Skip to main content
GDPRRegulation (EU) 2016/679

Definition: binding corporate rules: binding corporate rules

GDPR Art. 4 (binding corporate rules)

personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity

Defines (1)

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

GDPR 32016R0679

Every connection on this page is drawn from the official text of Regulation (EU) 2016/679. Study aid, not legal advice.

See how GDPR sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.

Useful to someone you work with?

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.