Binding corporate rules

Data protection policies approved by a supervisory authority that let a group of companies transfer personal data within the group to countries outside the EU (GDPR Article 47).

They must be legally binding on every member of the group, give data subjects enforceable rights and cover the points Article 47(2) lists. They cover transfers inside the group only, so a vendor’s transfers to outside subprocessors still need a mechanism of their own.

Source: GDPR Art. 47 ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.