Article 47 of the GDPR: Binding Corporate Rules (BCR)
Article 47 of the GDPR Explained
BCRs are internal rules adopted by a multinational group, legally binding and enforceable, which must:
- Be approved by a supervisory authority (such as the French supervisory authority);
- Guarantee effective rights for data subjects (remedies, redress, transparency);
- Define responsibilities, internal procedures, control and training mechanisms;
- Be enforceable between group entities, regardless of their country of establishment.
Why This Article Matters for Your GDPR Compliance
BCRs are a sustainable and structuring solution for governing international intra-group transfers. They enable organisations to demonstrate a high level of compliance, even in a complex global context.
Practical Applications of GDPR Article 47
- A French pharmaceutical group implements BCRs to govern transfers to its subsidiaries in the United States and Asia;
- A tech company establishes an internal GDPR control committee to ensure compliance with BCRs;
- An annual internal audit verifies the application of the binding corporate rules across all entities.
Related Resources
Accelerate Your Compliance in a Few Clicks
Thanks to our all-in-one solution, you can accelerate and ensure your compliance with ease:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise your teams' awareness with our GDPR training e-learning
Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.
How to Comply with Article 47 of the GDPR