The classic trap
Recital 37 defines the notion of group of undertakings which feeds several operational mechanisms of the GDPR: shared DPO (Art. 37(2)), intra-group legitimate interest (recital 48), binding corporate rules (Art. 47), one-stop-shop. The CNPD and CNIL regularly sanction Luxembourg holdings that claim group membership to share HR, client or marketing data without ever formalising the control perimeter or demonstrating dominant influence. The result: the legal basis collapses and each entity becomes an isolated controller, individually exposed.
The 'dominant influence' test applied to the Luxembourg landscape
In Luxembourg, holding structures (SOPARFI, family office, SICAR) create particular complexity: indirect ownership via fiduciary arrangements, minority shareholding with shareholders' agreement, management mandates entrusted to domiciliation companies. Recital 37 requires concrete demonstration of who can impose data protection rules. Criteria to document:
- Direct or indirect capital ownership (effective control threshold, not just 50% + 1)
- Power to appoint directors and the DPO
- Existence of a group data protection policy enforceable on all subsidiaries
- Breach escalation mechanisms toward the controlling undertaking
- Intra-group data sharing agreement signed by each entity
- Mapping of HR, client and supplier data flows between entities in the perimeter
Without this documentation, it is impossible to invoke the intra-group legitimate interest of recital 48, or to share a DPO between Luxembourg subsidiaries and French or Belgian sister entities.
How Luxgap automates this risk
Our Luxgap Group Perimeter Mapper materialises in real time the group of undertakings perimeter under recital 37 by cross-referencing your capital and operational data rather than asking your legal department to fill in a spreadsheet. The tool automatically ingests your Luxembourg RCS extract, Belgian BCE and French Infogreffe registers, your shareholders' agreements filed with the notary, and your inter-tenant Azure AD flows to rebuild the actual control chain.
- Scans the RCS and beneficial owners registers (RBE Luxembourg) to automatically detect capital links between all entities in your perimeter.
- Calculates a dominant influence score for each relationship combining direct ownership, voting rights, appointment power and shareholders' agreement clauses.
- Detects orphan subsidiaries: entities operationally integrated into the group but without formal legal attachment, the number one source of CNPD disputes.
- Generates the intra-group data sharing agreement ready to sign, with annexes by typology (HR, CRM, finance, IT shared services).
- Produces a time-stamped PDF report enforceable before the CNPD during an audit, demonstrating that your invocation of recital 37 rests on documented facts rather than self-declaration.
- Alerts in real time when a divestment, merger or change of agreement modifies the perimeter, preventing you from continuing to invoke a group that no longer exists.
Available as part of a Luxgap DPO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual capital structure, with a free 48-hour white audit to measure the legal soundness of your group perimeter before any commitment.