GDPRRegulation (EU) 2016/679
Definition: binding corporate rules: binding corporate rules
GDPR Art. 4 (binding corporate rules)
personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity
Defines (1)
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2016/679. Study aid, not legal advice.
See how GDPR sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.