Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Legitimate interests for intra-group data sharing between group companies with purpose, necessity and safeguards

Legitimate Interests for Intra-Group Data Sharing: 2026

Legitimate interests for intra-group data sharing is a basis that many corporate groups assume they have, and few document properly. Recital 48 of the GDPR says that controllers that are part of a group of undertakings may have a legitimate interest in transmitting personal data within the group for internal administrative purposes, including the processing of clients’ or employees’ personal data. That is a useful starting point, but it is not a free pass.

This guide explains what Recital 48 does and does not allow, how to apply the three-part test to group sharing, how to handle transparency and international transfers and what agreements to put in place. It is general information, not legal advice.

What Recital 48 actually says

Recital 48 acknowledges that group companies have a legitimate interest in sharing personal data for internal administrative purposes. It also says the general principles for transfers to a country outside the EU remain unaffected. In other words, the recital supports the interest, but the necessity and balancing tests, the transparency duties and the transfer rules all continue to apply.

It is also a recital rather than an operative article, so it guides interpretation but does not create an automatic right. Treat it as support for your argument, not a substitute for the assessment. You can read it in Recital 48 of the GDPR.

Each group company is its own controller

Under the GDPR, each legal entity is a separate controller or processor. Sharing between them is a disclosure, not an internal movement of data. The receiving company needs its own purpose and its own lawful basis, and each entity is accountable for what it does.

That means group-wide policies are not enough on their own. You need to identify, for each flow, which entity is sharing, which is receiving, for what purpose and on what basis. Where entities decide jointly, they may be joint controllers, which brings an arrangement requirement. Our page on joint controller records explains how to record that.

Group sharing scenarioTypical positionWatch out for
Shared HR and payroll servicesOften workable for administrationSpecial category data and monitoring
Central customer databasePossible with clear limitsMarketing use by other entities
Group-wide reporting and analyticsOften workable with aggregationIdentifiable data not needed for reporting
Shared IT and security servicesUsually workableAccess by staff who do not need it
Cross-border sharing with non-EEA entitiesNeeds a transfer mechanism as wellThird-country laws and onward transfer

Free legitimate interests assessment

Can you rely on legitimate interests for this processing?

Check whether legitimate interests is available, set out the purpose, test necessity, weigh the impact on people from 25 scenarios and choose the safeguards that tip the balance. Built to GDPR Article 6(1)(f), free.

Start the free LIA →  or  View premium report sample

Step one: pin down the purpose

State the administrative purpose in specific terms: centralised payroll processing, a shared service desk, consolidated financial reporting, group security monitoring. Avoid vague statements such as “group efficiency”. A concrete purpose lets you check each data element against it and prevents drift.

Keep marketing and product analytics separate. Recital 48 speaks of internal administrative purposes, and using shared customer data for cross-selling by another entity is a different purpose that needs its own assessment and often a different basis.

Step two: test necessity of intra-group data sharing

Ask whether the receiving entity really needs identifiable data. Group reporting might work with aggregated or pseudonymised figures. Shared services may need names and contact details but not full personnel files. Limit access to the teams that perform the service, and remove data fields that are not needed.

Also consider whether the same result could be achieved with fewer transfers, for example by processing in one place under a service agreement instead of copying data to several entities. Record the alternatives and why you chose your approach.

Step three: balance the interests

Weigh the group’s interest against the impact on individuals. Employees and customers generally expect some sharing with related companies for administration, but not unlimited sharing or use for unrelated aims. The closer the shared data is to sensitive information, the stronger the case for restricting it.

Think about the relationship. Staff have less choice than customers, so extra care is needed with HR data. Consider whether people would be surprised to learn who sees their data, and whether a privacy notice would make that clear. Document the safeguards that make the sharing proportionate.

