Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Cross-Border Transfers

Binding Corporate Rules

Also known as:
Simply put

Binding Corporate Rules are internal data protection policies adopted by a group of companies under common ownership or engaged in a joint economic activity, allowing them to transfer personal data across borders within the group. They must be approved by the relevant data protection regulator before they can be relied upon. BCRs are one of several tools available to legitimize transfers of personal data out of jurisdictions that restrict such transfers, such as the European Economic Area.

Formal definition

Binding Corporate Rules (BCRs) are legally binding and enforceable internal rules and policies adopted by a group of undertakings or a group of enterprises engaged in a joint economic activity to provide appropriate safeguards for restricted (cross-border) transfers of personal data among group members. The concept was developed under EU law as a transfer mechanism, for example to permit transfers of personal data from the European Economic Area (EEA) to affiliates outside it, and requires prior approval by the competent supervisory authority. Following EU exit, a distinct UK regime also recognizes BCRs; practitioners should distinguish EU/EEA approvals from UK approvals and note that BCRs are one appropriate-safeguard option among others (such as standard contractual clauses) rather than the only route. This entry describes BCRs at a conceptual level; the specific approval procedures, required content, and applicable versions of guidance evolve, so readers should verify against the current authoritative text from the relevant supervisory authority. Application to particular corporate structures and transfer scenarios requires professional judgment.

Why it matters

Cross-border data flows are essential to how multinational groups operate, yet jurisdictions such as the European Economic Area restrict transfers of personal data to territories that do not offer equivalent protection. For a corporate group that moves personal data routinely among affiliates in different countries, negotiating separate contractual arrangements for every intra-group transfer can be cumbersome. Binding Corporate Rules address this by establishing a single set of internal, enforceable policies that the group's members commit to follow, providing the appropriate safeguards that the law generally requires for such restricted transfers.

The significance of BCRs lies in their status once approved: they are legally binding and enforceable within the group, which means individuals whose data is transferred are intended to benefit from consistent protection regardless of where within the group their data is processed. This distinguishes BCRs from a purely aspirational corporate policy. It is important, however, to keep BCRs in perspective. They are one appropriate-safeguard option among several, and standard contractual clauses remain a widely used alternative that may be more practical for organizations that do not wish to undertake the approval process. BCRs do not, on their own, resolve every transfer question, and their suitability depends on the group's structure and transfer patterns.

Practitioners should also note the jurisdictional split that followed EU exit. The concept was developed under EU law, but a distinct UK regime now also recognizes BCRs, and an approval under one does not automatically carry over to the other. Because approval procedures, required content, and the applicable guidance evolve over time, organizations relying on BCRs should verify their position against the current authoritative text from the relevant supervisory authority rather than assuming a fixed or permanent standard.

Who it's relevant to

Multinational corporate groups
Groups of companies under common ownership, or engaged in a joint economic activity, that transfer personal data among affiliates across borders are the primary candidates for BCRs. For such groups, BCRs can provide a single internal framework for intra-group transfers rather than a patchwork of separate arrangements. Suitability depends on the group's structure and the volume and nature of its transfers, and BCRs remain one option alongside alternatives such as standard contractual clauses.
Data protection officers and privacy teams
Those responsible for a group's data protection posture need to understand what BCRs are, what they are not, and how they compare with other transfer tools. They are typically involved in assessing whether the approval process is worthwhile for their organization and in maintaining the internal policies that make up the rules. They should track how requirements and guidance evolve and verify against the current authoritative text.
Legal counsel and compliance officers
Because BCRs are intended to be legally binding and enforceable and require prior regulatory approval, counsel and compliance functions are central to their preparation, submission, and ongoing governance. They must distinguish EU/EEA approvals from UK approvals following EU exit and apply professional judgment to particular transfer scenarios, as this material is informational rather than advice for a specific situation.
Supervisory authorities and auditors
Competent supervisory authorities approve BCRs and assess whether they provide appropriate safeguards. Internal and external auditors reviewing a group's international transfer practices may need to confirm that BCRs relied upon have been approved by the relevant authority and are being applied consistently across group members.

Inside BCRs

Intra-group transfer mechanism
BCRs are internal data protection policies adopted by a corporate group (or group of enterprises engaged in a joint economic activity) to legitimize transfers of personal data from EU/EEA entities to affiliated entities located in third countries that lack an adequacy decision. They function as one of the appropriate safeguards recognized under EU data protection law for such transfers.
Supervisory authority approval
Unlike standard contractual clauses, which parties can adopt without prior sign-off, BCRs generally require formal approval by a competent EU/EEA supervisory authority, typically following a cooperation and consistency procedure involving other concerned authorities. This approval step is a defining feature and distinguishes BCRs from off-the-shelf transfer tools.
Binding and enforceable commitments
To be effective, BCRs must be legally binding on and enforced by every member of the corporate group, including employees. They typically must also confer enforceable rights on data subjects, meaning affected individuals should be able to invoke the rules and seek remedies. Non-binding internal guidance would not qualify.
Controller and processor variants
BCRs are commonly distinguished into those covering a group acting as controller and those covering processing activities performed on behalf of external controllers. The two variants address different roles and obligations and should not be treated as interchangeable; an organization may need one, the other, or both depending on its activities.
Content and accountability elements
Approved BCRs generally set out the structure of the group and the transfers covered, the data protection principles applied, mechanisms for data subject rights and complaint handling, allocation of liability, training and audit arrangements, and cooperation duties with supervisory authorities. Practitioners should verify the specific required elements against current authoritative guidance, as expectations evolve.

