International companies · Data sent to group finance
A reporting package can carry personal data
Numbers sent to the parent company can include information about employees and other individuals. From that point this is not only an accounting question: GDPR roles, transfer mechanisms, minimisation and security also apply.
Who has which role
A controller determines the purposes and means of processing; a processor processes personal data on the controller's behalf. In a typical accounting arrangement the client is the controller and the accounting firm is the processor. Where two organisations jointly determine purposes and means, their joint-controller arrangement must be defined rather than assumed.
A processor may appoint a subprocessor only with written authorisation and must impose equivalent obligations. Every system in the reporting chain is therefore a documented choice. The processor also maintains its own record of processing activities.
Transfers to the parent company
A transfer within the EU does not trigger the third-country transfer chapter. A transfer outside the EU needs an applicable basis: an adequacy decision, safeguards such as standard contractual clauses or binding corporate rules, or a narrowly construed derogation for a specific situation. A monthly reporting process should not be designed around an exception.
There is a separate accounting restriction: accounting documents and books may be stored outside Croatia only in another EU Member State, with supervisory access available. The GDPR analysis and the accounting-location rule must both be satisfied.
The most sensitive part
Payroll may contain health data through sick-leave records and, occasionally, trade-union data. Before asking how to secure such data, ask whether group finance needs to receive it at all.
Security and automated decisions
GDPR requires technical and organisational measures appropriate to risk, including encryption where appropriate. A decision based solely on automated processing that has legal or similarly significant effects is generally restricted. This matters if group systems use employee data for automated scoring or decisions.
Where generative AI is used for language or preparation work, the EU AI Act adds transparency duties. Our process uses AI as an assisted tool with named human review, not as the final decision-maker over client or employee data.
Illustrative situation
A monthly headcount and payroll-cost total may meet the parent's management need without transferring named sick-leave records. Data minimisation begins with the design of the reporting template.
Primary legal basis
- General Data Protection Regulation (EU) 2016/679 — Articles 4, 9, 22, 26, 28, 30, 32 and 44–49.
- Croatian GDPR Implementation Act — national framework and AZOP.
- EU Artificial Intelligence Act 2024/1689 — transparency obligations.
- Accounting Act — storage of accounting records and books.
Verified as at 2 August 2026. The concrete controller/processor and transfer analysis depends on the actual systems and data flow.
Next step
Tell us what the Croatian entity and group finance need
We will separate statutory accounting, recurring reporting and any integration project into a clear scope.
Request an assessment