Data Protection Officer · European Union

DPO for Corporate Groups

A single DPO for a group of undertakings, under Article 37(2) of the GDPR, provided the DPO is easily accessible from each establishment.

Legal framework

The essentials in four points

One DPO for the group

Article 37(2) of the GDPR allows a group of undertakings to appoint a single DPO, provided the DPO is easily accessible from each establishment.

Accessibility in practice

The DPO must be able to communicate efficiently with data subjects and supervisory authorities, in the languages they use, across every establishment.

Lead authority

Groups with a main establishment in the Union deal with a lead supervisory authority for cross-border processing under the one-stop-shop mechanism.

Fines and the group

The Court of Justice has confirmed that GDPR fines are calculated on the turnover of the undertaking in the competition-law sense, which may cover the whole group (Case C-807/21).

Who it is for

  • European groups: with establishments in several Member States that need one DPO accessible in all of them;

  • non-EU groups with EU subsidiaries: that need a coordinated EU data protection function;

  • groups operating in Portugal, Spain and Latin America: that must align the GDPR with Brazil's LGPD and other Ibero-American laws.

How it works

  1. group map: identification of the entities, the data flows between them and the shared services;

  2. conflict-of-interest review: a prior check for each entity;

  3. designation and notification: a designation document for each entity and notification to each competent supervisory authority;

  4. group policies: a common privacy management programme, adapted to each entity;

  5. intra-group agreements: allocation of controller, joint controller and processor roles, data protection clauses and transfer mechanisms;

  6. reporting: a report for each entity and a consolidated report for the group's management body.

Plans

  • Group base: the statutory DPO tasks for all entities, group policies and reports;

  • Group advanced: adds impact assessments, training and coordinated breach management;

  • Group international: adds coordination with other jurisdictions and international data transfers.

Fees are set in a tailored proposal, with a group component and a component per entity.

National offers: Portugal · Spain · Brazil

Other offers: Private organisations · Public bodies · Shared DPO for public bodies · European Union

General information as at October 2026; it does not constitute legal advice.

Frequently asked questions

The DPO in corporate groups

Can one DPO serve every company in the group?

Yes. Article 37(2) of the GDPR allows it, provided the DPO is easily accessible from each establishment, which includes being able to communicate with data subjects and supervisory authorities in the relevant languages.

Does each company still need to notify its supervisory authority?

Yes. Even with a common DPO, each entity that is required to designate one must publish the contact details and notify them to its competent supervisory authority.

How do you coordinate the GDPR with Brazil's LGPD?

We coordinate the European DPO with the Brazilian encarregado, aligning policies, records and international transfers. See the offer for economic groups in Brazil.