Group privilege
The group privilege is the widespread misconception that data transfers between affiliated companies are exempt from data protection law; in reality the GDPR grants no such exemption, each group company is a controller in its own right and every transfer needs a legal basis.
Company law, accounting law and competition law frequently treat a corporate group as a single economic unit. Data protection law deliberately does not follow that logic. Art. 4(7) GDPR attaches controllership to the individual natural or legal person that determines the purposes and means of processing – that is, to the specific group entity, not to the group as a whole. The GDPR does recognise the concepts of a group of undertakings and a controlling undertaking in Art. 4(19), but it derives no exemption from them. Passing personal data from a subsidiary to its parent or to a sister company is therefore a disclosure to a third party within the meaning of Art. 4(10) GDPR and a processing operation in its own right, requiring a legal basis under Art. 6(1) GDPR.
Recital 48 GDPR is often cited as proof that a group privilege exists. It states that controllers forming part of a group of undertakings may have a legitimate interest in transmitting personal data within the group for internal administrative purposes, including the processing of clients' and employees' data. Recitals, however, are interpretative guidance and not an autonomous legal basis: they merely strengthen the argument under Art. 6(1)(f) GDPR and replace neither the documented balancing test nor the assessment of the data subjects' reasonable expectations. For employee data there is an additional complication: the opening clause in Art. 88 GDPR and its German implementation in Section 26 BDSG were called into question by the Court of Justice in its judgment of 30 March 2023 (Case C-34/21), and a dedicated German employee data protection act has been announced several times but has not yet entered into force.
In practice, intra-group data flows can be legitimised through three constructions that must be kept clearly apart. Where one entity processes on the documented instructions of another – for example a shared service centre running payroll or IT operations – the relationship is processing on behalf of a controller and requires a contract under Art. 28(3) GDPR. Where two entities jointly determine purposes and means, joint controllership applies and an arrangement under Art. 26 GDPR is needed. Where each entity remains an independent controller, the transfer itself must rest on Art. 6(1)(b), (c) or (f) GDPR and be reflected in the record of processing activities, in the transparency notices under Art. 13 and 14 GDPR and in the retention and deletion concept. If group entities sit outside the EEA, Chapter V adds a second layer: an adequacy decision, standard contractual clauses plus a transfer impact assessment, or binding corporate rules approved under Art. 47 GDPR, which are the instrument genuinely designed for corporate groups. A group-wide data protection policy, a common role and authorisation concept and consistent technical and organisational measures are what turn this structure from paper into practice.
Legal Basis
Art. 4(7), 4(10) and 4(19), Art. 6(1), Art. 26, Art. 28, Art. 44 et seq. and Art. 47 GDPR; Recital 48 GDPR; Art. 88 GDPR in conjunction with Section 26 BDSG
Practical Example
An automotive supplier with its parent company in Germany, production entities in Poland and Mexico and a sales subsidiary in France rolls out a group-wide HR system. The business side argues that transfers inside the group are unproblematic. The group data protection officer instead maps the data flows and classifies each one separately: every local entity remains the controller for its own employees, the parent operates the system as a processor for them and concludes an Art. 28 GDPR contract with each subsidiary, including the sub-processor chain down to the cloud provider. The group-wide talent review, where central HR independently decides how performance data on senior management is used, is treated as a controller-to-controller transfer based on Art. 6(1)(f) GDPR, with a documented balancing test, a strict limitation to defined data fields and an update to the employee privacy notice. Access by the Mexican entity is covered by standard contractual clauses together with a transfer impact assessment; in the medium term the group intends to replace this patchwork with approved binding corporate rules. All three constellations end up as separate entries in the record of processing activities of the entity concerned.