Bay Area Business Lawyers | Primum Law

Data Transfer Agreement

Do I Need a Data Transfer Agreement Between My Company and My Foreign Subsidiary?

Do I Need a Data Transfer Agreement Between My Company and My Foreign Subsidiary?

Your US team pulls a customer record from the CRM. Your London subsidiary’s support team opens the same record an hour later.

Nobody wrote that down anywhere. It just happens, the way it has every day since you opened the second office.

Common ownership does not make that transfer invisible to regulators. The moment personal data crosses a border, even between entities you control, the law treats it as a transfer needing a lawful basis.

“Affiliate” Does Not Mean “Exempt”

Privacy law does not care that your foreign subsidiary is wholly owned by your US parent. GDPR and UK GDPR treat a transfer from an EU or UK entity to a US affiliate the same as a transfer to any unrelated company: it needs a valid legal mechanism. Shared ownership is a corporate fact, not a privacy exemption.

Geography Decides Which Rules Actually Apply

Which privacy regime governs your data flow depends on where the data physically moves, where it is stored, and where the people it describes live, not where your parent is headquartered. The same company can face different rules depending on:

  • Whether employees or customers sit in the EU, UK, California, or elsewhere.
  • Where the receiving entity stores and processes the data.
  • Whether either entity sits in a jurisdiction facing added restrictions, such as the DOJ rule limiting bulk sensitive data transfers to certain countries.

The Mechanism You Pick Has to Match the Actual Flow

If personal data moves from the EU or UK to your US entity, you need a recognized mechanism: Standard Contractual Clauses (SCCs), EU-approved contract terms, or the UK’s International Data Transfer Agreement (IDTA). Both require documenting the transfer, not claiming it happens under a general policy.

One Intercompany Agreement Should Cover the Whole Flow

An intra-group data transfer agreement puts SCC or IDTA terms into one document: what data moves, why, and under what safeguards. Without it, you are relying on informal practice to satisfy a requirement that expects a signed record.

Common Founder Mistakes

  • Assuming a Privacy Policy Covers Intercompany Transfers. Founders write a customer-facing privacy policy and assume it handles everything, including how the parent and subsidiary share data internally. A privacy policy tells the public what you do. It does not create the legal mechanism the transfer itself requires.
  • Not Knowing Where Data Actually Lives. Founders describe their data flow by org chart, not server location. If data collected by the foreign entity sits on US-hosted infrastructure, or vice versa, that is the transfer that matters, not which entity nominally “owns” the record.
  • Treating This as a One-Time Setup Task. Founders draft an intercompany agreement once, usually at incorporation, then never revisit it as the business adds vendors, hires abroad, or new customer geographies. Each new flow needs checking against the agreement, not assumed to already be covered.

10-Minute Self-Check

Before your teams keep moving data across entities, you work through this:

  • Do you know exactly which data moves between your US and foreign entities?
  • Have you identified every country where that data is collected, stored, or accessed?
  • Do you have a signed intercompany agreement covering this specific data flow?
  • Have you confirmed whether SCCs, an IDTA, or another mechanism applies here?
  • Have you checked whether either entity sits in a jurisdiction with added restrictions?
  • Would this agreement hold up if a regulator asked to see it tomorrow?

If you cannot answer yes to all of these, you do not yet have a data transfer agreement that matches how your business actually operates.

Bottom Line

An intercompany data transfer agreement is not paperwork for its own sake. It turns an informal, invisible data flow into something you can defend. The businesses that get caught are not the ones moving data between entities. They are the ones who never wrote it down.

Since Geography Is Half This Problem, Have I Actually Mapped Where My Data Goes?

Download our free Data Mapping Worksheet to identify where personal information is collected, stored, and transferred throughout your business. Mapping your data before updating your privacy documentation helps ensure your policies accurately reflect how your product actually works.

Get the free worksheet: https://primumlaw.com/data-mapping-worksheet/?post_type=page

Scroll to Top