Gdpr Intercompany Agreement Template for Ireland
Generate a bespoke document
What is a Gdpr Intercompany Agreement?
GDPR Intercompany Agreements are essential legal instruments for organizations operating through multiple entities that need to share personal data within their corporate structure. This document is specifically designed for implementation under Irish law, incorporating both EU GDPR requirements and Irish data protection regulations. It becomes necessary when group companies regularly transfer or process personal data of employees, customers, or other data subjects between different entities within the same corporate group. The agreement establishes clear protocols for data handling, defines responsibilities and liabilities, and ensures consistent data protection standards across the organization. It's particularly crucial for companies with Irish operations or those using Ireland as their EU base, as it must align with the Irish Data Protection Commission's requirements and guidelines.
Frequently Asked Questions
Is a GDPR intercompany agreement legally binding under Irish law?
Yes, a properly executed GDPR intercompany agreement is legally binding under Irish law and EU GDPR requirements. The agreement creates enforceable obligations between group companies for data protection compliance and establishes liability frameworks that Irish courts and the Data Protection Commission can enforce.
Can my company transfer personal data between Irish subsidiaries without a GDPR intercompany agreement?
No, transferring personal data between separate legal entities, even within the same corporate group, requires proper legal documentation under GDPR Article 28 and Irish Data Protection Act 2018. Operating without this agreement exposes your company to regulatory action by the Irish Data Protection Commission.
How does a GDPR intercompany agreement differ from standard data processing agreements in Ireland?
A GDPR intercompany agreement is specifically designed for data transfers between related companies and typically includes joint controller provisions, group-wide data governance frameworks, and shared liability arrangements. Standard data processing agreements are used for third-party processors and don't address the unique legal relationships within corporate groups.
How long does it typically take to prepare a GDPR intercompany agreement for Irish companies?
Preparation typically takes 2-4 weeks depending on the complexity of your corporate structure and data flows. This includes mapping data transfers, identifying legal bases, drafting appropriate clauses, and obtaining necessary approvals from each entity's board of directors.
Are there specific Irish Data Protection Commission requirements for intercompany data transfers?
Yes, the Irish DPC requires clear documentation of lawful bases for processing, appropriate technical and organizational measures, and proper records of processing activities. Companies must also ensure data subject rights can be exercised across all group entities and maintain audit trails for international transfers outside the EU/EEA.
Can the Irish Data Protection Commission fine my company for not having an intercompany agreement?
Yes, the Irish DPC can impose significant administrative fines for GDPR violations, including lack of proper documentation for data transfers. Fines can reach up to €20 million or 4% of annual global turnover, whichever is higher, plus potential enforcement orders and reputational damage.
Should my GDPR intercompany agreement include provisions for data transfers to non-EU subsidiaries?
Yes, if your group includes entities outside the EU/EEA, your agreement must include appropriate safeguards such as Standard Contractual Clauses or adequacy decision references. Irish law requires additional documentation and risk assessments for any transfers to countries without adequate data protection frameworks.
About the Gdpr Intercompany Agreement
A Gdpr Intercompany Agreement is a specialized legal document that governs how personal data is shared and processed between companies within the same corporate group under Irish law. This agreement ensures your organization complies with both EU GDPR requirements and Irish-specific data protection legislation when transferring personal data across your business entities.
When do you need this document?
You need a Gdpr Intercompany Agreement when your corporate group regularly shares personal data between different legal entities. This includes transferring employee records between parent and subsidiary companies, sharing customer databases across regional operations, or consolidating operational data at headquarters level. The agreement is particularly crucial when your group includes entities in different jurisdictions, operates shared services centers, or maintains centralized HR, finance, or customer management systems. Without this agreement, each data transfer could potentially violate GDPR requirements, exposing your organization to regulatory penalties and compliance risks.
Key legal considerations
Your Gdpr Intercompany Agreement must clearly define the roles and responsibilities of each group company as data controllers or processors. The document should specify the categories of personal data being transferred, the purposes for processing, and the legal basis under GDPR for each transfer. Security measures and data retention periods must be explicitly outlined to ensure consistent protection standards across your organization. The agreement should also include breach notification procedures, data subject rights protocols, and liability allocation between group entities. Consider including provisions for international data transfers if your group operates outside the EU, ensuring compliance with adequacy decisions or Standard Contractual Clauses where necessary.
Legal requirements in Ireland
Under Irish law, your Gdpr Intercompany Agreement must comply with the Irish Data Protection Act 2018, which implements GDPR domestically and adds specific national requirements. The Irish Data Protection Commission requires clear documentation of data transfer arrangements and may request copies during regulatory inspections. Your agreement must address the appointment of Data Protection Officers where required and ensure compliance with Irish employment law when processing employee data. The document should reference relevant Irish statutory instruments, including the ePrivacy Regulations 2011 for electronic communications data. Additionally, consider the specific requirements for processing special category data under Irish law, particularly health and biometric information, which may require additional safeguards and explicit consent mechanisms.
GOVERNING LAW
Applicable law
This Gdpr Intercompany Agreement is drafted to comply with Ireland law. Key legislation includes:
Irish Data Protection Act 2018: National legislation implementing GDPR in Ireland and providing additional local requirements for data processing
EU Standard Contractual Clauses (SCCs): European Commission-approved contractual clauses for international data transfers, essential for transfers outside the EU/EEA
Data Protection Commission (DPC) Guidelines: Guidelines and recommendations from the Irish Data Protection Commission regarding data transfers and processing
ePrivacy Regulations 2011 (S.I. No. 336 of 2011): Irish regulations concerning electronic communications and data privacy, relevant for digital data transfers
European Union (Cross-Border Data Processing) Regulations 2021: Irish regulations specifically addressing cross-border data processing activities
Article 29 Working Party Guidelines (now EDPB Guidelines): Essential interpretative guidance on GDPR implementation and international data transfers
Binding Corporate Rules (BCRs) Framework: EU-approved mechanism for multinational companies to transfer data within their corporate group
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it