee data. This is therefore sometimes referred to as a limited intra-group privilege.
Structuring within a group
In practice, intra-group data flows are governed by data processing agreements, joint controllership arrangements or, for international groups, binding corporate rules. A group of undertakings may designate a single data protection officer.
Legal provisions
- Art. 4(19) GDPR
- Definition of a group of undertakings.
- Recital 48 GDPR
- Legitimate interest in transmissions for internal administrative purposes.
- Arts. 26 and 28 GDPR
- Joint controllers and processing on behalf of a controller.
- Art. 37(2) GDPR
- Single data protection officer for a group of undertakings.