Skip to main content
GDPRRegulation (EU) 2016/679

Definition: binding corporate rules: binding corporate rules

GDPR Art. 4 (binding corporate rules)

personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity

Defines (1)

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

GDPR 32016R0679

Every connection on this page is drawn from the official text of Regulation (EU) 2016/679. Study aid, not legal advice.

See how GDPR sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.