Common questions

Answers to the questions practitioners most commonly ask about BCRs.

Do Binding Corporate Rules let a company transfer personal data anywhere without further restriction?
No. BCRs are a mechanism under EU data protection law for lawful transfers of personal data outside the EEA within a single corporate group or group of enterprises engaged in a joint economic activity. They authorize intra-group transfers among the entities bound by the approved rules; they do not provide a general license to transfer data to unrelated third parties or to destinations outside the scope of what was approved. Transfers to external recipients generally require a separate lawful transfer mechanism. Application to any specific arrangement depends on the facts and on the approved BCR text.
Is having Binding Corporate Rules the same as being certified as compliant with the GDPR?
No. BCRs are a transfer mechanism approved by a competent supervisory authority, not a certification of overall GDPR compliance. Approval addresses the safeguards for international data transfers within the group and does not attest that every processing activity across the organization meets all legal obligations. Certification and BCR approval are distinct concepts, and readers should not treat one as evidence of the other. Verify the precise scope of any approval against the current authoritative documentation.
How does an organization obtain approval for Binding Corporate Rules?
BCRs generally require submission to and approval by a competent supervisory authority, typically involving a lead authority and a cooperation and consistency procedure among relevant authorities. The process usually assesses whether the rules contain the required elements, such as binding effect, enforceable rights, and appropriate safeguards. The procedure can be substantial in time and documentation. Specific procedural steps, timelines, and requirements vary and evolve, so organizations should confirm current expectations with the relevant authority and against the latest official guidance.
What is the difference between BCRs for controllers and BCRs for processors?
The distinction reflects the role the group entities play in relation to the data. Controller BCRs generally cover transfers where group entities determine the purposes and means of processing, while processor BCRs address situations where group entities process personal data on behalf of external controllers, such as clients. The two are drafted to reflect these different roles and responsibilities. Which type applies depends on how processing is structured, and organizations should keep the controller and processor roles clearly distinguished when scoping their rules.
Do all entities in a corporate group need to be bound by the BCRs?
BCRs are intended to be binding on the group members that participate in the covered transfers, and enforceability is a core feature of the mechanism. In practice this typically involves internal legal instruments or other means that make the rules binding on the relevant entities and their staff, together with enforceable rights for data subjects. The precise scope of which entities are bound is defined in the approved rules, so organizations should confirm coverage against their own approved BCR text rather than assume automatic group-wide application.
How should an organization maintain BCRs after approval?
BCRs are not a one-time achievement; they generally require ongoing governance, including keeping the rules current, monitoring adherence, handling data subject complaints through the mechanisms provided, and cooperating with the relevant supervisory authority. Material changes to the group, its structure, or its processing may need to be managed in line with the approved rules and applicable requirements. Because expectations and legal interpretations evolve, organizations should periodically review their arrangements against the latest authoritative guidance and apply professional judgment to their specific circumstances.

Common misconceptions

BCRs are a certification that can be purchased or quickly obtained like an off-the-shelf compliance tool.
BCRs are not a certification and are not immediately available. They are internal rules that generally require preparation, internal binding measures, and formal approval by a competent supervisory authority through a cooperation procedure, a process that typically takes considerable time and effort.
BCRs cover all types of international data transfers for any organization.
BCRs are designed for transfers within a corporate group or group of enterprises engaged in a joint economic activity. They do not, on their own, legitimize transfers to unrelated third parties outside the group, for which other transfer mechanisms would generally be needed.
Once approved, BCRs are permanent and require no further attention.
Approved BCRs remain subject to ongoing obligations, including auditing, training, cooperation with authorities, and updates to reflect changes in the group or in legal requirements. Regulatory expectations and the surrounding legal framework can change, so BCRs should be maintained and reviewed rather than treated as a one-time achievement.

Best practices

Determine early whether you need controller BCRs, processor BCRs, or both, based on a clear mapping of the roles your group entities play in the relevant processing activities.
Ensure the rules are genuinely binding on and enforceable against every group member and relevant personnel, rather than expressed as aspirational internal policy.
Engage with the competent supervisory authority and plan for the approval procedure as a multi-stage process, allowing realistic time and resources.
Build in the accountability elements authorities generally expect, such as data subject rights mechanisms, complaint handling, liability allocation, training, and audit arrangements.
Establish a maintenance process to review and update the BCRs when the group structure, processing activities, or applicable legal requirements change.
Verify the specific required content, procedural steps, and current expectations against the latest authoritative supervisory guidance, and seek professional judgment for application to your particular circumstances.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."