Recital 37

Recital 37

General Data Protection Regulation · UE 2016/679

(37)

A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings by virtue, for example, of ownership, financial participation or the rules which govern it or the power to have personal data protection rules implemented. An undertaking which controls the processing of personal data in undertakings affiliated to it should be regarded, together with those undertakings, as a group of undertakings.

Luxembourg specificity
loi du 1er aout 2018 portant organisation de la CNPD et mise en oeuvre du RGPD, articulee avec la loi du 13 janvier 2019 instituant le RBE

In Luxembourg, the CNPD (never APDL) is the competent authority to validate the applicability of recital 37 in holding structures. The law of 1 August 2018 organising the CNPD and implementing the GDPR does not derogate from recital 37 but articulates it with the beneficial owners register (RBE) kept by the LBR since the law of 13 January 2019: the CNPD systematically cross-checks group declarations against the RBE during audits, and any inconsistency between the GDPR org chart and the RBE triggers a flag.

Luxgap practice: before invoking a group perimeter to share a DPO or justify an intra-group transfer, align your controllers and processors mapping with your RBE filing and your RCS extract, otherwise documentary contradiction becomes enforceable during a CNPD audit.