Multinational corporations (MNCs), especially micro-MNCs in Southeast Asia (ASEAN), are increasingly relying on the transfer of personal data between internal offices to support centralized business functions such as finance, human resources, etc research and development (R&D), or customer service. However, cross-border transfers of personal data are subject to strict data protection regulations in the countries concerned, which can vary significantly. This article will analyze the essential elements that multinational enterprises should include in the Group Internal Agreement when transferring personal data between offices in multiple countries, and clarify the role of this agreement in the context of ASEAN.

1. Context and importance of Group Internal Agreements
1.1. Expansion trends in ASEAN
According to a 2022 survey[1], 3 out of 5 small and medium enterprises (SMEs) in Singapore plan to expand to ASEAN countries within the next three years. By 2024, 66% of Singaporean companies expanding abroad for the first time will be small businesses. In particular, 7 out of 10 Singaporean enterprises already have a presence abroad, with Malaysia (63%) and Indonesia (49%) being the top two markets. This indicates the growing need for the transfer of personal data between regional offices to support activities such as logistics, manufacturing, or customer service.
1.2. Role of the Group's Internal Agreement
The Group Internal Agreement is a legal instrument designed to assist MNCs, especially micro-MNCs, in carrying out the transfer of personal data between internal branches in a legal and efficient manner. Developed on the basis of the ASEAN Model Contractual Clauses (MCCs[2]), especially Module 1 (Controller-to-Processor), this agreement is aimed at businesses that use Binding Corporate Rules (BCRs) or need a standardized solution for centralized operations. The agreement helps to ensure that personal data is protected in accordance with legal standards in the countries concerned, while minimizing legal costs and operational risks.
2. Essentials in the Group's Internal Agreement
To ensure compliance with the law and effective operation, the Group Internal Agreement should include the following specific provisions:
2.1. Define the roles and responsibilities of the parties
Controller and Processor: The agreement should clarify the roles of the affiliates in the group. The Controller decides on the purpose and method of data processing, while the Processor follows the instructions of the Controller. For example, an MNC headquartered in Singapore may be the Data Controller, while the manufacturing branch in Vietnam is the Data Processor.
Data processing instructions: The Agreement shall provide that the Processor may only process personal data in accordance with specific instructions from the Controller, unless otherwise required by local law.
2.2. Purpose of data transfer
Centralized business function: The agreement should clearly define the purpose of the data transfer, such as financial support, human resources, R&D, or customer service functions. Parties can define these functions themselves to suit business needs.
Limitation of purpose: The data is only used for the agreed purposes, ensuring compliance with the principle of purpose limitation in data protection laws such as Singapore's PDPA or another specific purpose.
2.3. Compliance with the Group's data protection policy
The agreement requires all affiliates to comply with the Group's data protection policy, including security measures, data breach handling procedures, and data subject rights.
In addition, this policy helps standardize data protection standards across the group, ensuring that data is protected at the same level across all branches, regardless of country.
2.4. Rights and obligations related to data subjects
The Processor must cooperate with the Controller to satisfy the rights of the data subject, including the right to access, modify, delete the data, or object to the processing of the data. The agreement should specify specific processes for handling requests from data subjects, such as response deadlines or communication methods between affiliates.
2.5. Data breach management
The Agreement shall provide that the Processor shall immediately notify the Controller of the occurrence of a data breach affecting the transferred data. This includes details of the time, scope of the violation, and remedial measures.
The agreement should also clarify the parties' responsibilities in dealing with the consequences of the breach, including notifying regulators and data subjects if required by law.
2.6. Right to inspect and supervise
The Agreement should give the Controller the right to inspect the Processor's records and processes to ensure compliance with data protection regulations. At the same time, the Agreement may provide for periodic audits or ad hoc inspections to assess the compliance of affiliates.
2.7. Right to return and delete data
Return of data: The agreement should provide that the Supervisory Party has the right to request the Processor to return personal data when it is no longer necessary for the agreed purpose.
Deletion of data: Upon completion of the purpose of processing, the Processor must delete the data or securely store it at the request of the Controller, unless retention is required by local law.
2.8. Security measures
Technical and organizational measures: The agreement should list specific security measures (e.g., encryption, access control, or system monitoring) to protect personal data from unauthorized access or leakage.
Country-by-country: These measures need to be tailored to meet country-specific legal requirements, such as the Personal Data Protection Law/Decree 13/2023/ND-CP of Vietnam or Singapore's PDPA.
2.9. Restrictions on transfers to third parties
The agreement should provide that personal data may not be transferred to third parties outside the group without the permission of the Controller, unless required by law. This is necessary to ensure the rights of data subjects regardless of whether the data is transferred to any country in which the group's business is located.

