Gdpr Intercompany Agreement Template for Ireland

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Gdpr Intercompany Agreement?

GDPR Intercompany Agreements are essential legal instruments for organizations operating through multiple entities that need to share personal data within their corporate structure. This document is specifically designed for implementation under Irish law, incorporating both EU GDPR requirements and Irish data protection regulations. It becomes necessary when group companies regularly transfer or process personal data of employees, customers, or other data subjects between different entities within the same corporate group. The agreement establishes clear protocols for data handling, defines responsibilities and liabilities, and ensures consistent data protection standards across the organization. It's particularly crucial for companies with Irish operations or those using Ireland as their EU base, as it must align with the Irish Data Protection Commission's requirements and guidelines.

Frequently Asked Questions

Is a GDPR intercompany agreement legally binding under Irish law?

Yes, a properly executed GDPR intercompany agreement is legally binding under Irish law and EU GDPR requirements. The agreement creates enforceable obligations between group companies for data protection compliance and establishes liability frameworks that Irish courts and the Data Protection Commission can enforce.

Can my company transfer personal data between Irish subsidiaries without a GDPR intercompany agreement?

No, transferring personal data between separate legal entities, even within the same corporate group, requires proper legal documentation under GDPR Article 28 and Irish Data Protection Act 2018. Operating without this agreement exposes your company to regulatory action by the Irish Data Protection Commission.

How does a GDPR intercompany agreement differ from standard data processing agreements in Ireland?

A GDPR intercompany agreement is specifically designed for data transfers between related companies and typically includes joint controller provisions, group-wide data governance frameworks, and shared liability arrangements. Standard data processing agreements are used for third-party processors and don't address the unique legal relationships within corporate groups.

How long does it typically take to prepare a GDPR intercompany agreement for Irish companies?

Preparation typically takes 2-4 weeks depending on the complexity of your corporate structure and data flows. This includes mapping data transfers, identifying legal bases, drafting appropriate clauses, and obtaining necessary approvals from each entity's board of directors.

Are there specific Irish Data Protection Commission requirements for intercompany data transfers?

Yes, the Irish DPC requires clear documentation of lawful bases for processing, appropriate technical and organizational measures, and proper records of processing activities. Companies must also ensure data subject rights can be exercised across all group entities and maintain audit trails for international transfers outside the EU/EEA.

Can the Irish Data Protection Commission fine my company for not having an intercompany agreement?

Yes, the Irish DPC can impose significant administrative fines for GDPR violations, including lack of proper documentation for data transfers. Fines can reach up to €20 million or 4% of annual global turnover, whichever is higher, plus potential enforcement orders and reputational damage.

Should my GDPR intercompany agreement include provisions for data transfers to non-EU subsidiaries?

Yes, if your group includes entities outside the EU/EEA, your agreement must include appropriate safeguards such as Standard Contractual Clauses or adequacy decision references. Irish law requires additional documentation and risk assessments for any transfers to countries without adequate data protection frameworks.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Ireland

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Gdpr Intercompany Agreement

A Gdpr Intercompany Agreement is a specialized legal document that governs how personal data is shared and processed between companies within the same corporate group under Irish law. This agreement ensures your organization complies with both EU GDPR requirements and Irish-specific data protection legislation when transferring personal data across your business entities.

When do you need this document?

You need a Gdpr Intercompany Agreement when your corporate group regularly shares personal data between different legal entities. This includes transferring employee records between parent and subsidiary companies, sharing customer databases across regional operations, or consolidating operational data at headquarters level. The agreement is particularly crucial when your group includes entities in different jurisdictions, operates shared services centers, or maintains centralized HR, finance, or customer management systems. Without this agreement, each data transfer could potentially violate GDPR requirements, exposing your organization to regulatory penalties and compliance risks.

Key legal considerations

Your Gdpr Intercompany Agreement must clearly define the roles and responsibilities of each group company as data controllers or processors. The document should specify the categories of personal data being transferred, the purposes for processing, and the legal basis under GDPR for each transfer. Security measures and data retention periods must be explicitly outlined to ensure consistent protection standards across your organization. The agreement should also include breach notification procedures, data subject rights protocols, and liability allocation between group entities. Consider including provisions for international data transfers if your group operates outside the EU, ensuring compliance with adequacy decisions or Standard Contractual Clauses where necessary.

Legal requirements in Ireland

Under Irish law, your Gdpr Intercompany Agreement must comply with the Irish Data Protection Act 2018, which implements GDPR domestically and adds specific national requirements. The Irish Data Protection Commission requires clear documentation of data transfer arrangements and may request copies during regulatory inspections. Your agreement must address the appointment of Data Protection Officers where required and ensure compliance with Irish employment law when processing employee data. The document should reference relevant Irish statutory instruments, including the ePrivacy Regulations 2011 for electronic communications data. Additionally, consider the specific requirements for processing special category data under Irish law, particularly health and biometric information, which may require additional safeguards and explicit consent mechanisms.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it