3.6 Governing Internal & External Data Sharing and Disclosure
Key Takeaways
- Indicator II.B.2 requires defined roles and responsibilities for managing the sharing and disclosure of data for internal and external use — internal sharing is expressly in scope.
- The first question in any sharing scenario is the relationship: controller-to-processor, controller-to-controller, or joint controllers under GDPR Article 26 — each needs a different instrument.
- Joint controllers must agree in a transparent arrangement who fulfils which obligation, and the essence of that arrangement must be made available to data subjects.
- Government and law-enforcement disclosure requests need a standing procedure: validate legal authority, scope-minimise, log, and notify the individual unless legally prohibited.
- Every disclosure needs a log entry; without one, an organization cannot answer a rights request, scope a breach, or evidence lawful sharing.
Sharing Is Where Programs Quietly Leak
Competency II.B requires clarifying roles and responsibilities, and its second indicator is specific: define the roles and responsibilities for managing the sharing and disclosure of data for internal and external use. The word internal is deliberate. Moving customer data from the support platform into the marketing warehouse is a disclosure decision as surely as sending it to a vendor, and it is far more likely to happen without anyone approving it.
Classify the relationship first
Every credited answer in a sharing scenario starts with the relationship, because the relationship determines the instrument.
| Relationship | Test | Instrument | Common trap |
|---|---|---|---|
| Controller to processor | Recipient processes only on documented instructions | Article 28 DPA with the mandatory clauses | Assuming a standard vendor MSA covers it |
| Controller to controller | Recipient determines its own purposes | Data sharing agreement; each party needs its own lawful basis and notice | Treating the recipient as a processor to avoid the notice duty |
| Joint controllers | Parties jointly determine purposes and means | Article 26 arrangement allocating obligations transparently | Assuming joint control means shared liability only |
| Intra-group transfer | Between entities of the same corporate family | Intra-group agreement plus a transfer tool if borders are crossed | Treating group companies as one legal person |
| Internal cross-purpose | Same controller, new purpose | Compatible-purpose assessment; new lawful basis if incompatible | Assuming one controller means one purpose |
The last row is the one most often missed. A single legal entity cannot repurpose data freely just because no third party is involved — purpose limitation binds the controller to itself.
Joint controllership under Article 26
Where two parties jointly determine the purposes and means, Article 26 requires them to determine their respective responsibilities in a transparent manner by means of an arrangement, covering in particular who provides the Article 13-14 information and who handles rights requests. The essence of the arrangement must be made available to data subjects, and — critically — the data subject may exercise rights against each of the controllers, regardless of what the arrangement says between them. The arrangement allocates work; it does not carve up the data subject's rights.
Government and law-enforcement requests
A standing procedure is expected because these requests arrive under time pressure, often to someone who has never seen one:
- Route every request to a single named function; front-line staff never respond directly.
- Validate the legal authority — is it a subpoena, warrant, court order, statutory notice, or an informal request with no compulsion behind it? An informal request can usually be declined.
- Check jurisdiction and conflict of laws — a foreign demand may conflict with GDPR, where Article 48 makes third-country judgments enforceable only through mutual legal assistance or another international agreement.
- Scope-minimise — produce only what the instrument actually compels, and push back on overbroad demands.
- Log the request, the authority relied on, what was produced, who approved and when.
- Notify the data subject unless legally prohibited by a gag provision.
- Report in aggregate through a transparency report where the organization publishes one.
Internal sharing controls
The practical governance moves are: purpose tags on datasets so a warehouse copy carries its original purpose; an approval gate for cross-functional data movement; access provisioned by role and reviewed periodically; and a rule that analytics copies inherit the retention schedule of their source rather than living forever in a lake.
The disclosure log
The log is the connective tissue. Without a record of who received what and when, an organization cannot answer an access request that asks about recipients, cannot scope a breach to downstream copies, cannot honour a deletion request across recipients, and cannot evidence lawful sharing to a regulator. GDPR Article 19 even requires the controller to communicate rectification, erasure or restriction to each recipient unless impossible or disproportionate — an obligation that is unmeetable without a recipient list.
Worked scenario
A support team exports a customer list to a spreadsheet and hands it to an agency running a re-engagement campaign. No DPA, no notice update, no log entry. Three failures stack: the agency is an undocumented processor (Article 28), the marketing purpose was not assessed for compatibility with the support purpose it was collected for (Article 5(1)(b)), and the absence of a log means a subsequent deletion request cannot be propagated under Article 19. The credited remediation is not "tell the team off" — it is a sharing approval gate with a named owner, a standing DPA template, and a log entry as a mandatory step in the export process itself.
Two companies jointly design and operate a co-branded loyalty programme, deciding together what data is collected and why. They sign an arrangement allocating rights-request handling to Company A. A data subject sends an erasure request to Company B. What is the correct position?
A support team emails a customer spreadsheet to a marketing agency for a re-engagement campaign, with no data processing agreement, no notice update and no record of the transfer. Which combination of failures does this create?