Intra Group Data Transfer Agreement Template for England and Wales

Generate a bespoke document

What is a Intra Group Data Transfer Agreement?

The Intra Group Data Transfer Agreement is essential for corporate groups operating in or from the UK that need to transfer personal data between group entities. This agreement becomes necessary when organizations need to ensure compliance with UK GDPR and the Data Protection Act 2018, particularly for systematic data sharing within the group structure. It provides a comprehensive framework for data protection, covering aspects such as transfer mechanisms, security measures, and data subject rights, while ensuring accountability and consistent standards across the group.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Intra Group Data Transfer Agreement

An Intra Group Data Transfer Agreement is a specialized legal contract that governs how corporate groups transfer personal data between their entities while maintaining compliance with UK data protection laws. Under England and Wales jurisdiction, this agreement ensures your organization meets the stringent requirements of UK GDPR and the Data Protection Act 2018 when sharing personal data across group companies, subsidiaries, and regional offices.

When do you need this document?

You need an Intra Group Data Transfer Agreement when your corporate group regularly shares personal data between different legal entities within your organization. This becomes essential when your parent company needs to transfer employee records to subsidiaries, when regional headquarters process customer data on behalf of local entities, or when you consolidate data processing activities across multiple group companies. The agreement is particularly crucial if your group operates across different jurisdictions, as it provides a consistent framework for data protection compliance. You'll also need this agreement when conducting due diligence activities, implementing group-wide systems, or centralizing HR, finance, or customer service functions that involve personal data processing.

Key legal considerations

The agreement must establish clear legal bases for data transfers under UK GDPR, whether through legitimate interests, contractual necessity, or consent. You need to define the roles and responsibilities of each group entity, specifying which entities act as data controllers versus data processors for different types of personal data. Security measures and technical safeguards must be detailed to protect data during transfer and storage. The agreement should address data subject rights, including how individuals can exercise their rights to access, rectify, or delete their personal data across the group. Include provisions for data breach notification procedures, ensuring compliance with the 72-hour reporting requirement under UK GDPR. Consider implementing Standard Contractual Clauses if your group includes entities outside the UK, particularly when transferring data to countries without adequacy decisions.

Legal requirements in England and Wales

Under England and Wales law, your Intra Group Data Transfer Agreement must comply with UK GDPR principles, ensuring data is processed lawfully, fairly, and transparently. The Data Protection Act 2018 requires specific safeguards for sensitive personal data categories, including health records and criminal conviction data. You must conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities within the group. The agreement must designate a Data Protection Officer if required under UK GDPR thresholds. Include provisions for supervisory authority cooperation, as the Information Commissioner's Office (ICO) has jurisdiction over UK-based processing activities. Ensure the agreement addresses international transfer mechanisms, particularly post-Brexit requirements for transfers to EU entities, which may require adequacy decisions or appropriate safeguards under Standard Contractual Clauses or Binding Corporate Rules.

GOVERNING LAW

Applicable law

This Intra Group Data Transfer Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The United Kingdom General Data Protection Regulation - the primary legislation governing data protection in the UK post-Brexit, setting out the key principles, rights and obligations for processing personal data

Data Protection Act 2018: The UK's implementation of data protection laws, working alongside and supplementing the UK GDPR, providing specific data protection requirements and derogations for the UK context

PECR 2003: Privacy and Electronic Communications Regulations - specific rules for electronic communications, including electronic marketing and cookies

EU GDPR: European Union General Data Protection Regulation - relevant when EU entities are involved in the group or when data transfers include EU territories

Standard Contractual Clauses: Pre-approved contractual terms for international data transfers, ensuring adequate protection when transferring personal data outside the UK/EEA

Binding Corporate Rules: Internal codes of conduct for multinational companies, allowing international data transfers within the same corporate group

Adequacy Decisions: Official determinations by relevant authorities that certain countries provide adequate level of data protection, facilitating easier data transfers

ICO Guidance: Official guidance and codes of practice from the Information Commissioner's Office, providing practical interpretation of data protection requirements

Employment Law: Relevant employment legislation that intersects with data protection when handling employee personal data within the group

Companies Act 2006: Primary legislation governing company operations in the UK, relevant for corporate governance aspects of intra-group arrangements

Data Transfer Mechanisms: Specific procedures and safeguards required for transferring data between group entities, including technical and organizational measures

Data Protection Principles: Core principles including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality

Data Subject Rights: Rights granted to individuals whose data is processed, including access, rectification, erasure, portability, and objection rights

Security Measures: Technical and organizational security requirements for protecting personal data during processing and transfer

Breach Notification: Procedures and timelines for reporting data breaches to authorities and affected individuals

Accountability Framework: Requirements for demonstrating compliance, including documentation, impact assessments, and appointment of responsible personnel

Record Keeping: Obligations to maintain detailed records of processing activities, data transfers, and compliance measures

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.