3.6 Governing Internal & External Data Sharing and Disclosure

Key Takeaways

  • Indicator II.B.2 requires defined roles and responsibilities for managing the sharing and disclosure of data for internal and external use — internal sharing is expressly in scope.
  • The first question in any sharing scenario is the relationship: controller-to-processor, controller-to-controller, or joint controllers under GDPR Article 26 — each needs a different instrument.
  • Joint controllers must agree in a transparent arrangement who fulfils which obligation, and the essence of that arrangement must be made available to data subjects.
  • Government and law-enforcement disclosure requests need a standing procedure: validate legal authority, scope-minimise, log, and notify the individual unless legally prohibited.
  • Every disclosure needs a log entry; without one, an organization cannot answer a rights request, scope a breach, or evidence lawful sharing.
Last updated: August 2026

Sharing Is Where Programs Quietly Leak

Competency II.B requires clarifying roles and responsibilities, and its second indicator is specific: define the roles and responsibilities for managing the sharing and disclosure of data for internal and external use. The word internal is deliberate. Moving customer data from the support platform into the marketing warehouse is a disclosure decision as surely as sending it to a vendor, and it is far more likely to happen without anyone approving it.

Classify the relationship first

Every credited answer in a sharing scenario starts with the relationship, because the relationship determines the instrument.

RelationshipTestInstrumentCommon trap
Controller to processorRecipient processes only on documented instructionsArticle 28 DPA with the mandatory clausesAssuming a standard vendor MSA covers it
Controller to controllerRecipient determines its own purposesData sharing agreement; each party needs its own lawful basis and noticeTreating the recipient as a processor to avoid the notice duty
Joint controllersParties jointly determine purposes and meansArticle 26 arrangement allocating obligations transparentlyAssuming joint control means shared liability only
Intra-group transferBetween entities of the same corporate familyIntra-group agreement plus a transfer tool if borders are crossedTreating group companies as one legal person
Internal cross-purposeSame controller, new purposeCompatible-purpose assessment; new lawful basis if incompatibleAssuming one controller means one purpose

The last row is the one most often missed. A single legal entity cannot repurpose data freely just because no third party is involved — purpose limitation binds the controller to itself.

Joint controllership under Article 26

Where two parties jointly determine the purposes and means, Article 26 requires them to determine their respective responsibilities in a transparent manner by means of an arrangement, covering in particular who provides the Article 13-14 information and who handles rights requests. The essence of the arrangement must be made available to data subjects, and — critically — the data subject may exercise rights against each of the controllers, regardless of what the arrangement says between them. The arrangement allocates work; it does not carve up the data subject's rights.

Government and law-enforcement requests

A standing procedure is expected because these requests arrive under time pressure, often to someone who has never seen one:

  1. Route every request to a single named function; front-line staff never respond directly.
  2. Validate the legal authority — is it a subpoena, warrant, court order, statutory notice, or an informal request with no compulsion behind it? An informal request can usually be declined.
  3. Check jurisdiction and conflict of laws — a foreign demand may conflict with GDPR, where Article 48 makes third-country judgments enforceable only through mutual legal assistance or another international agreement.
  4. Scope-minimise — produce only what the instrument actually compels, and push back on overbroad demands.
  5. Log the request, the authority relied on, what was produced, who approved and when.
  6. Notify the data subject unless legally prohibited by a gag provision.
  7. Report in aggregate through a transparency report where the organization publishes one.

Internal sharing controls

The practical governance moves are: purpose tags on datasets so a warehouse copy carries its original purpose; an approval gate for cross-functional data movement; access provisioned by role and reviewed periodically; and a rule that analytics copies inherit the retention schedule of their source rather than living forever in a lake.

The disclosure log

The log is the connective tissue. Without a record of who received what and when, an organization cannot answer an access request that asks about recipients, cannot scope a breach to downstream copies, cannot honour a deletion request across recipients, and cannot evidence lawful sharing to a regulator. GDPR Article 19 even requires the controller to communicate rectification, erasure or restriction to each recipient unless impossible or disproportionate — an obligation that is unmeetable without a recipient list.

Worked scenario

A support team exports a customer list to a spreadsheet and hands it to an agency running a re-engagement campaign. No DPA, no notice update, no log entry. Three failures stack: the agency is an undocumented processor (Article 28), the marketing purpose was not assessed for compatibility with the support purpose it was collected for (Article 5(1)(b)), and the absence of a log means a subsequent deletion request cannot be propagated under Article 19. The credited remediation is not "tell the team off" — it is a sharing approval gate with a named owner, a standing DPA template, and a log entry as a mandatory step in the export process itself.

Test Your Knowledge

Two companies jointly design and operate a co-branded loyalty programme, deciding together what data is collected and why. They sign an arrangement allocating rights-request handling to Company A. A data subject sends an erasure request to Company B. What is the correct position?

A
B
C
D
Test Your Knowledge

A support team emails a customer spreadsheet to a marketing agency for a re-engagement campaign, with no data processing agreement, no notice update and no record of the transfer. Which combination of failures does this create?

A
B
C
D