Intra-Group Transfers (Data Transfer Agreement)
How a group of undertakings maps its many internal data transfers onto a single framework agreement (intra-group data transfer agreement): processing on behalf of a controller, joint controllership, separate controllers and transfers to third countries by way of standard contractual clauses, steered by an allocation clause and a continuously maintained Data Transfer Directory.
Within a group of undertakings, personal data flows constantly between the individual companies: through matrix structures, shared services, central IT systems and group-wide functions. Depending on the allocation of roles, each of these data flows requires its own contract, and some of them go to unsafe third countries. Instead of concluding a separate contract for every constellation, all of this can be bundled into a single framework agreement, the intra-group data transfer agreement.
Key takeaways
- A framework agreement bundles all contracts required within the group: processing on behalf of a controller (Article 28 GDPR), joint controllership (Article 26 GDPR), transfers between separate controllers and transfers to third countries by way of standard contractual clauses (Article 46 GDPR).
- An allocation clause determines which contract applies in which constellation, depending on the role and the country of establishment of the exporter and the recipient.
- A Data Transfer Directory, kept as a continuously maintained register, documents the mandatory details for every data transfer and at the same time populates the annexes to the incorporated clauses.
- The accession and withdrawal of companies, as well as amendments, are handled through simplified mechanisms, without having to conclude the entire agreement afresh.
- The transfer impact assessment and the substantive assessment of lawfulness are not covered; both remain to be carried out separately.
1. Background and objective
In data protection terms, a corporate group consists of many independent controllers. Between them there are numerous and constantly changing transfer scenarios (new tools, restructurings, acquisitions and disposals of shareholdings) for which, depending on the allocation of roles, different contracts are required. The purpose of the framework agreement is to implement the contracts prescribed by the GDPR for intra-group transfers in a uniform, flexible and easily adaptable manner:
- data processing agreements under Article 28 GDPR,
- standard contractual clauses for transfers to unsafe third countries under Articles 44 et seq. GDPR,
- arrangements between joint controllers under Article 26 GDPR,
- optionally, an agreement between separate controllers within the EU in order to secure a legal basis for the transfer (for example the legitimate interest under Article 6(1)(f) GDPR).
2. The contractual structure at a glance
The framework agreement consists of a general part, several annexes containing model clauses, an allocation clause and the Data Transfer Directory.
Each annex contains one ready-made set of clauses. Depending on the constellation, the allocation clause refers to the appropriate annex. The Data Transfer Directory supplies the transfer-related details that would otherwise have to be completed in the annexes to the individual contracts.
3. The allocation clause
The allocation clause assigns the applicable instrument to each transfer constellation. What is decisive are the role (controller, processor, joint controllers) and the country of establishment (EU/EEA or third country) of the data exporter and the data recipient.
| Exporter | Recipient | Applicable instrument |
|---|---|---|
| Controller (EU) | Processor (EU) | Data processing agreement (Article 28 GDPR) |
| Joint controllers (EU) | Joint controllers (EU) | Joint controller arrangement (Article 26 GDPR) |
| Separate controller (EU) | Separate controller (EU) | Separate controller agreement (optional) |
| Controller (EU) | Controller (third country) | Standard contractual clauses, Module 1 |
| Controller (EU) | Processor (third country) | Standard contractual clauses, Module 2 |
| Processor (EU) | Sub-processor (third country) | Standard contractual clauses, Module 3 |
| Processor (EU) | Controller (third country) | Standard contractual clauses, Module 4 |
The allocation of the modules corresponds to the general module structure of the standard contractual clauses.
4. The Data Transfer Directory
The Data Transfer Directory is a continuously maintained register of all intra-group transfer scenarios. It contains the details that would otherwise have to be stated, on a case-by-case basis, in the annexes to the data processing agreement, the standard contractual clauses or the joint controller arrangement, and it completes those annexes at the same time.
4.1 Mandatory details for each transfer
For each transfer scenario (for example a process or a tool), the following in particular have to be recorded:
- which company transfers the data and which company receives it,
- the role of the transferring and of the receiving company (controller, processor, joint controllers),
- the categories of data subjects and of transferred data, including special categories of data,
- the nature and purposes of the processing,
- the frequency (one-off or continuous) and the storage period or the criteria for determining it,
- the sub-processors engaged and the technical and organizational measures.
4.2 Form and maintenance
The directory can be kept electronically, for example in a data protection management tool, and may where appropriate form part of the records of processing activities. It is maintained centrally by the parent company; the participating companies have access to it. Typical scenarios are the matrix organization, HR and CRM software, the intranet and the employee directory, central communication and project tools, and shared services.
5. Transfers to third countries under the framework agreement
For transfers to a recipient outside the EU/EEA, the framework agreement incorporates the standard contractual clauses. In practice this is achieved through the following provisions:
- Incorporation by reference. The standard contractual clauses are incorporated into the framework agreement by reference and, upon its entry into force, are treated as concluded between the parties concerned, without reproducing the full text.
- Annexes taken from the schedules. The list of parties and the description of the transfer taken from the directory serve as the corresponding annexes to the clauses; the security measures form the annex on measures.
- Optional clauses. It is customary to select the docking clause (accession of further parties) and, for Modules 2 and 3, the general written authorization of sub-processors with a period for prior notification (for example 30 days).
- The supervisory authority, the choice of law and the place of jurisdiction are determined uniformly.
- Survival clause. If the standard contractual clauses are amended, replaced or declared invalid, the parties undertake to move in good faith to an updated version or to another appropriate transfer instrument.
- Country-specific adaptations. For recipients that are subject to additional national law (such as UK law), a supplementary addendum is added.
6. How the framework agreement operates
So that the framework agreement can grow with the group, it contains a number of procedural rules:
- Accession and withdrawal. New companies accede by way of a declaration of accession; withdrawing companies cease to be parties but remain responsible for the obligations that have arisen up to that point.
- Simplified amendment. Subject to narrow conditions, the parent company may amend the agreement unilaterally (for example where new standard contractual clauses are adopted), with prior notice and a right of objection for the companies concerned within a set period (for example six weeks).
- Form of conclusion. Conclusion in electronic form is sufficient; the companies send a signed copy to the parent company or use an e-signing procedure.
- Term and termination, together with fallback provisions for technical and organizational measures and erasure periods, round off the framework.
7. Limits of the framework agreement
The framework agreement provides the contractual safeguards, but it does not replace the remaining obligations. In particular, the following fall outside its scope:
- the transfer impact assessment for every transfer to a third country, which has to be carried out separately,
- the substantive assessment of the lawfulness of each transfer (legal basis under Article 6 GDPR, purpose limitation, storage periods, transparency, works agreements),
- having regard to local data protection laws outside the company's own country of establishment.
Binding Corporate Rules are a prestigious but burdensome alternative for intra-group transfers to third countries. An intra-group framework agreement based on the standard contractual clauses achieves the same result with less effort (see Binding Corporate Rules).
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Binding Corporate Rules (BCR)
Binding Corporate Rules as an appropriate safeguard for intra-group transfers to third countries under Article 47 GDPR: binding internal data protection rules, scope, approval by the supervisory authority, minimum content and liability, as well as the relationship to the Schrems II case law. Distinction between controller and processor BCR, reach and limits.
Automated individual decision-making (Article 22 GDPR)
General prohibition, statutory criteria and exceptions of automated individual decision-making under Article 22 GDPR: solely automated processing, profiling and scoring, safeguards under Article 22(3), sensitive data and the relationship to the AI Act.