Data Protection HubIndividual TopicsTransfers to Third Countries (Data Export)

Binding Corporate Rules (BCR)

Binding Corporate Rules as an appropriate safeguard for intra-group transfers to third countries under Article 47 GDPR: binding internal data protection rules, scope, approval by the supervisory authority, minimum content and liability, as well as the relationship to the Schrems II case law. Distinction between controller and processor BCR, reach and limits.

Binding Corporate Rules (BCR) are binding internal data protection rules of a group of undertakings. They are an appropriate safeguard under Article 46(2)(b) and Article 47 GDPR and permit transfers to third countries within the group without standard contractual clauses having to be concluded for each individual transfer. Once approved, they cover all intra-group transfers falling within their scope.

Key takeaways

  • BCR apply only to transfers within a group of undertakings, not to transfers from external bodies to the group.
  • A distinction is drawn between controller BCR and processor BCR.
  • BCR must be approved by the competent supervisory authority in the consistency mechanism; the procedure is burdensome and lengthy.
  • What is approved are the rules themselves, not the individual transfers. The legal basis under Article 6 GDPR and the transfer impact assessment still have to be addressed separately.
  • For many constellations, an intra-group framework agreement based on the standard contractual clauses is a more practicable alternative.

1. Concept and function

BCR are a self-imposed, binding set of rules by which a group of undertakings commits itself internally to a uniform level of protection that complies with the GDPR. They rest on the idea that the group establishes an autonomous data protection regime under private law and is also able to enforce it by virtue of its internal steering and control mechanisms. This is a form of regulated self-regulation: the group develops the rules tailored to its own needs, but legal recognition as an appropriate safeguard lies with the supervisory authority. On this basis, personal data may also be transferred within the group to third countries that do not ensure an adequate level of protection. At the same time, BCR are seen as an opportunity to establish a uniform data protection culture across a globally active group.

2. Scope

2.1 Who can use BCR

BCR may be used by hierarchically organized groups of undertakings (Article 4(19) GDPR) as well as by undertakings that pursue a joint economic activity without being affiliated in a corporate group, for example in a joint venture. BCR are also conceivable within a single undertaking, for example for data flows between legally dependent establishments. It is always a prerequisite that the controller or processor has an establishment in the EU, so that data subjects can turn to an entity within the Union.

2.2 Which transfers are covered

BCR legitimize only transfers within the group or between the undertakings engaged in a joint economic activity. They do not justify any transfer from external bodies to the group. Where data are passed on from the group to a third party outside the EU (onward transfer), the general requirements of Chapter V apply to that transfer just as they do to a direct transfer from the EU.

BCR cover at least the data transferred from the EU or the EEA to a third country and their further processing there. Whether the group subjects all data uniformly to the BCR irrespective of their origin is a matter of corporate policy; if it differentiates according to origin, the data should be marked accordingly. Where data are to be transferred from one group with BCR to another group with BCR, this is not automatically permissible, because the respective sets of rules may differ in detail.

3. Controller BCR and processor BCR

Two types must be distinguished. Controller BCR govern transfers between the group companies acting as controllers. Processor BCR concern constellations in which group companies act as processors, for example where one company processes on behalf of an external controller and passes the data on to a group company in a third country. The external client may also rely on processor BCR even though it is not itself part of the group, in so far as this does not conflict with the agreement under Article 28(3) GDPR.

4. Approval by the supervisory authority

4.1 Competent supervisory authority and procedure

BCR are approved by the competent supervisory authority in the consistency mechanism (Article 47(1), Article 63 and Article 64(1), second sentence, point (f), GDPR). Competence lies with the lead authority at the seat of the main establishment; where there is only one establishment in the EU, with the authority competent for that establishment. Where the main establishment is located outside the EU, the EU establishment whose supervisory authority is competent must be determined on the basis of its influence over the processing. The procedure of mutual recognition practiced in the past is therefore essentially obsolete.

4.2 Subject matter and effect of the approval

The subject matter of the approval is the BCR themselves, not the individual transfer operations. Once the approval has been granted, the transfer to a third country is permissible without a separate authorization being required for each individual transfer. Where a group meets the requirements of Article 47 GDPR, it is in principle entitled to approval and may take legal action against a refusal.

