Establishing Binding Corporate Rules
Overview
Binding Corporate Rules (BCRs) are internal data protection policies adopted by a multinational group of undertakings or enterprises to permit transfers of personal data from EU/EEA entities to group members in third countries under GDPR Article 47. BCRs provide a legally binding framework that ensures an essentially equivalent level of protection for personal data transferred within the corporate group, regardless of the destination country. The approval process involves a lead supervisory authority, a cooperation procedure among concerned SAs, and typically spans 12 to 18 months from initial submission to final approval.
Art. 47(2) Content Requirements
(a) Structure and Contact Details of the Group
The BCR must specify the structure of the group of undertakings or enterprises, including the identity and contact details of each member bound by the BCR.
Athena Global Logistics implementation:
- Group parent entity: Athena Global Logistics GmbH, Friedrichstrasse 112, 10117 Berlin, Germany
- Group DPO: Elisa Brandt, elisa.brandt@athenalogistics.eu, +49 30 1234 5678
- Bound entities: All wholly-owned subsidiaries and majority-controlled affiliates listed in BCR Annex A (currently 47 entities across 31 jurisdictions)
- Structure chart: Updated annually and annexed to the BCR as Annex A, reflecting the legal entity hierarchy from the parent to each subsidiary
(b) Data Transfers Covered
The BCR must describe the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected, and the identification of the third country or countries.
Implementation requirements:
- Scope document specifying all intra-group transfer categories: HR data (employee records, payroll, benefits), customer data (shipment records, billing, communications), supplier data (contact details, contractual records), and operational data (vehicle tracking, warehouse access logs)
- Purpose register linking each transfer category to one or more specified purposes: employment administration, freight operations, financial reporting, regulatory compliance, IT support
- Data subject taxonomy: employees, contractors, temporary workers, customers (individual and corporate contacts), suppliers, business partners, website visitors
- Destination country register: all non-EEA jurisdictions where bound group entities operate
(c) Legally Binding Nature
The BCR must establish the legally binding nature of the rules, both internally and externally.
Implementation elements:
- Intra-group agreement signed by all bound entities, creating contractual obligations enforceable between group members
- BCR adopted as a binding corporate policy by resolution of the board of the parent company, with cascading adoption resolutions by each subsidiary board
- Employee handbook incorporation: BCR summary and compliance obligations included in all employment contracts and data handling procedures
- External enforceability: explicit third-party beneficiary clause granting data subjects the right to enforce the BCR provisions directly against any bound entity
(d) Application of the General Data Protection Principles
The BCR must demonstrate the application of all general data protection principles under Article 5, including purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis, special category data processing, and measures to ensure data security.
Required content:
- Purpose limitation: data transferred under the BCR may be processed only for the purposes specified in the BCR scope document; any new purpose requires a compatibility assessment under Art. 6(4) and BCR amendment procedure
- Data minimisation: transfers limited to data adequate, relevant, and necessary for the specified purpose; group-wide data classification policy mandating review of data elements before transfer
- Storage limitation: retention schedules specified per data category and jurisdiction; automated deletion or anonymisation upon expiry
- Accuracy: procedures for data subjects to request correction; data quality checks at transfer points
- Security: minimum security standards applicable to all bound entities per BCR Annex C (aligned with ISO 27001:2022)
(e) Third-Party Beneficiary Rights
Data subjects must be able to enforce the BCR as third-party beneficiaries and have the right to:
- Receive compensation for material and non-material damages resulting from BCR violations
- Lodge complaints with the competent supervisory authority
- Exercise all data subject rights (access, rectification, erasure, restriction, portability, objection) against any bound entity
(f) Acceptance of Liability
The BCR must include acceptance of liability by the entity established in the EU (the BCR Lead) for any breach committed by a non-EU bound entity, with the burden of proof on the BCR Lead to demonstrate the non-EU entity was not responsible.
