Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Intra-group data transfers between group companies with transfer mechanism and assessment

Intra-Group Transfers: Transfer Impact Assessment 2026

Intra-group data transfers are the transfers most often assumed to be safe. The recipient is a sister company or a parent, the same policies apply and staff share an email domain, so many groups treat them as internal moves rather than transfers. Under the GDPR, however, companies in the same group are separate legal entities. Sending personal data from an EU company to an affiliate in a country without an adequacy decision needs a transfer mechanism and, in most cases, an assessment of the destination’s laws and practice.

This guide explains why intra-group data transfers are covered by the rules, which mechanisms fit, how to run a transfer impact assessment efficiently for a group and how to keep the records.

Why intra-group data transfers are covered

Chapter V of the GDPR regulates transfers of personal data to third countries and international organisations. It does not exempt transfers within a corporate group. The regulation recognises groups in some places, for instance by allowing binding corporate rules and by referring to groups of undertakings in Article 4, but each company remains a controller or processor in its own right. Our overview of international data transfers sets out the framework, and the CJEU’s Schrems II judgment of 2020 confirmed that transfers based on safeguards such as standard contractual clauses require an assessment of whether the level of protection is essentially equivalent in practice.

The result is that a group that shares HR data, customer records or system logs with affiliates in third countries has the same duties as one that shares them with an outside supplier.

Mechanisms for intra-group data transfers

MechanismHow it worksPoints to watch
Adequacy decisionThe destination country or scheme has been recognised by the CommissionCheck scope; some decisions cover only certified entities or certain sectors
Standard contractual clausesGroup companies sign the Commission’s clausesChoose the right module; needs a transfer assessment; many-to-many structures need care
Binding corporate rulesGroup-wide rules approved by a supervisory authorityLong approval process; still requires assessment of local laws
DerogationsLimited exceptions in Article 49Not for routine or repeated transfers

Many groups use standard clauses because they are quick to adopt. Groups with extensive global flows may invest in binding corporate rules, which give one framework for all affiliates. Whichever you choose, the same assessment duty applies.

Free transfer impact assessment

Can this transfer of personal data go ahead?

Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.

Start the free TIA →  or  View premium report sample

Binding corporate rules and assessments

Binding corporate rules are approved by the competent supervisory authority under Article 47 and are legally binding within the group. The EDPB has made clear in its guidance on transfers that supplementary measures and an assessment of third-country law are relevant to transfers under binding corporate rules as well as to those under standard clauses. So approval of rules does not remove the need to consider local laws and practices where the recipient affiliate operates.

Running a transfer impact assessment across a group

A group with dozens of affiliates cannot run dozens of unrelated assessments. Organise the work so that it is done once at the right level.

  1. Map the flows. List which entities send which categories of data to which affiliates, for what purposes, and through which systems.
  2. Group by destination. Country analysis is the heavy part, and it can be done once per country and reused for every flow to that country.
  3. Assess flow by flow. For each flow, consider the data, the affiliate’s role and the likelihood that public authorities would seek it. Our guide to the transfer impact assessment of third country laws shows the method.
  4. Decide measures. Where laws create a concern, select supplementary measures such as encryption with keys held in the EEA, pseudonymisation or access limits; see supplementary measures for data transfers.
  5. Record centrally. Keep a group register that each exporting entity can rely on and adapt.

Who is responsible in a group

The exporter, meaning the group company that sends the data from the EEA, is responsible for its own transfers. The group privacy office can coordinate, produce the country analysis and maintain the register, but each exporting entity must be able to show that it has assessed and approved its own flows. Document this split in the group privacy policy. Where the parent controls the systems, agree how the local entity obtains the information it needs from the parent.

Common intra-group flows to check

Certain flows recur in nearly every group. HR data flows to a global HR platform run from a headquarters country. Customer data goes to shared service centres for support, finance or analytics. Log and security data is sent to a central security operations team, often in another region. Group-wide directories, email systems and collaboration tools store personal data in a chosen location and may be accessed by affiliates worldwide. Add each to the map, including remote access by staff in other countries to data stored in the EEA.

A hypothetical example of intra-group data transfers

The following is a hypothetical example invented for illustration. A European manufacturer with subsidiaries in eight countries maps its flows and finds twelve, including HR data to its parent in one Asian country, customer support data to a shared service centre in another and security logs to a central team in a third. Two of the destinations benefit from an adequacy decision. For the rest the group signs standard contractual clauses using the appropriate modules and adopts a group-wide transfer policy.

The privacy office prepares country analyses for the three remaining destinations, and each exporting entity reviews and adopts them for its own flows. For HR data, the group adds pseudonymised identifiers and role-based access limits. The register lists each flow, mechanism, assessment reference and review date, and the local privacy contacts confirm the entries. When the group later opens a new affiliate in one of the assessed countries, it reuses the country analysis and only assesses the new flows.

Contracts and governance for the group

Standard clauses signed between dozens of affiliates can become unmanageable if each pair signs separately. Many groups use an intra-group data transfer agreement with an accession mechanism, so that new affiliates sign once and become bound to all others, and so that the Commission’s clauses are incorporated by reference with the correct modules for each relationship. Keep a controlled list of signatories and dates, and make the current agreement available to every exporting entity.

Governance matters as much as paperwork. Appoint a privacy contact in each affiliate, define escalation for government access requests, and require affiliates to notify the exporter promptly if a law changes or they are unable to comply. Test the process once with a scenario, so people know what to do when a request arrives.

Common mistakes with intra-group data transfers

Common weaknesses include assuming that group membership removes the need for a mechanism, using standard clauses without an assessment, relying on out-of-date group agreements, ignoring remote access, treating binding rules as a substitute for local law review, unclear allocation of responsibility, missing records at the exporting entity, and failing to update after reorganisations or new affiliates. Another is putting all documentation with the parent, so the local entity cannot produce it on request.

Keeping the group assessment current

Review each country analysis at least annually and when the law changes, a significant ruling occurs or an affiliate reports a government access request. Update the register when systems move, affiliates are added or sold, or flows change. Maintain a routine so that local privacy contacts confirm their flows every year. If a country becomes unsuitable, define in advance what happens: suspend the flow, add measures or move the data.

Linking to the RoPA

Each exporting entity should reflect these flows in its record of processing, naming the affiliate, the country and the mechanism. See our guide to RoPA international transfers for how to write the entries. The register and the RoPA should agree, so review them together.

Templates for intra-group data transfers

A consistent report helps every entity document its flows in the same way and lets the group office review them together. The Transfer Impact Assessment Report and Workbook provides a report and workbook for documenting transfers, tools and legal analysis. For the underlying rules, the EDPB publishes its recommendations on supplementary measures. Whichever format you use, keep the same headings across all entities.

Intra-group data transfers FAQ

Do intra-group data transfers need a transfer mechanism?

Yes. Group companies are separate legal entities, so transfers to affiliates in third countries without an adequacy decision need a mechanism such as standard clauses or binding corporate rules.

Do binding corporate rules remove the need for a TIA?

No. The EDPB guidance indicates that the assessment of third-country law and the need for supplementary measures also apply to transfers under binding corporate rules.

Can one assessment cover the whole group?

The country analysis can be shared, but each exporting entity must assess its own flows and approve them, taking account of the data and the affiliate’s role.

Are remote access and shared systems transfers?

Access from a third country to data stored in the EEA can be a transfer. Include it in the map, along with shared group platforms.

How often should we review the assessments?

At least annually and when a relevant law, ruling, flow or affiliate changes. Keep the group register up to date.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.