Skip to main content

How do I structure my company in a sensible way?

Updated over a month ago

From a legal perspective, an organizational structure is not required under the GDPR. In principle, it would be sufficient to name the controller for a processing activity (e.g. caralegal GmbH) and provide the relevant information such as the address.

However, an organizational structure is necessary for the efficient use of caralegal. It allows you to:

  • filter processing activities by organizational units

  • assign users to departments

  • assign processing activities to one or multiple organizational units

  • manage access rights and roles

  • export processing activities for specific organizational units

  • assign responsibilities within the organization

During onboarding, our team supports you in setting up the organizational structure.

Recommended structure for companies with up to 5 legal entities

  1. ROOT / Tenant level – system-defined (editable only by caralegal support)

  2. Legal entities – first editable level

  3. Departments – e.g. HR, Sales, Finance (sub-departments possible)

Recommended structure for companies with more than 5 legal entities

  1. ROOT / Tenant level

  2. Regions – e.g. EMEA, North America, APAC

  3. Countries – e.g. Germany, France, Spain

  4. Legal entities – subsidiaries within each country

  5. Departments – e.g. HR, Sales, Finance (sub-departments possible)

Did this answer your question?