Intra-group privilege (Konzernprivileg)

Data protection glossary · 1 minute read

The intra-group privilege refers to a simplified sharing of personal data within a group of undertakings, which the GDPR does not, however, provide for as such.

No general intra-group privilege

Each group company is a separate entity under data protection law. If one company passes data to another, this is a transfer that requires its own legal basis.

The GDPR does, however, recognise that there may be a legitimate interest in transmitting data within a group of undertakings for internal administrative purposes, for example customer or employee data. This is therefore sometimes referred to as a limited intra-group privilege.

Structuring within a group

In practice, intra-group data flows are governed by data processing agreements, joint controllership arrangements or, for international groups, binding corporate rules. A group of undertakings may designate a single data protection officer.

Art. 4(19) GDPR
Definition of a group of undertakings.
Recital 48 GDPR
Legitimate interest in transmissions for internal administrative purposes.
Arts. 26 and 28 GDPR
Joint controllers and processing on behalf of a controller.
Art. 37(2) GDPR
Single data protection officer for a group of undertakings.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.