Athena Global Logistics implementation:
- BCR Lead: Athena Global Logistics GmbH (Berlin)
- Liability clause: The BCR Lead accepts liability for breaches by any non-EU bound entity and agrees to take necessary action to remedy the breach and pay compensation
- Insurance: professional indemnity insurance covering BCR-related claims with a minimum coverage of EUR 10,000,000 per claim
(g) Information Provided to Data Subjects
The BCR must specify the information provided to data subjects about the BCR and their rights, including:
- The BCR and a summary in plain language published on the company website
- Information about the complaints procedure and the right to lodge a complaint with the SA
- Information about the right to seek judicial remedies
- The identity and contact details of the BCR Lead and the DPO
(h) DPO Tasks
The BCR must describe the tasks of the Data Protection Officer (or equivalent responsible person/entity), including:
- Monitoring BCR compliance across all bound entities
- Conducting or overseeing BCR audits
- Handling data subject complaints related to BCR transfers
- Serving as the contact point for supervisory authorities
- Reporting to the board on BCR compliance status
(i) Complaint Procedures
The BCR must establish a complaints mechanism enabling data subjects to:
- Submit complaints to any bound entity or the BCR Lead
- Receive a response within 30 calendar days
- Escalate unresolved complaints to the DPO, then to the competent SA
- Access mediation or arbitration as an alternative dispute resolution mechanism
(j) Compliance Verification Mechanisms
The BCR must describe mechanisms for ensuring compliance:
- Internal BCR audit programme: conducted by the internal audit function, with at least one full-cycle audit every three years covering all bound entities
- Annual compliance self-assessments by each bound entity, reported to the DPO
- Monitoring tools: data transfer logging, access reviews, policy adherence metrics
- Results reported to the BCR Lead's management and, upon request, to the competent SA
(k) Change Reporting Mechanisms
The BCR must establish reporting and recording mechanisms for changes:
- Amendment procedure: any change to the BCR requires approval by the BCR Lead, notification to the lead SA, and communication to all bound entities
- Annual update cycle for the entity list (Annex A) and security standards (Annex C)
- Material changes (new countries, new data categories, structural changes) must be notified to the SA before implementation
(l) Cooperation with the Supervisory Authority
The BCR must establish a cooperation mechanism with the SA:
- The BCR Lead will submit to the jurisdiction of the competent SA
- The BCR Lead will make audit results available to the SA upon request
- The BCR Lead will comply with SA advice regarding BCR interpretation and application
- Annual BCR compliance report submitted to the lead SA
(m) Local Law Reporting
The BCR must require any bound entity to report to the BCR Lead any legal requirement in its jurisdiction that is likely to have a substantial adverse effect on the guarantees provided by the BCR.
Implementation:
- Annual local law survey conducted by outside counsel in each jurisdiction
- Immediate escalation procedure for new legislation or government access demands that conflict with BCR commitments
- Assessment protocol: evaluate whether the local law requirement materially undermines BCR protections and, if so, notify the SA and suspend affected transfers
(n) Training
The BCR must describe appropriate data protection training for personnel with access to transferred data:
- Mandatory onboarding training for all new employees with data access
- Annual refresher training on BCR requirements, data subject rights, and breach reporting
- Role-specific training for IT administrators, HR staff, and customer-facing personnel
- Training records maintained centrally and available for SA audit
BCR Approval Process
Step 1: Preparation (Months 1-3)
- Draft the BCR document against the WP256 rev.01 referential (BCR for controllers) or WP257 rev.01 referential (BCR for processors).
- Map all intra-group data flows to identify the transfers covered by the BCR.
- Prepare the Annex A entity list, Annex B transfer scope, and Annex C security standards.
- Conduct a gap analysis against the referential checklist.
- Prepare the BCR application form for the lead SA.
Step 2: Lead SA Identification (Month 3)
- Identify the lead SA per the EDPB criteria: the SA of the Member State where the BCR Lead (typically the parent or the entity with delegated data protection responsibility) is established.
- For Athena Global Logistics: the lead SA is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit (BlnBDI).
- Identify concerned SAs: all SAs of Member States where bound entities are established.
Step 3: Formal Submission (Month 4)
- Submit the BCR application to the lead SA with all supporting documentation.
- Include: BCR text, entity list, data flow maps, gap analysis results, evidence of internal approval, DPO contact details.
