Legitimate interests for intra-group data sharing is a basis that many corporate groups assume they have, and few document properly. Recital 48 of the GDPR says that controllers that are part of a group of undertakings may have a legitimate interest in transmitting personal data within the group for internal administrative purposes, including the processing of clients’ or employees’ personal data. That is a useful starting point, but it is not a free pass.
This guide explains what Recital 48 does and does not allow, how to apply the three-part test to group sharing, how to handle transparency and international transfers and what agreements to put in place. It is general information, not legal advice.
What Recital 48 actually says
Recital 48 acknowledges that group companies have a legitimate interest in sharing personal data for internal administrative purposes. It also says the general principles for transfers to a country outside the EU remain unaffected. In other words, the recital supports the interest, but the necessity and balancing tests, the transparency duties and the transfer rules all continue to apply.
It is also a recital rather than an operative article, so it guides interpretation but does not create an automatic right. Treat it as support for your argument, not a substitute for the assessment. You can read it in Recital 48 of the GDPR.
Each group company is its own controller
Under the GDPR, each legal entity is a separate controller or processor. Sharing between them is a disclosure, not an internal movement of data. The receiving company needs its own purpose and its own lawful basis, and each entity is accountable for what it does.
That means group-wide policies are not enough on their own. You need to identify, for each flow, which entity is sharing, which is receiving, for what purpose and on what basis. Where entities decide jointly, they may be joint controllers, which brings an arrangement requirement. Our page on joint controller records explains how to record that.
| Group sharing scenario | Typical position | Watch out for |
|---|---|---|
| Shared HR and payroll services | Often workable for administration | Special category data and monitoring |
| Central customer database | Possible with clear limits | Marketing use by other entities |
| Group-wide reporting and analytics | Often workable with aggregation | Identifiable data not needed for reporting |
| Shared IT and security services | Usually workable | Access by staff who do not need it |
| Cross-border sharing with non-EEA entities | Needs a transfer mechanism as well | Third-country laws and onward transfer |
Free legitimate interests assessment
Can you rely on legitimate interests for this processing?
Check whether legitimate interests is available, set out the purpose, test necessity, weigh the impact on people from 25 scenarios and choose the safeguards that tip the balance. Built to GDPR Article 6(1)(f), free.
Step one: pin down the purpose
State the administrative purpose in specific terms: centralised payroll processing, a shared service desk, consolidated financial reporting, group security monitoring. Avoid vague statements such as “group efficiency”. A concrete purpose lets you check each data element against it and prevents drift.
Keep marketing and product analytics separate. Recital 48 speaks of internal administrative purposes, and using shared customer data for cross-selling by another entity is a different purpose that needs its own assessment and often a different basis.
Step two: test necessity of intra-group data sharing
Ask whether the receiving entity really needs identifiable data. Group reporting might work with aggregated or pseudonymised figures. Shared services may need names and contact details but not full personnel files. Limit access to the teams that perform the service, and remove data fields that are not needed.
Also consider whether the same result could be achieved with fewer transfers, for example by processing in one place under a service agreement instead of copying data to several entities. Record the alternatives and why you chose your approach.
Step three: balance the interests
Weigh the group’s interest against the impact on individuals. Employees and customers generally expect some sharing with related companies for administration, but not unlimited sharing or use for unrelated aims. The closer the shared data is to sensitive information, the stronger the case for restricting it.
Think about the relationship. Staff have less choice than customers, so extra care is needed with HR data. Consider whether people would be surprised to learn who sees their data, and whether a privacy notice would make that clear. Document the safeguards that make the sharing proportionate.
- Limit fields and access to what the service needs
- Keep special category data out unless a specific condition applies
- Use aggregation or pseudonymisation for reporting
- Restrict secondary uses such as marketing
Transparency about intra-group data sharing
Your notices should tell people that data is shared within the group, identify the categories of recipient and explain the purpose. If the entities are outside the EU, say so and describe the safeguard used. Avoid a bare reference to “our affiliates” without explanation.
Because the basis is legitimate interests, people can object under Article 21. Set up a process so an objection received by one entity reaches the others that hold the data. See legitimate interests and the right to object for how to respond.
International transfers within the group
If group entities sit in different countries, transfers to entities outside the EU or UK need a lawful transfer mechanism such as adequacy, standard contractual clauses or binding corporate rules. Legitimate interests does not cover the transfer itself. Our guides to international data transfers and intra-group transfer impact assessments explain the steps.
Check the laws of the destination country for government access and assess whether supplementary measures are needed, as described in supplementary measures for data transfers.
Agreements and governance for intra-group data sharing
Put an intra-group data sharing agreement in place. It should describe the purposes, data categories, roles, security standards, retention, breach notification, handling of data subject requests and audit rights. Where one entity processes for another, a processor contract is needed, as covered in controller and processor records.
Governance matters as much as paper. Name a group privacy lead, keep a register of flows and review it at least annually. Add the flows to each entity’s record of processing so they stay consistent.
Governance checklist for intra-group data sharing
Keep a short checklist for every new flow: which entities are involved, what the purpose is, what data moves, who can access it, which transfer mechanism applies, what the notice says and when the assessment will be reviewed. Approval should come from the privacy lead before the flow starts, not after. The same checklist helps when you integrate a newly acquired company, since acquisitions are the moment when unassessed flows appear most often.
Common mistakes
Frequent errors include assuming Recital 48 removes the need for an assessment, treating the group as a single controller, sharing more data than the service needs, using shared data for marketing, ignoring transfer rules and failing to update notices when new entities join. Another is forgetting acquisitions: integrating a newly bought company often brings new data flows that nobody has assessed.
Review the assessment when the group structure changes, when a new shared service starts or when the purpose shifts. Our legitimate interests assessment example shows a format you can adapt.
Reviewing the arrangement over time
Set a review date for each arrangement and note who is responsible. Ask whether the purpose, the data or the entities have changed, whether any objections or complaints have arisen and whether access is still limited to the right teams. Record the outcome even when nothing changes, so you can show that the assessment is maintained.
A short worked example
A group with entities in three countries centralises payroll in one shared service centre. The assessment records the purpose, limits data to what payroll needs, excludes health data except where required for statutory pay and restricts access to the payroll team. Reporting to group management uses aggregated figures only.
Notices to employees name the shared service entity and explain the safeguards for transfers. An intra-group agreement is signed, and the flows appear in each entity’s record of processing. The assessment is reviewed annually and after any change to the service. It is documented, proportionate and easy to explain.
A structured assessment
If you want a consistent format to record purpose, necessity, balance and safeguards for each flow, the Legitimate Interests Assessment Report and Workbook provides a report and workbook that follow the three-part test. Whatever tool you use, sound legitimate interests for intra-group data sharing means treating each company as its own controller, sharing the minimum and telling people plainly what happens.
Legitimate interests for intra-group data sharing FAQ
Does Recital 48 let group companies share data freely?
No. It supports a legitimate interest in internal administrative sharing, but each company still needs a purpose and basis, and the necessity and balancing tests still apply.
Is the group one controller?
No. Each legal entity is a separate controller or processor, so sharing between them is a disclosure that needs its own justification.
Do we need an intra-group agreement?
It is strongly advisable. It records purposes, roles, security, retention and how requests are handled, and may be required for processors or joint controllers.
Does legitimate interests cover transfers outside the EU?
No. A transfer mechanism such as adequacy, standard contractual clauses or binding corporate rules is needed in addition to a lawful basis.
Can another group company use the data for marketing?
That is a different purpose that needs its own assessment and often consent under ePrivacy rules. Do not assume the administrative basis covers it.