EU Commissioner Reding Promotes Use of BCRs at IAPP Congress in Paris
Time 2 Minute Read

On November 29, 2011, at the International Association of Privacy Professionals (“IAPP”) Europe Data Protection Congress in Paris, France, Viviane Reding, Vice President of the European Commission and Commissioner for Justice, Fundamental Rights and Citizenship, provided insight into details of the proposals for the revised EU data protection framework. She focused explicitly on solutions for international data transfers, promoting Binding Corporate Rules ("BCRs") as a solution that can offer a simplified, yet comprehensive, structure for safeguarding international flows of data. Commissioner Reding referred to BCRs as offering the possibility of consistent enforcement and legal certainty, without stifling innovation.

Commissioner Reding's vision is for BCRs to become the tool of choice for organizations of all sizes and structures, which process data internationally, including those that process data in the cloud. She said she hoped BCRs would be recognized as more than merely a mechanism for facilitating intragroup transfers from the EU. She spoke of further simplifying the approval process for BCRs, so that a single data protection authority would be able to approve a BCR, without the need for additional local approvals. This would shorten the time taken to complete the approval process and dramatically reduce the cost of gaining approval.

Commissioner Reding characterized BCRs as accessible to all organizations and capable of governing all international data flows. According to Commissioner Reding, BCRs should be a code of practice for organizations, rather than merely a mechanism to facilitate international data transfers. In this spirit, she urged organizations to begin now to work on their BCRs.

View Commissioner Reding’s speech.

You May Also Be Interested In

Time 2 Minute Read

On April 29, 2025, the UK Information Commissioner’s Office and the California Privacy Protection Agency signed a declaration of cooperation regarding international privacy and data protection coordination, formalizing their existing collaboration.

Time 3 Minute Read

On April 29, 2025, the CNIL published its Annual Activity Report for 2024. The Report provides an overview of the CNIL’s activities in 2024, including enforcement activities and other new developments.

Time 2 Minute Read

On February 11, 2025, the data protection authorities of the UK, Ireland, France, South Korea and Australia issued a joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protective artificial intelligence.

Time 10 Minute Read

On February 7, 2025, the French Data Protection Authority (“CNIL”) released two recommendations aimed at guiding organizations in the responsible development and deployment of artificial intelligence (“AI”) systems in compliance with the EU General Data Protection Regulation (“GDPR”). The first recommendation is titled “AI: Informing Data Subjects” (the “Recommendation on Informing Individuals”) and the second recommendation is titled “AI: Complying and Facilitating Individuals’ Rights” (the “Recommendation on Individual Rights”). The recommendations build on the CNIL’s four-pillar AI action plan announced in 2023.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page