Step 4: Lead SA Review (Months 4-9)
- The lead SA reviews the BCR for completeness and compliance with Art. 47(2).
- Expect multiple rounds of questions and amendments.
- Maintain a correspondence log and amendment tracker.
- Typical duration: 4-6 months of iterative review.
Step 5: Cooperation Procedure (Months 9-12)
- The lead SA circulates the reviewed BCR to all concerned SAs.
- Concerned SAs have a defined period (typically 2 months) to raise objections or comments.
- The lead SA consolidates feedback and works with the applicant to address concerns.
- If consensus is reached, the lead SA provides a positive opinion.
Step 6: Consistency Mechanism (Months 12-14)
- Under Art. 63-64 GDPR, the lead SA may submit the draft approval to the EDPB for an opinion if there are unresolved objections.
- The EDPB issues an opinion within 8 weeks (extendable by 6 weeks).
Step 7: Formal Approval (Months 14-18)
- The lead SA issues the formal BCR approval decision.
- The approval may include conditions or recommendations.
- The BCR Lead must implement any conditions before relying on the BCR for transfers.
- Publish the approved BCR summary on the EDPB BCR register and the company website.
Step 8: Implementation and Rollout (Post-Approval)
- Communicate the approved BCR to all bound entities.
- Execute the intra-group agreement binding all entities.
- Deploy the training programme.
- Activate the audit programme.
- Begin the monitoring and reporting cycle.
WP256 Rev.01 Referential (BCR for Controllers) — Key Elements Checklist
| Element |
WP256 Section |
Status |
| Binding nature of the BCR |
Section 1 |
Required |
| Scope — data, transfers, entities |
Section 2 |
Required |
| Application of GDPR principles |
Section 3 |
Required |
| Rights of data subjects and enforcement |
Section 4 |
Required |
| Liability and jurisdiction |
Section 5 |
Required |
| Cooperation duty with SAs |
Section 5.4 |
Required |
| How to handle requests from authorities |
Section 5.5 |
Required |
| Complaint handling |
Section 6 |
Required |
| Training programme |
Section 7 |
Required |
| Audit programme |
Section 7 |
Required |
| Network of privacy officers |
Section 7.3 |
Required |
| Update and change management |
Section 8 |
Required |
| Local law conflicts |
Section 5.5 |
Required |
| Description of conflict resolution |
Section 6 |
Required |
WP257 Rev.01 Referential (BCR for Processors) — Additional Elements
| Element |
Description |
| Instructions-based processing |
Processor BCR must confirm processing only on documented instructions |
| Sub-processor management |
Procedures for sub-processor authorisation, due diligence, and contractual flow-down |
| Controller notification |
Obligation to inform the controller of any inability to comply |
| Data return/deletion |
Procedures upon termination of the processing relationship |
| Audit facilitation |
Obligation to make available all information necessary to demonstrate compliance |
Post-Approval Ongoing Obligations
- Annual compliance audit: At least one comprehensive BCR audit per year, with each bound entity audited within a three-year rolling cycle.
- Entity list maintenance: Annex A updated whenever entities join or leave the group; SA notified of material changes.
- Incident reporting: Any breach involving BCR-covered data reported to the BCR Lead and, where required, to the competent SA per Art. 33.
- Local law monitoring: Continuous monitoring of legal developments in third countries that may affect BCR protections.
- Training records: Maintained and available for SA review at all times.
- BCR review and amendment: Full BCR review at least every three years, with interim amendments as needed for material changes.
1---2name: bcr-establishment3description: Guides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(n) content requirements, BCR approval process with lead supervisory authority, and WP256/WP257 referentials. Keywords: BCR, binding corporate rules, intra-group transfers, Art. 47.4license: Apache-2.05---6# Establishing Binding Corporate Rules
7
8## Overview
9
10Binding Corporate Rules (BCRs) are internal data protection policies adopted by a multinational group of undertakings or enterprises to permit transfers of personal data from EU/EEA entities to group members in third countries under GDPR Article 47. BCRs provide a legally binding framework that ensures an essentially equivalent level of protection for personal data transferred within the corporate group, regardless of the destination country. The approval process involves a lead supervisory authority, a cooperation procedure among concerned SAs, and typically spans 12 to 18 months from initial submission to final approval.