BCR do not replace the legal basis. Whether the processing is permissible at the first stage under Article 6 GDPR is assessed independently of the approval. BCR therefore allow no free flow of data within the group; each transfer additionally requires its own legal basis (two-stage assessment).

5. Requirements and minimum content (Article 47(1) and (2))

5.1 Legally binding effect internally and externally

BCR must be legally binding, and this in two directions:

  • Internal binding effect (Article 47(1)(a) GDPR): the rules must apply to all group companies concerned and their employees and must be enforced. In a corporate group, this is frequently achieved through the internal steering mechanisms, through reciprocal contracts between the companies (intra group agreement) or through unilateral undertakings, in so far as the applicable law permits this. Employees are bound by way of the right to issue instructions or by incorporating the rules into the employment contract. The rules must also actually be enforced, for example through training and internal control structures.
  • External binding effect (Article 47(1)(b) GDPR): data subjects must be granted expressly enforceable rights so that they can themselves assert compliance with the BCR. Under German law, this is generally done by means of a contract for the benefit of third parties under § 328 of the German Civil Code (BGB) or a unilateral declaration of guarantee (§ 311(1), § 151, first sentence, BGB). For actions against a controller or processor, data subjects may also turn to the courts of their habitual residence (Article 79(2) GDPR).

5.2 Minimum content

Article 47(2) GDPR sets out a catalog of mandatory particulars which ultimately reflect all relevant provisions of the GDPR in the BCR. The rules must not merely name the data protection principles but must give them concrete form for the processing operations covered; a mere reference to the GDPR is not sufficient.

ContentProvision
Structure and contact details of the group and its membersArticle 47(2)(a) GDPR
Transfers covered: categories of data, purposes, data subjects, third countriesArticle 47(2)(b) GDPR
Internal and external binding effectArticle 47(2)(c) GDPR
Application of the data protection principles and requirements for onward transfersArticle 47(2)(d) GDPR
Rights of data subjects and the means of exercising themArticle 47(2)(e) GDPR
Assumption of liability by the EU establishmentArticle 47(2)(f) GDPR
Information of data subjects about the BCRArticle 47(2)(g) GDPR
Tasks of the data protection officer and of data protection complianceArticle 47(2)(h) GDPR
Complaint proceduresArticle 47(2)(i) GDPR
Procedures for verifying compliance (audits)Article 47(2)(j) GDPR
Reporting and recording of changesArticle 47(2)(k) GDPR
Cooperation with the supervisory authorityArticle 47(2)(l) GDPR
Reporting of problematic third-country legislationArticle 47(2)(m) GDPR
Data protection trainingArticle 47(2)(n) GDPR

5.3 Liability

A group company established in the EU must accept liability for infringements of the BCR by other group members established outside the Union (Article 47(2)(f) GDPR). The group is free to determine which establishment this is; a company with sufficient financial resources is advisable. Liability is presumed; exemption comes into consideration only where the liable entity proves that the member concerned is not responsible for the event giving rise to the damage.

6. Third-country law and Schrems II

The approval of BCR, too, presupposes that a level of protection essentially equivalent to that in the EU is ensured in the third country. Where public authorities there have powers of access that go beyond what is acceptable under Article 23 GDPR and that relate to the data covered, approval is ruled out. The standards of the Schrems II case law therefore apply here as well: before and during the use of the BCR, the law of the third country must be assessed and, where necessary, backed up by supplementary measures (transfer impact assessment).

The reporting obligation under Article 47(2)(m) GDPR serves this purpose. If the legal situation in the third country changes in such a way that an equivalent level of protection no longer exists, the supervisory authority must withdraw the approval; irrespective of this, the BCR must ensure that transfers to the group entity concerned are suspended.

7. Assessment and practice

BCR are a high-quality but demanding instrument. Their introduction is complex and resource-intensive and requires the approval procedure before the competent supervisory authority. For many intra-group constellations, an intra-group framework agreement based on the standard contractual clauses achieves the same result with less effort (see Intra-group transfers). BCR are worthwhile above all for large, globally active groups with extensive and permanent internal data flows.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn