Executive summary

Privacy teams inside multinational groups are increasingly asked to answer a deceptively simple question: is our internal data sharing actually compliant? The honest answer, in most organisations, is that nobody has a complete picture. Data moves between entities for HR, IT, customer support, and product delivery in ways that were never formally mapped, let alone documented under a coherent legal framework.

An Intra-Group Data Transfer Agreement (IGDTA) is the instrument that closes this gap: a single contractual and governance framework that regulates how personal data flows between group entities, allocates privacy roles consistently, and centralises the mechanisms required for cross-border transfers. Done well, it replaces a patchwork of ad-hoc arrangements with one document the organisation can actually stand behind under regulatory scrutiny.

This paper does not attempt to be a step-by-step drafting manual. Instead, it sets out the level of rigour a defensible IGDTA demands, from the structural decisions it requires to the multi-jurisdictional complexity it must absorb and the pitfalls that make so many existing agreements fragile in practice. The aim is to give Privacy leadership a clear bar against which to assess whether their current framework holds up, and what it would take to close the gap.

Download the white paper here