Intercompany Data Processing Agreement Template for Germany
Generate a bespoke document
What is a Intercompany Data Processing Agreement?
The Intercompany Data Processing Agreement is essential for corporate groups operating in Germany who need to establish compliant data processing relationships between group entities. This document is required whenever one group company processes personal data on behalf of another group company, ensuring compliance with Article 28 GDPR and German data protection law. It addresses specific requirements under German jurisdiction, including the BDSG, while accounting for the interconnected nature of group operations. The agreement is particularly important in the context of shared services arrangements, IT infrastructure sharing, and centralized data processing operations within corporate groups. It includes provisions for technical and organizational measures, data breach notifications, audit rights, and sub-processing arrangements, all tailored to the German legal framework and intra-group relationships.
About the Intercompany Data Processing Agreement
When your corporate group operates multiple entities in Germany that share or process personal data, you need a comprehensive Intercompany Data Processing Agreement to ensure GDPR compliance. This specialized contract establishes the legal framework for data processing relationships between group companies, clearly defining roles as controllers and processors while meeting Article 28 GDPR requirements and German data protection standards.
When do you need this document?
You need this agreement whenever one group company processes personal data on behalf of another within your corporate structure. Common scenarios include shared IT services where a parent company processes employee data for subsidiaries, centralized HR operations handling personnel records across multiple entities, or when one group company provides customer service functions for related companies. The agreement is also essential for international groups with German entities that need to transfer data between jurisdictions while maintaining GDPR compliance. Any situation involving cross-border data flows within your group, shared databases, or centralized processing operations requires this specialized documentation.
Key legal considerations
Your agreement must clearly define the controller-processor relationship, specify the categories of personal data being processed, and detail the purposes of processing activities. Technical and organizational measures must be documented to ensure data security, including encryption, access controls, and staff training requirements. The contract should address data subject rights procedures, establishing how requests will be handled across group entities. Sub-processing provisions are crucial if additional group companies or third parties will be involved in data handling. You must include data breach notification procedures that comply with both GDPR's 72-hour reporting requirement and internal escalation protocols. Audit rights and compliance monitoring mechanisms ensure ongoing adherence to data protection standards throughout the processing relationship.
Legal requirements in Germany
Under German law, your Intercompany Data Processing Agreement must comply with GDPR Article 28 while incorporating specific BDSG requirements that supplement EU regulations. The Bundesdatenschutzgesetz provides additional obligations for data processing arrangements, particularly regarding employee data protection and special categories of personal data. Your agreement must be governed by German contract law principles under the BGB, ensuring enforceability and proper legal structure. For commercial relationships between group entities, HGB provisions may apply to certain transaction aspects. If your group includes non-EU entities, you must incorporate Standard Contractual Clauses or adequacy decisions to legitimize international data transfers. The agreement should designate data protection responsibilities clearly, often involving your Group Data Protection Officer in oversight roles and compliance monitoring activities.
GOVERNING LAW
Applicable law
This Intercompany Data Processing Agreement is drafted to comply with Germany law. Key legislation includes:
Bundesdatenschutzgesetz (BDSG): German Federal Data Protection Act - National law supplementing GDPR, providing specific German requirements for data processing and protection
Bürgerliches Gesetzbuch (BGB): German Civil Code - Provides the legal framework for contract formation, validity, and interpretation under German law
Handelsgesetzbuch (HGB): German Commercial Code - Relevant for commercial relationships between companies, including provisions on commercial transactions and business relationships
EU Standard Contractual Clauses (SCCs): If international data transfers are involved, these EU-approved clauses must be considered for transfers outside the EEA
Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG): German Telecommunications and Telemedia Data Protection Act - Relevant if the data processing involves telecommunications or electronic communications services
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it