Article 47 of the GDPR: Binding Corporate Rules (BCR)

Article 47 of the GDPR: Binding Corporate Rules (BCR)

Article 47 of the GDPR Explained

BCRs are internal rules adopted by a multinational group, legally binding and enforceable, which must:

  • Be approved by a supervisory authority (such as the French supervisory authority);
  • Guarantee effective rights for data subjects (remedies, redress, transparency);
  • Define responsibilities, internal procedures, control and training mechanisms;
  • Be enforceable between group entities, regardless of their country of establishment.

Why This Article Matters for Your GDPR Compliance

BCRs are a sustainable and structuring solution for governing international intra-group transfers. They enable organisations to demonstrate a high level of compliance, even in a complex global context.

How to Comply with Article 47 of the GDPR

  • Identify intra-group data transfers to non-adequate countries;
  • Draft BCRs compliant with the requirements of Article 47;
  • Submit them for approval by the competent supervisory authority;
  • Ensure effective implementation (processes, documentation, training, etc.).

Practical Applications of GDPR Article 47

  • A French pharmaceutical group implements BCRs to govern transfers to its subsidiaries in the United States and Asia;
  • A tech company establishes an internal GDPR control committee to ensure compliance with BCRs;
  • An annual internal audit verifies the application of the binding corporate rules across all entities.

Related Resources

Accelerate Your Compliance in a Few Clicks

Thanks to our all-in-one solution, you can accelerate and ensure your compliance with ease:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise your teams' awareness with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.

GDPR: Self-assess now