From a legal perspective, an organizational structure is not required under the GDPR. In principle, it would be sufficient to name the controller for a processing activity (e.g. caralegal GmbH) and provide the relevant information such as the address.
However, an organizational structure is necessary for the efficient use of caralegal. It allows you to:
filter processing activities by organizational units
assign users to departments
assign processing activities to one or multiple organizational units
manage access rights and roles
export processing activities for specific organizational units
assign responsibilities within the organization
During onboarding, our team supports you in setting up the organizational structure.
Recommended structure for companies with up to 5 legal entities
ROOT / Tenant level – system-defined (editable only by caralegal support)
Legal entities – first editable level
Departments – e.g. HR, Sales, Finance (sub-departments possible)
Recommended structure for companies with more than 5 legal entities
ROOT / Tenant level
Regions – e.g. EMEA, North America, APAC
Countries – e.g. Germany, France, Spain
Legal entities – subsidiaries within each country
Departments – e.g. HR, Sales, Finance (sub-departments possible)
