Article 29 Working Party Releases Updated Standard Application Forms for BCRs
Time 2 Minute Read

On April 11, 2018, the Article 29 Working Party (the “Working Party”) adopted two Recommendations on the Standard Application for Approval of Data Controller or Processor Binding Corporate Rules for the Transfer of Personal Data (the “Recommendations”). Binding Corporate Rules (“BCRs”) are one of the mechanisms offered to companies to transfer data outside the European Economic Area to a country which does not provide an adequate level of protection for the data according to Article 45 of the GDPR. These Recommendations, in the form of questionnaires, are intended to help BCR applicants demonstrate how they fulfill the requirements of Article 47 of the GDPR.

In addition, the Working Party also released a Working Document Setting Forth a Co-Operation Procedure for the Approval of “Binding Corporate Rules” for Controllers and Processors under the GDPR (“the Working Document”). The Working Document specifically refers to a scenario in which a group of undertakings or group of enterprises engaged in a joint economic activity, with entities in more than one Member State, wishes to submit draft BCRs to a Supervisory Authority (“SA”). In this case, the GDPR does not provide any guidance on how the group of undertakings or enterprises should determine their choice of SA as BCR Lead. The BCR Lead will act as the point of contact for the applicant during the approval process and will also manage the application throughout the cooperation phase with the relevant SAs. As such, the Working Document provides a series of criteria to identify the appropriate BCR Lead, such as the location of the group’s European Headquarters or the location of the company with the delegated data protection responsibilities. Finally, the Working Document also details the cooperation procedure to follow between the BCR Lead and the other relevant SAs for the approval of BCRs.

The Recommendations are available for data controllers and for data processors. View the Working Document.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page