Data Protection Officer · European Union
A single DPO for a group of undertakings, under Article 37(2) of the GDPR, provided the DPO is easily accessible from each establishment.
Legal framework
Article 37(2) of the GDPR allows a group of undertakings to appoint a single DPO, provided the DPO is easily accessible from each establishment.
The DPO must be able to communicate efficiently with data subjects and supervisory authorities, in the languages they use, across every establishment.
Groups with a main establishment in the Union deal with a lead supervisory authority for cross-border processing under the one-stop-shop mechanism.
The Court of Justice has confirmed that GDPR fines are calculated on the turnover of the undertaking in the competition-law sense, which may cover the whole group (Case C-807/21).
European groups: with establishments in several Member States that need one DPO accessible in all of them;
non-EU groups with EU subsidiaries: that need a coordinated EU data protection function;
groups operating in Portugal, Spain and Latin America: that must align the GDPR with Brazil's LGPD and other Ibero-American laws.
group map: identification of the entities, the data flows between them and the shared services;
conflict-of-interest review: a prior check for each entity;
designation and notification: a designation document for each entity and notification to each competent supervisory authority;
group policies: a common privacy management programme, adapted to each entity;
intra-group agreements: allocation of controller, joint controller and processor roles, data protection clauses and transfer mechanisms;
reporting: a report for each entity and a consolidated report for the group's management body.
Group base: the statutory DPO tasks for all entities, group policies and reports;
Group advanced: adds impact assessments, training and coordinated breach management;
Group international: adds coordination with other jurisdictions and international data transfers.
Fees are set in a tailored proposal, with a group component and a component per entity.
National offers: Portugal · Spain · Brazil
Other offers: Private organisations · Public bodies · Shared DPO for public bodies · European Union
General information as at October 2026; it does not constitute legal advice.
Frequently asked questions
Yes. Article 37(2) of the GDPR allows it, provided the DPO is easily accessible from each establishment, which includes being able to communicate with data subjects and supervisory authorities in the relevant languages.
Yes. Even with a common DPO, each entity that is required to designate one must publish the contact details and notify them to its competent supervisory authority.
We coordinate the European DPO with the Brazilian encarregado, aligning policies, records and international transfers. See the offer for economic groups in Brazil.