11
12## Art. 47(2) Content Requirements
13
14### (a) Structure and Contact Details of the Group
15
16The BCR must specify the structure of the group of undertakings or enterprises, including the identity and contact details of each member bound by the BCR.
17
18**Athena Global Logistics implementation**:
19- Group parent entity: Athena Global Logistics GmbH, Friedrichstrasse 112, 10117 Berlin, Germany
20- Group DPO: Elisa Brandt, elisa.brandt@athenalogistics.eu, +49 30 1234 5678
21- Bound entities: All wholly-owned subsidiaries and majority-controlled affiliates listed in BCR Annex A (currently 47 entities across 31 jurisdictions)
22- Structure chart: Updated annually and annexed to the BCR as Annex A, reflecting the legal entity hierarchy from the parent to each subsidiary
23
24### (b) Data Transfers Covered
25
26The BCR must describe the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected, and the identification of the third country or countries.
27
28**Implementation requirements**:
29- Scope document specifying all intra-group transfer categories: HR data (employee records, payroll, benefits), customer data (shipment records, billing, communications), supplier data (contact details, contractual records), and operational data (vehicle tracking, warehouse access logs)
30- Purpose register linking each transfer category to one or more specified purposes: employment administration, freight operations, financial reporting, regulatory compliance, IT support
31- Data subject taxonomy: employees, contractors, temporary workers, customers (individual and corporate contacts), suppliers, business partners, website visitors
32- Destination country register: all non-EEA jurisdictions where bound group entities operate
33
34### (c) Legally Binding Nature
35
36The BCR must establish the legally binding nature of the rules, both internally and externally.
37
38**Implementation elements**:
39- Intra-group agreement signed by all bound entities, creating contractual obligations enforceable between group members
40- BCR adopted as a binding corporate policy by resolution of the board of the parent company, with cascading adoption resolutions by each subsidiary board
41- Employee handbook incorporation: BCR summary and compliance obligations included in all employment contracts and data handling procedures
42- External enforceability: explicit third-party beneficiary clause granting data subjects the right to enforce the BCR provisions directly against any bound entity
43
44### (d) Application of the General Data Protection Principles
45
46The BCR must demonstrate the application of all general data protection principles under Article 5, including purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis, special category data processing, and measures to ensure data security.
47
48**Required content**:
49- Purpose limitation: data transferred under the BCR may be processed only for the purposes specified in the BCR scope document; any new purpose requires a compatibility assessment under Art. 6(4) and BCR amendment procedure
50- Data minimisation: transfers limited to data adequate, relevant, and necessary for the specified purpose; group-wide data classification policy mandating review of data elements before transfer
51- Storage limitation: retention schedules specified per data category and jurisdiction; automated deletion or anonymisation upon expiry
52- Accuracy: procedures for data subjects to request correction; data quality checks at transfer points
53- Security: minimum security standards applicable to all bound entities per BCR Annex C (aligned with ISO 27001:2022)
54
55### (e) Third-Party Beneficiary Rights
56
57Data subjects must be able to enforce the BCR as third-party beneficiaries and have the right to:
58- Receive compensation for material and non-material damages resulting from BCR violations
59- Lodge complaints with the competent supervisory authority
60- Exercise all data subject rights (access, rectification, erasure, restriction, portability, objection) against any bound entity
61
62### (f) Acceptance of Liability
63
64The BCR must include acceptance of liability by the entity established in the EU (the BCR Lead) for any breach committed by a non-EU bound entity, with the burden of proof on the BCR Lead to demonstrate the non-EU entity was not responsible.