  • Limit fields and access to what the service needs
  • Keep special category data out unless a specific condition applies
  • Use aggregation or pseudonymisation for reporting
  • Restrict secondary uses such as marketing

Transparency about intra-group data sharing

Your notices should tell people that data is shared within the group, identify the categories of recipient and explain the purpose. If the entities are outside the EU, say so and describe the safeguard used. Avoid a bare reference to “our affiliates” without explanation.

Because the basis is legitimate interests, people can object under Article 21. Set up a process so an objection received by one entity reaches the others that hold the data. See legitimate interests and the right to object for how to respond.

International transfers within the group

If group entities sit in different countries, transfers to entities outside the EU or UK need a lawful transfer mechanism such as adequacy, standard contractual clauses or binding corporate rules. Legitimate interests does not cover the transfer itself. Our guides to international data transfers and intra-group transfer impact assessments explain the steps.

Check the laws of the destination country for government access and assess whether supplementary measures are needed, as described in supplementary measures for data transfers.

Agreements and governance for intra-group data sharing

Put an intra-group data sharing agreement in place. It should describe the purposes, data categories, roles, security standards, retention, breach notification, handling of data subject requests and audit rights. Where one entity processes for another, a processor contract is needed, as covered in controller and processor records.

Governance matters as much as paper. Name a group privacy lead, keep a register of flows and review it at least annually. Add the flows to each entity’s record of processing so they stay consistent.

Governance checklist for intra-group data sharing

Keep a short checklist for every new flow: which entities are involved, what the purpose is, what data moves, who can access it, which transfer mechanism applies, what the notice says and when the assessment will be reviewed. Approval should come from the privacy lead before the flow starts, not after. The same checklist helps when you integrate a newly acquired company, since acquisitions are the moment when unassessed flows appear most often.

Common mistakes

Frequent errors include assuming Recital 48 removes the need for an assessment, treating the group as a single controller, sharing more data than the service needs, using shared data for marketing, ignoring transfer rules and failing to update notices when new entities join. Another is forgetting acquisitions: integrating a newly bought company often brings new data flows that nobody has assessed.

Review the assessment when the group structure changes, when a new shared service starts or when the purpose shifts. Our legitimate interests assessment example shows a format you can adapt.

Reviewing the arrangement over time

Set a review date for each arrangement and note who is responsible. Ask whether the purpose, the data or the entities have changed, whether any objections or complaints have arisen and whether access is still limited to the right teams. Record the outcome even when nothing changes, so you can show that the assessment is maintained.

A short worked example

A group with entities in three countries centralises payroll in one shared service centre. The assessment records the purpose, limits data to what payroll needs, excludes health data except where required for statutory pay and restricts access to the payroll team. Reporting to group management uses aggregated figures only.

Notices to employees name the shared service entity and explain the safeguards for transfers. An intra-group agreement is signed, and the flows appear in each entity’s record of processing. The assessment is reviewed annually and after any change to the service. It is documented, proportionate and easy to explain.

A structured assessment

If you want a consistent format to record purpose, necessity, balance and safeguards for each flow, the Legitimate Interests Assessment Report and Workbook provides a report and workbook that follow the three-part test. Whatever tool you use, sound legitimate interests for intra-group data sharing means treating each company as its own controller, sharing the minimum and telling people plainly what happens.

Legitimate interests for intra-group data sharing FAQ

Does Recital 48 let group companies share data freely?

No. It supports a legitimate interest in internal administrative sharing, but each company still needs a purpose and basis, and the necessity and balancing tests still apply.

Is the group one controller?

No. Each legal entity is a separate controller or processor, so sharing between them is a disclosure that needs its own justification.

Do we need an intra-group agreement?

It is strongly advisable. It records purposes, roles, security, retention and how requests are handled, and may be required for processors or joint controllers.

Does legitimate interests cover transfers outside the EU?

No. A transfer mechanism such as adequacy, standard contractual clauses or binding corporate rules is needed in addition to a lawful basis.

Can another group company use the data for marketing?

That is a different purpose that needs its own assessment and often consent under ePrivacy rules. Do not assume the administrative basis covers it.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.