Skip to main content
Category: Controller & Processor Roles

Group of Undertakings

Also known as: Corporate group, Group of companies
Simply put

A group of undertakings is a corporate group made up of a controlling undertaking (typically a parent company) and the undertakings it controls (such as subsidiaries). In practical terms, this concept recognises that related businesses within the same corporate structure may share certain interests, including in some circumstances a basis for sharing personal data internally. The precise boundaries of the group depend on which entity holds a controlling or dominant influence over the others.

Formal definition

Under the GDPR, a 'group of undertakings' comprises a controlling undertaking together with its controlled undertakings, where the controlling undertaking is generally the entity able to exert a dominant influence over the others, for example by virtue of ownership, financial participation, or the rules governing it (see Recital 37). An 'undertaking' in this context is understood to mean any entity engaged in economic activity, regardless of its legal status or method of financing, a formulation drawn from EU competition-law concepts and applied by regulators including in the fining context (see ICO guidance, Source 1). The concept is significant because, per Recital 48, controllers forming part of a group of undertakings may have a legitimate interest in transmitting personal data within the group for internal administrative purposes; however, this is a recital-based interpretive aid rather than an operative obligation, and any intra-group transfer must still satisfy an appropriate Article 6 lawful basis (and, where special category data under Article 9 is involved, an additional Article 9 condition). Reliance on legitimate interests in this scenario remains subject to a case-by-case balancing assessment and is not automatic. Note that the term should be distinguished from the separate concept of 'undertaking' used when calculating administrative fines by reference to group-wide turnover; readers should verify current article references, any UK GDPR divergence, and applicable regulatory guidance against the official text.

Why it matters

The concept of a group of undertakings matters because modern businesses frequently operate through networks of parent companies and subsidiaries that share systems, personnel, and administrative functions. GDPR recognises this reality: under Recital 48, controllers that form part of a group of undertakings may have a legitimate interest in transmitting personal data within the group for internal administrative purposes. This offers a practical starting point for justifying certain intra-group data flows, such as centralised HR, IT, or finance operations. However, it is important to stress that Recital 48 is an interpretive aid, not a standalone permission, and any intra-group transfer must still be supported by an appropriate Article 6 lawful basis, with an additional Article 9 condition where special category data is involved.

The concept also carries weight in the fining context, though in a distinct sense. Regulators, including the ICO, apply an 'undertaking' definition drawn from EU competition-law concepts, treating an undertaking as any entity engaged in economic activity regardless of its legal status or method of financing. This can influence how group-wide turnover is assessed when calculating administrative fines. Organisations should be careful not to conflate the 'group of undertakings' concept relevant to intra-group data sharing with the separate 'undertaking' concept used for fine calculation, as they serve different purposes.

Because reliance on legitimate interests for intra-group transfers is subject to a case-by-case balancing assessment and is not automatic, and because the precise boundaries of a group depend on which entity exercises a controlling or dominant influence, this is an area where organisations should document their reasoning carefully rather than assume group membership alone resolves lawfulness. Readers should also verify current article references and any UK GDPR divergence against the official text.

Who it's relevant to

Multinational and Corporate Groups
Organisations structured as parent companies with subsidiaries need to understand this concept when designing intra-group data sharing, such as centralised HR, IT, or administrative functions. Recital 48 may support a legitimate interest in internal transmission, but each transfer must still satisfy an Article 6 basis and, where applicable, an Article 9 condition, subject to a case-by-case balancing assessment.
Data Protection Officers and Compliance Leads
DPOs and compliance teams should map which entity holds controlling or dominant influence within the group and document the lawful basis for each intra-group flow. They should be careful not to treat group membership as automatically resolving lawfulness, and should distinguish the intra-group sharing concept from the 'undertaking' concept used in fine calculation.
Privacy and In-House Counsel
Lawyers advising on corporate structures need to distinguish the 'group of undertakings' definition used for intra-group data sharing (Recitals 37 and 48) from the competition-law-derived 'undertaking' concept applied by regulators such as the ICO when assessing group-wide turnover for administrative fines. They should verify current article references and any UK GDPR divergence against the official text.
Engineers and System Architects
Those building data flows across affiliated entities should understand that a shared corporate structure does not, on its own, make cross-entity personal data transfers lawful. Technical designs should reflect the documented lawful basis and any balancing assessment reached by the compliance function for each internal transfer.

Inside Group of Undertakings

Controlling Undertaking
Under the GDPR, a group of undertakings consists of a controlling undertaking and its controlled undertakings. The controlling undertaking is the entity that exercises a dominant influence over the others, typically by virtue of ownership, financial participation, or the rules governing it.
Controlled Undertakings
The subsidiary or affiliated entities over which the controlling undertaking exercises dominant influence. Together with the controlling undertaking, they form the group. Each entity generally retains its own legal personality and may act as controller or processor in its own right.
Dominant Influence
The organising criterion for the group concept, generally arising from ownership, financial participation, or governance rules. The precise assessment can be fact-specific, and the boundary of what constitutes dominant influence may need to be evaluated case by case.
Intra-Group Processing and Legitimate Interests
GDPR recitals recognise that a group may have a legitimate interest in transmitting personal data within the group for internal administrative purposes, including the processing of clients' or employees' personal data. This is a possible basis to consider, not an automatic authorisation, and remains subject to the balancing assessment required for the legitimate interests basis under Article 6.
Distinction from Related Concepts
A group of undertakings is a defined structural concept and should not be conflated with a 'joint controller' arrangement, a controller-processor relationship, or a Binding Corporate Rules mechanism. Group membership does not by itself determine the controller or processor role of any given entity, nor does it lawfully authorise international transfers without an appropriate transfer tool.

