Binding Corporate Rules (BCRs) are an intra-group data transfer mechanism approved by EU data protection authorities that allow multinational corporate groups to transfer personal data from the European Economic Area to group entities in third countries lacking an EU adequacy decision, provided the group adopts and enforces a comprehensive, legally binding internal data protection code. BCRs are assessed and approved by a lead supervisory authority under the GDPR framework.
Content
- BCRs were introduced conceptually under the EU Data Protection Directive 95/46/EC and formalised in Article 26(2) of that Directive as a derogation for intra-group transfers. The Working Party 29 (now the European Data Protection Board) issued guidance documents (WP74, WP102, WP195) through the 2000s and 2010s establishing the criteria for BCR approval: they must be legally binding, apply to all group members, confer enforceable rights on data subjects in the EEA, and provide for liability acceptance by the EU establishment. BCRs were explicitly codified in the GDPR under Articles 46 and 47 when it came into force in May 2018.
- The approval process involves submitting a detailed BCR document to a lead supervisory authority selected based on the location of the group’s EU headquarters or principal establishment. The lead authority reviews the BCR against a standardised checklist, coordinates with other concerned authorities, and grants approval that is binding across the EEA. The process typically takes 12–24 months and requires significant legal and governance investment, making BCRs practical primarily for large multinationals. BCRs for processors (BCR-P), covering data processing on behalf of external clients, were formalised separately.
- In practice, BCRs are used by major technology, financial services, and manufacturing multinationals including Google, IBM, Philips, and General Electric. They are managed by internal data protection functions in coordination with group legal and compliance teams, requiring ongoing maintenance as group structure, processing activities, and applicable law evolve. The EDPB maintains a public register of approved BCRs and published updated referential documents for both controllers and processors in 2022 to align with GDPR requirements.
- By 2024–2025 BCRs face renewed scrutiny in light of the Schrems II judgment (2020), which invalidated the Privacy Shield and reinforced the obligation to assess third-country law for surveillance risks even where BCRs are in place. The EDPB’s guidance requires BCR holders to conduct transfer impact assessments for transfers to countries whose national security laws may override BCR commitments. The EU-US Data Privacy Framework (2023) has partially eased this burden for US transfers, but BCRs remain central to transfers to countries without adequacy decisions such as India and Brazil.