Juridique

Binding corporate rules and Article 49 GDPR derogations explained

When there is no adequacy decision and standard clauses do not fit, the GDPR offers binding corporate rules for groups and narrow derogations for specific situations. This page sets out what Articles 47 and 49 require.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

Binding corporate rules for groups

Binding corporate rules are data protection policies adhered to by a group of undertakings, or a group of enterprises engaged in a joint economic activity, for transfers to members of the group in third countries.

The competent supervisory authority approves them through the consistency mechanism of Article 63, provided they are legally binding on every member concerned, including employees, and expressly confer enforceable rights on data subjects.

They must also specify, among other things, how the general data protection principles apply, the rights of data subjects, and the acceptance by the EU-based member of liability for breaches by members outside the Union.

Article 49: derogations for specific situations

Without an adequacy decision or appropriate safeguards, a transfer may only take place on one of the listed conditions: explicit consent after being informed of the possible risks, necessity for a contract with or in the interest of the data subject, important reasons of public interest, legal claims, vital interests where the person cannot consent, or a transfer from a public register.

If none applies, a transfer is possible only if it is not repetitive, concerns a limited number of data subjects and is necessary for compelling legitimate interests not overridden by the person's rights. The controller must assess the circumstances, provide suitable safeguards, inform the supervisory authority and inform the data subject.

Questions fréquentes

Can public authorities rely on consent or contract derogations?

No. Points (a), (b) and (c) of Article 49(1) and the compelling legitimate interests route do not apply to activities carried out by public authorities in the exercise of their public powers.

Must the compelling legitimate interests assessment be documented?

Yes. The controller or processor must document the assessment and the suitable safeguards in the records of processing activities referred to in Article 30.

Can a whole public register be transferred?

No. A transfer from a register must not involve the entirety of the personal data or entire categories of data it contains. Where the register is open only to people with a legitimate interest, the transfer is made at their request or if they are the recipients.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-gdpr-official-texts-data-transfers": {
      "url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.