65
66**Athena Global Logistics implementation**:
67- BCR Lead: Athena Global Logistics GmbH (Berlin)
68- Liability clause: The BCR Lead accepts liability for breaches by any non-EU bound entity and agrees to take necessary action to remedy the breach and pay compensation
69- Insurance: professional indemnity insurance covering BCR-related claims with a minimum coverage of EUR 10,000,000 per claim
70
71### (g) Information Provided to Data Subjects
72
73The BCR must specify the information provided to data subjects about the BCR and their rights, including:
74- The BCR and a summary in plain language published on the company website
75- Information about the complaints procedure and the right to lodge a complaint with the SA
76- Information about the right to seek judicial remedies
77- The identity and contact details of the BCR Lead and the DPO
78
79### (h) DPO Tasks
80
81The BCR must describe the tasks of the Data Protection Officer (or equivalent responsible person/entity), including:
82- Monitoring BCR compliance across all bound entities
83- Conducting or overseeing BCR audits
84- Handling data subject complaints related to BCR transfers
85- Serving as the contact point for supervisory authorities
86- Reporting to the board on BCR compliance status
87
88### (i) Complaint Procedures
89
90The BCR must establish a complaints mechanism enabling data subjects to:
91- Submit complaints to any bound entity or the BCR Lead
92- Receive a response within 30 calendar days
93- Escalate unresolved complaints to the DPO, then to the competent SA
94- Access mediation or arbitration as an alternative dispute resolution mechanism
95
96### (j) Compliance Verification Mechanisms
97
98The BCR must describe mechanisms for ensuring compliance:
99- Internal BCR audit programme: conducted by the internal audit function, with at least one full-cycle audit every three years covering all bound entities
100- Annual compliance self-assessments by each bound entity, reported to the DPO
101- Monitoring tools: data transfer logging, access reviews, policy adherence metrics
102- Results reported to the BCR Lead's management and, upon request, to the competent SA
103
104### (k) Change Reporting Mechanisms
105
106The BCR must establish reporting and recording mechanisms for changes:
107- Amendment procedure: any change to the BCR requires approval by the BCR Lead, notification to the lead SA, and communication to all bound entities
108- Annual update cycle for the entity list (Annex A) and security standards (Annex C)
109- Material changes (new countries, new data categories, structural changes) must be notified to the SA before implementation
110
111### (l) Cooperation with the Supervisory Authority
112
113The BCR must establish a cooperation mechanism with the SA:
114- The BCR Lead will submit to the jurisdiction of the competent SA
115- The BCR Lead will make audit results available to the SA upon request
116- The BCR Lead will comply with SA advice regarding BCR interpretation and application
117- Annual BCR compliance report submitted to the lead SA
118
119### (m) Local Law Reporting
120
121The BCR must require any bound entity to report to the BCR Lead any legal requirement in its jurisdiction that is likely to have a substantial adverse effect on the guarantees provided by the BCR.
122
123**Implementation**:
124- Annual local law survey conducted by outside counsel in each jurisdiction
125- Immediate escalation procedure for new legislation or government access demands that conflict with BCR commitments
126- Assessment protocol: evaluate whether the local law requirement materially undermines BCR protections and, if so, notify the SA and suspend affected transfers
127
128### (n) Training
129
130The BCR must describe appropriate data protection training for personnel with access to transferred data:
131- Mandatory onboarding training for all new employees with data access
132- Annual refresher training on BCR requirements, data subject rights, and breach reporting
133- Role-specific training for IT administrators, HR staff, and customer-facing personnel
134- Training records maintained centrally and available for SA audit
135
136## BCR Approval Process
137
138### Step 1: Preparation (Months 1-3)
139
1401. Draft the BCR document against the WP256 rev.01 referential (BCR for controllers) or WP257 rev.01 referential (BCR for processors).
1412. Map all intra-group data flows to identify the transfers covered by the BCR.
1423. Prepare the Annex A entity list, Annex B transfer scope, and Annex C security standards.
1434. Conduct a gap analysis against the referential checklist.
1445. Prepare the BCR application form for the lead SA.
145
146### Step 2: Lead SA Identification (Month 3)
147
1481. Identify the lead SA per the EDPB criteria: the SA of the Member State where the BCR Lead (typically the parent or the entity with delegated data protection responsibility) is established.
