Legal

Binding corporate rules and Article 49 GDPR derogations explained

When there is no adequacy decision and standard clauses do not fit, the GDPR offers binding corporate rules for groups and narrow derogations for specific situations. This page sets out what Articles 47 and 49 require.

Ask your question

Free account required

Each question stands alone · 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

Binding corporate rules for groups

Binding corporate rules are data protection policies adhered to by a group of undertakings, or a group of enterprises engaged in a joint economic activity, for transfers to members of the group in third countries.

The competent supervisory authority approves them through the consistency mechanism of Article 63, provided they are legally binding on every member concerned, including employees, and expressly confer enforceable rights on data subjects.

They must also specify, among other things, how the general data protection principles apply, the rights of data subjects, and the acceptance by the EU-based member of liability for breaches by members outside the Union.

Article 49: derogations for specific situations

Without an adequacy decision or appropriate safeguards, a transfer may only take place on one of the listed conditions: explicit consent after being informed of the possible risks, necessity for a contract with or in the interest of the data subject, important reasons of public interest, legal claims, vital interests where the person cannot consent, or a transfer from a public register.

If none applies, a transfer is possible only if it is not repetitive, concerns a limited number of data subjects and is necessary for compelling legitimate interests not overridden by the person's rights. The controller must assess the circumstances, provide suitable safeguards, inform the supervisory authority and inform the data subject.

Frequently asked questions

Can public authorities rely on consent or contract derogations?

No. Points (a), (b) and (c) of Article 49(1) and the compelling legitimate interests route do not apply to activities carried out by public authorities in the exercise of their public powers.

Must the compelling legitimate interests assessment be documented?

Yes. The controller or processor must document the assessment and the suitable safeguards in the records of processing activities referred to in Article 30.

Can a whole public register be transferred?

No. A transfer from a register must not involve the entirety of the personal data or entire categories of data it contains. Where the register is open only to people with a legitimate interest, the transfer is made at their request or if they are the recipients.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-gdpr-official-texts-data-transfers": {
      "url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.