Common questions

Answers to the questions practitioners most commonly ask about Group of Undertakings.

Does membership in a group of undertakings automatically allow personal data to flow freely between the companies in the group?
No. Being part of a group of undertakings does not create an automatic right to share personal data internally. Each intra-group disclosure or transfer is still a processing operation that requires an appropriate legal basis under Article 6 (and, for special category data, an additional condition under Article 9). GDPR does acknowledge in a recital that controllers within a group may have a legitimate interest in transmitting personal data for internal administrative purposes, but this is a factor to weigh in a legitimate interests assessment, not a standalone authorization. The position should be assessed case by case, and other requirements such as transparency, purpose limitation, and cross-border transfer rules still apply.
Is a group of undertakings treated as a single controller so that only one entity is responsible for compliance across the group?
Generally no. GDPR does not treat a corporate group as a single legal person or a single controller by default. Each undertaking is typically assessed on its own to determine whether it acts as a controller, joint controller, or processor for a given processing activity. Group companies may choose to arrange joint controllership or a controller-processor relationship among themselves, but those roles must be established on the facts and documented appropriately. Responsibility and accountability are allocated according to the actual role each entity plays, not according to group membership as such.
How does the concept of a group of undertakings relate to intra-group data sharing arrangements?
Where companies within a group share personal data, they should first identify each entity's role for the specific processing (controller, joint controller, or processor) and then put in place the corresponding governance. This may include an Article 28 data processing agreement where one entity processes on behalf of another, a joint controller arrangement where they jointly determine purposes and means, or documented legitimate interests assessments where that is the legal basis relied on. The appropriate instrument depends on the facts of the arrangement, and organisations should verify their approach against the current regulatory guidance applicable to them.
Can a group rely on Binding Corporate Rules because it is a group of undertakings?
Binding Corporate Rules are a transfer mechanism designed for use within a group of undertakings or a group of enterprises engaged in a joint economic activity, but they are not automatic. They must be drawn up, submitted, and approved through the relevant competent supervisory authority process before they can be relied upon. Group membership makes an organisation eligible to pursue BCRs, but does not itself constitute an approved transfer tool. Organisations considering this route should confirm current approval requirements and timelines with the relevant authority.
Does having a group structure affect how a Data Protection Officer or DPO function can be organised?
A group of undertakings may in appropriate circumstances appoint a single DPO, provided that the DPO is easily accessible from each establishment. Whether a single DPO is sufficient depends on the structure, the nature of the processing, and accessibility in practice. This does not remove the underlying obligation on each entity to assess whether a DPO is required for its own activities, and organisations should evaluate accessibility and resourcing rather than assume a single appointment satisfies every entity's needs.
When documenting group processing, how should roles and responsibilities be recorded across the entities?
It is generally advisable to map the processing activities across the group, identify for each activity which entity determines purposes and means and which acts on another's behalf, and record the corresponding legal basis and role. This mapping supports records of processing, informs which agreements are needed between entities, and clarifies accountability. Because roles can differ from one processing activity to another even between the same two companies, documentation should be activity-specific rather than assigning a single fixed role to each entity for all purposes.

Common misconceptions

Companies within the same group can share personal data freely because they are one organisation.
Each undertaking in a group generally retains separate legal personality and its own data protection responsibilities. Intra-group sharing still requires a valid Article 6 legal basis (and an Article 9 condition for special category data). The GDPR recitals acknowledge a possible legitimate interest in internal administrative transfers, but this is subject to a balancing assessment rather than being automatic.
Belonging to a group of undertakings means all entities are treated as a single controller.
Group membership does not itself allocate controller or processor status. Each entity's role must be assessed on the facts of who determines the purposes and means of processing. Depending on the arrangement, entities may be separate controllers, joint controllers, or processors.
Being in a group of undertakings permits personal data to flow between group members located outside the EEA.
The group concept does not authorise international transfers. Transfers to third countries still require an appropriate transfer mechanism (such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules), and these tools and any supplementary measures evolve over time and should be verified against current guidance.

Best practices

Map the group structure to identify which entity is the controlling undertaking and which are controlled undertakings, and document the basis on which dominant influence is established.
Assess and record the controller, joint controller, or processor role of each group entity separately, rather than assuming a single unified status across the group.
Identify and document a specific Article 6 legal basis for each intra-group processing activity, and where relying on legitimate interests for internal administrative transfers, carry out and retain the balancing assessment.
Apply an additional Article 9 condition where special category data is shared within the group, and confirm it before any such processing.
Where personal data moves to group entities outside the EEA, put in place an appropriate transfer mechanism and review it periodically, as transfer tools and supplementary measures evolve.
Verify any GDPR article references, recital reliance, and current transfer requirements against the official text and up-to-date regulatory guidance before operationalising group data-sharing arrangements.