1492. For Athena Global Logistics: the lead SA is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit (BlnBDI).
1503. Identify concerned SAs: all SAs of Member States where bound entities are established.
151
152### Step 3: Formal Submission (Month 4)
153
1541. Submit the BCR application to the lead SA with all supporting documentation.
1552. Include: BCR text, entity list, data flow maps, gap analysis results, evidence of internal approval, DPO contact details.
156
157### Step 4: Lead SA Review (Months 4-9)
158
1591. The lead SA reviews the BCR for completeness and compliance with Art. 47(2).
1602. Expect multiple rounds of questions and amendments.
1613. Maintain a correspondence log and amendment tracker.
1624. Typical duration: 4-6 months of iterative review.
163
164### Step 5: Cooperation Procedure (Months 9-12)
165
1661. The lead SA circulates the reviewed BCR to all concerned SAs.
1672. Concerned SAs have a defined period (typically 2 months) to raise objections or comments.
1683. The lead SA consolidates feedback and works with the applicant to address concerns.
1694. If consensus is reached, the lead SA provides a positive opinion.
170
171### Step 6: Consistency Mechanism (Months 12-14)
172
1731. Under Art. 63-64 GDPR, the lead SA may submit the draft approval to the EDPB for an opinion if there are unresolved objections.
1742. The EDPB issues an opinion within 8 weeks (extendable by 6 weeks).
175
176### Step 7: Formal Approval (Months 14-18)
177
1781. The lead SA issues the formal BCR approval decision.
1792. The approval may include conditions or recommendations.
1803. The BCR Lead must implement any conditions before relying on the BCR for transfers.
1814. Publish the approved BCR summary on the EDPB BCR register and the company website.
182
183### Step 8: Implementation and Rollout (Post-Approval)
184
1851. Communicate the approved BCR to all bound entities.
1862. Execute the intra-group agreement binding all entities.
1873. Deploy the training programme.
1884. Activate the audit programme.
1895. Begin the monitoring and reporting cycle.
190
191## WP256 Rev.01 Referential (BCR for Controllers) — Key Elements Checklist
192
193| Element | WP256 Section | Status |
194|---------|--------------|--------|
195| Binding nature of the BCR | Section 1 | Required |
196| Scope — data, transfers, entities | Section 2 | Required |
197| Application of GDPR principles | Section 3 | Required |
198| Rights of data subjects and enforcement | Section 4 | Required |
199| Liability and jurisdiction | Section 5 | Required |
200| Cooperation duty with SAs | Section 5.4 | Required |
201| How to handle requests from authorities | Section 5.5 | Required |
202| Complaint handling | Section 6 | Required |
203| Training programme | Section 7 | Required |
204| Audit programme | Section 7 | Required |
205| Network of privacy officers | Section 7.3 | Required |
206| Update and change management | Section 8 | Required |
207| Local law conflicts | Section 5.5 | Required |
208| Description of conflict resolution | Section 6 | Required |
209
210## WP257 Rev.01 Referential (BCR for Processors) — Additional Elements
211
212| Element | Description |
213|---------|-------------|
214| Instructions-based processing | Processor BCR must confirm processing only on documented instructions |
215| Sub-processor management | Procedures for sub-processor authorisation, due diligence, and contractual flow-down |
216| Controller notification | Obligation to inform the controller of any inability to comply |
217| Data return/deletion | Procedures upon termination of the processing relationship |
218| Audit facilitation | Obligation to make available all information necessary to demonstrate compliance |
219
220## Post-Approval Ongoing Obligations
221
2221. **Annual compliance audit**: At least one comprehensive BCR audit per year, with each bound entity audited within a three-year rolling cycle.
2232. **Entity list maintenance**: Annex A updated whenever entities join or leave the group; SA notified of material changes.
2243. **Incident reporting**: Any breach involving BCR-covered data reported to the BCR Lead and, where required, to the competent SA per Art. 33.
2254. **Local law monitoring**: Continuous monitoring of legal developments in third countries that may affect BCR protections.
2265. **Training records**: Maintained and available for SA review at all times.
2276. **BCR review and amendment**: Full BCR review at least every three years, with interim amendments as needed for material changes.