Binding Corporate Rules
Definition
Binding Corporate Rules
Binding corporate rules are an internal data protection code, approved by a regulator, that permits personal data to move between companies in the same corporate group. They cover one group only — they do nothing for transfers to an unrelated provider.
That limitation defines when they are worth building — a multinational moving employee and customer data between its own entities benefits enormously, and a buyer sending work to a third party does not.
Approval is slow and expensive — a regulator reviews the whole scheme, and the process is usually measured in years rather than months.
The payoff is durability. Once approved, the rules cover every transfer within the group indefinitely, replacing a growing tangle of bilateral agreements.
Key takeaways
- The rules apply only between members of one corporate group or joint economic activity.
- Regulator approval is required, and the review process typically takes years.
- They must confer enforceable rights on individuals, not merely bind the companies.
- For third-party outsourcing they are irrelevant, and model clauses apply instead.
How it works
A group drafts a scheme covering its structure, its data flows, its principles and its complaint routes. A lead regulator reviews it, other authorities are consulted, and approval follows if the scheme meets the statutory tests.
The tests are demanding. The rules must be “legally binding and apply to and are enforced by every member concerned of the group of undertakings”, including their employees.
| Requirement | What it means | Why it is hard |
|---|---|---|
| Legally binding | Enforceable internally and externally | Needs intra-group contracts everywhere |
| Enforceable rights | Individuals can act against group members | Creates direct third-party exposure |
| Group-wide scope | Every entity concerned is covered | Acquisitions must be brought in |
| Principle compliance | Purpose limits, minimisation, security | Requires genuine operational change |
| Onward transfer rules | Bodies outside the group are covered | Third parties need separate safeguards |
The second row is what makes the scheme meaningful. The rules must “expressly confer enforceable rights on data subjects”, which is a real exposure rather than a policy statement.
Onward transfers are the boundary. The rules must set out requirements for transfers “to bodies not bound by the binding corporate rules”, which is precisely where an outsourcing provider sits.
Post-Brexit, the instruments diverged. UK guidance now covers the safeguards permitted, “including the UK IDTA, Addendum and UK BCRs”, which sit separately from the European approvals.
Examples
Binding corporate rules suit a narrow band of organisations, and outsourcing buyers are usually not in it. The four cases below show where they fit and where they do not.
A bank with entities in 14 countries adopts group rules for employee and customer data. Its global capability center in India is a group member, so transfers there are covered.
The same bank outsources collections to an independent provider. The group rules do nothing for that flow, and standard clauses have to be signed instead.
A manufacturer with a captive center in two markets decides the approval cost is not justified. Two sets of intra-group clauses are cheaper than a multi-year approval.
A group completes approval and then acquires a business in a new country. Bringing the acquisition inside the scheme takes another round of internal contracting.
Related terms
International transfer mechanisms differ by who they cover and who approves them. The entries below separate the group scheme from the off-the-shelf contract and the operating models involved.
- GDPR: the regulation that creates and governs the approval mechanism.
- GDPR outsourcing: how the same regime applies when a third party is involved.
- Data processing agreement: the instrument used for providers, which group rules cannot replace.
- Captive shared services: an internal model where intra-group transfers dominate.
- Compliance outsourcing: third-party work that always falls outside a group scheme.
FAQ
Who can use binding corporate rules?
A group of undertakings, or a group of enterprises engaged in a joint economic activity. Independent companies transacting with each other cannot.
How long does approval take?
Usually years rather than months, because a lead regulator reviews the scheme and other authorities are consulted before it is approved.
Do they cover transfers to outsourcing providers?
No. A provider outside the group is an onward transfer, and it needs its own safeguard such as standard contractual clauses.
Do individuals gain rights under them?
Yes. The rules must expressly confer enforceable rights on data subjects, which is one of the reasons approval is so demanding.
Are UK and European rules the same?
No longer. The United Kingdom operates its own approvals alongside its own transfer agreement, so multinationals may need both.
What happens when the group acquires a company?
The new entity must be brought inside the scheme through the group’s internal contracting, which takes time and does not happen automatically.
Explore how global delivery structures are organised at Outsource Accelerator.







Independent




