CEPD Approves Input on Police-Justice Directive and New BCR Subcontractor Framework

Updated Guidance on Binding Corporate Rules for Standard Contractual Clauses (BCR-ST)

The European Data Protection Board (EDPB) has released draft recommendations updating the guidance on Binding Corporate Rules for Standard Contractual Clauses (BCR-ST), used for data transfers outside the European Economic Area (EEA). These rules, outlined in Article 46 of the General Data Protection Regulation (GDPR), allow groups of companies to transfer personal data to their affiliates outside the EEA when operating as a data processor for a data controller not within the same corporate group.

What are BCR-STs?

BCR-STs are a mechanism for transferring personal data under Article 46 of the GDPR.They are designed for use by a corporate group acting as a data processor on behalf of a data controller outside of the group. They establish legally binding rights and obligations to ensure a level of data protection essentially equivalent to that guaranteed by the GDPR. This is particularly relevant when a multinational company uses shared service centers or other intra-group data processing arrangements.

Building on Existing Frameworks

The new recommendations build upon agreements already reached by data protection authorities and the collective experience gained from approving numerous BCR-ST applications since the GDPR’s implementation. They also draw on learnings from the development of the EDPB’s Recommendation 1/2022 regarding Binding Corporate Rules for Controllers (BCR-C) – Article 47 of the GDPR.

Key Clarifications in the New Recommendations

The draft recommendations provide clarified criteria to ensure GDPR compliance for BCR-STs developed by corporate groups. A key point is that BCR-STs are specifically intended for intra-group transfers between data processors when the data controller is not part of the same group.

Furthermore, the recommendations establish that BCR-STs are designed to meet the requirements of Article 28(4) of the GDPR. This means that a processor within a group utilizing BCR-STs does not need to sign individual data processing agreements wiht other processors within the same group.

Consultation Period

The draft recommendations are open for public consultation until March 2, 2026. This is an opportunity for stakeholders to provide feedback and contribute to the final guidance.

during their recent meeting, members of the EDPB also discussed a forthcoming joint opinion on the Digital Services Act (DSA), with its release expected during the February plenary session.

Key Takeaways

  • BCR-STs facilitate data transfers outside the EEA for processor-to-processor arrangements within a corporate group.
  • The new recommendations clarify the scope and requirements for BCR-ST compliance.
  • BCR-STs align with Article 28(4) of the GDPR, reducing the need for individual processing agreements within groups.
  • The draft recommendations are currently under public consultation until March 2, 2026.

Leave a Comment