Binding Corporate Rules
What is Binding Corporate Rules?
Internal policies adopted by multinational corporations for transferring personal data within the group across international borders in compliance with data protection laws.
Terms that appear alongside binding corporate rules
Each of these is named in at least one of the same controls as binding corporate rules. The number is how many controls name both.
- standard contractual clauses 35 shared controls
- consent 34 shared controls
- gdpr 23 shared controls
- certification 21 shared controls
- data subject 19 shared controls
- impact assessment 17 shared controls
- schrems ii 17 shared controls
- transfer impact assessment 16 shared controls
Frameworks that govern binding corporate rules
What the standards actually require on binding corporate rules
Requirements naming binding corporate rules across 6 standards, quoted from the control text.
Binding corporate rules must be approved by the competent supervisory authority under the consistency mechanism, must be legally binding on and enforced by every member of the group including its employees, and must expressly confer enforceable rights on data...
GDPR-Art.47 · Binding corporate rules →Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided.
JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations · Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data Flows + Caribbean Community + International Data Privacy →Transfers and transmissions within corporate groups may rely on binding corporate rules (normas corporativas vinculantes) authorized by the SIC.
CO-L1581-A27 · Binding Corporate Rules →Cross-border transfer of personal data from Italy is governed by GDPR Chapter V + Italian Codice + Italian Garante guidance. (1) GDPR Chapter V Transfer Mechanisms: (a) Adequacy decisions per Commission - Andorra + Argentina + Canada (commercial organisations)...
ItalyCodice-CrossBorder-Transfer-Adequacy-SCCs-BCRs-Retention-ItalianSectorRules-EUDataAct · Italy Codice Cross-Border Transfer + EU Adequacy + Standard Contractual Clauses + Binding Corporate Rules + EU Data Act + Italian Sector Retention Rules + Schrems II + Transfer Impact Assessment →Articles 20-21 of the Jordan PDPL govern cross-border transfers of personal data closely modelled on EU GDPR Chapter V. (1) Article 20 General Prohibition: Cross-border transfer prohibited unless one of these grounds applies (a) Adequacy Determination by Counc...
JO-PDPL-Cross-Border-Transfer-Article20-21-Adequacy-Consent-Public-Interest-Performance-Council-Approval · Jordan PDPL Cross-Border Transfer + Articles 20-21 + Adequacy + Consent + Public Interest + Performance + Council Approval + Standard Contractual Clauses + Binding Corporate Rules + Derogations + GCC Coordination →Transfers outside Thailand require destination country to have adequate protection, or one of the exceptions, including binding corporate rules or standard contractual clauses approved by PDPC.
Section 28 · Cross-Border Data Transfer →Questions people ask about binding corporate rules
What is Binding Corporate Rules?
Why is Binding Corporate Rules important for compliance?
Which compliance frameworks address Binding Corporate Rules?
Where can I learn more about Binding Corporate Rules?
See how Binding Corporate Rules applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.