Intercompany Data Processing Agreement Template for Germany

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Intercompany Data Processing Agreement?

The Intercompany Data Processing Agreement is essential for corporate groups operating in Germany who need to establish compliant data processing relationships between group entities. This document is required whenever one group company processes personal data on behalf of another group company, ensuring compliance with Article 28 GDPR and German data protection law. It addresses specific requirements under German jurisdiction, including the BDSG, while accounting for the interconnected nature of group operations. The agreement is particularly important in the context of shared services arrangements, IT infrastructure sharing, and centralized data processing operations within corporate groups. It includes provisions for technical and organizational measures, data breach notifications, audit rights, and sub-processing arrangements, all tailored to the German legal framework and intra-group relationships.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Germany

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Intercompany Data Processing Agreement

When your corporate group operates multiple entities in Germany that share or process personal data, you need a comprehensive Intercompany Data Processing Agreement to ensure GDPR compliance. This specialized contract establishes the legal framework for data processing relationships between group companies, clearly defining roles as controllers and processors while meeting Article 28 GDPR requirements and German data protection standards.

When do you need this document?

You need this agreement whenever one group company processes personal data on behalf of another within your corporate structure. Common scenarios include shared IT services where a parent company processes employee data for subsidiaries, centralized HR operations handling personnel records across multiple entities, or when one group company provides customer service functions for related companies. The agreement is also essential for international groups with German entities that need to transfer data between jurisdictions while maintaining GDPR compliance. Any situation involving cross-border data flows within your group, shared databases, or centralized processing operations requires this specialized documentation.

Key legal considerations

Your agreement must clearly define the controller-processor relationship, specify the categories of personal data being processed, and detail the purposes of processing activities. Technical and organizational measures must be documented to ensure data security, including encryption, access controls, and staff training requirements. The contract should address data subject rights procedures, establishing how requests will be handled across group entities. Sub-processing provisions are crucial if additional group companies or third parties will be involved in data handling. You must include data breach notification procedures that comply with both GDPR's 72-hour reporting requirement and internal escalation protocols. Audit rights and compliance monitoring mechanisms ensure ongoing adherence to data protection standards throughout the processing relationship.

Legal requirements in Germany

Under German law, your Intercompany Data Processing Agreement must comply with GDPR Article 28 while incorporating specific BDSG requirements that supplement EU regulations. The Bundesdatenschutzgesetz provides additional obligations for data processing arrangements, particularly regarding employee data protection and special categories of personal data. Your agreement must be governed by German contract law principles under the BGB, ensuring enforceability and proper legal structure. For commercial relationships between group entities, HGB provisions may apply to certain transaction aspects. If your group includes non-EU entities, you must incorporate Standard Contractual Clauses or adequacy decisions to legitimize international data transfers. The agreement should designate data protection responsibilities clearly, often involving your Group Data Protection Officer in oversight roles and compliance monitoring activities.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it