3. Case study of Ilovewinterwear Pte. Ltd. Singapore
Ilovewinterwear Pte. Ltd., a Singaporean company with branches in many ASEAN countries:. In particular, Singapore serves as the headquarters, in charge of finance, human resources, R&D, and strategic management. Meanwhile, Malaysia is a regional logistics and distribution hub. Vietnam and the Philippines are winter clothing factories and after-sales customer service centers, respectively.
The Group Internal Agreement helps Ilovewinterwear manage the transfer of personal data such as employee, customer, or logistics data between these branches. The provisions of the agreement ensure that:
- Personnel data from Vietnam is processed in accordance with the instructions of the head office in Singapore.
- Customer data from the Philippines is protected according to corporate standards.
- Data breaches (if any) are promptly notified and handled synchronously across the group.
4. Benefits of the Group Internal Agreement
4.1. Cost-effective and operational efficiency
The agreement was developed based on the ASEAN MCCs, which provide a standardized template, helping micro-MNCs avoid the cost of drafting contracts from scratch or hiring external consultants. The agreement is also designed to be easy to use, making it suitable for small businesses that lack in-depth legal resources. In addition, branches in countries can customize the agreement to fit specific business functions, such as adding security measures or audit procedures.
4.2. Compliance with the law
The agreement is suitable for businesses that use Internal Binding Rules (BCRs) as data transfer mechanisms in accepting countries, such as Singapore or the Philippines. In addition, the agreement helps ensure compliance with data protection regulations in ASEAN countries, such as Singapore's PDPA or Thailand's data protection laws.
4.3. Process standardization
The agreement helps to synchronize data protection standards across the group, minimizing risks due to regulatory differences between countries. At the same time, these agreements are not focused on specific transactions, but are designed for long-term internal relationships, in line with expanding MNCs.
5. Challenges in building agreements
In the process of building an internal agreement with the group, businesses will face many challenges and the biggest challenge is the different legal framework of ASEAN countries on personal data protection. Specifically, the challenges can be mentioned as:
Legal differences between countries: Each ASEAN country has its own legal framework for personal data protection, such as Singapore has a PDPA, Vietnam has a Personal Data Protection Law (PDPL) and a Personal Data Protection Law (PDPA) of Thailand,.... The agreement needs to be tailored to meet country-specific requirements.
In-house legal understanding: Micro-MNCs may lack the expertise to customize the agreement in accordance with local regulations, requiring consultation from an attorney or expert.
Continuous compliance management: Group-wide compliance monitoring and audits can be complex, especially when branches operate in multiple countries of different sizes.
In the process of drafting the Group Internal Agreement, businesses need to pay attention to a number of issues such as the need to clearly define centralized business functions and adjust the agreement to reflect specific needs. In addition, although the agreement is a standardized solution, consultation with lawyers may be necessary to ensure compliance with complex regulations, especially when transferring data to countries outside ASEAN. In addition, branches in different countries need to be trained on data protection policies and breach handling procedures to ensure uniform implementation across the group.
6. Steps to develop the Group Internal Agreement
To implement the Group Internal Agreement, businesses should take the following steps:
- Define the group structure: Clarify the role of each branch (Controller or Processor) and centralized business functions.
- Research local laws: Ensure that the agreement meets the data protection regulations in the relevant countries, Singapore's PDPA, Malaysia's or Vietnam's personal data protection laws.
- Use a standard template: Based on the Group Internal Agreement (or ASEAN MCCs) to build the draft, then customize it according to specific needs.
- Legal consultation: Work with an attorney to ensure the agreement complies with national and international regulations.
- Implementation and Monitoring: Train affiliates on agreements and establish monitoring and auditing processes to ensure ongoing compliance.
The Group Internal Agreement is an important legal tool that helps multinational enterprises, especially micro-MNCs, manage the transfer of personal data between branches in the ASEAN region and beyond. The agreement should include provisions on roles and responsibilities, the purpose of the transfer, compliance with the data protection policy, breach management, and the right to audit, and ensure security measures and support the rights of the data subject. With its flexibility, cost-effectiveness, and ability to standardize, this agreement helps multinational businesses in Southeast Asia operate efficiently and comply with the law in the context of multinational expansion. However, businesses need to pay attention to adjusting the agreement to comply with local regulations and maintain continuous monitoring to ensure compliance.
[1] https://www.uobgroup.com/asean-insights/articles/sme-outlook-study-2022-market-expansion.page, accessed on 07/09/2025.
