EU regulatory register · GDPR
Article 47Binding corporate rules
CELEX 32016R0679 · Read on 2026-08-18 · Chapter V
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. The competent supervisory authority shall approve binding corporate rules in accordance with the consistency mechanism set out in Article 63, provided that they:
(a)
are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees;
(b)
expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and
(c)
fulfil the requirements laid down in paragraph 2.
2. The binding corporate rules referred to in paragraph 1 shall specify at least:
(a)
the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity and of each of its members;
(b)
the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of the third country or countries in question;
(c)
their legally binding nature, both internally and externally;
The article continues in the official text.
Other articles in this chapter
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act