Processor Binding Corporate Rules — the EDPB’s draft Recommendations 1/2026
When a processor group moves personal data to its own companies outside the EEA on a client’s behalf, Binding Corporate Rules for processors are the transfer tool built for exactly that shape of transfer — and the reference document describing what they must contain has to date been a table the Article 29 Working Party adopted in 2018. The EDPB’s draft Recommendations 1/2026 are set to replace that referential and the separate application form with a single 57-page document: what a BCR-P must say, what goes to the lead supervisory authority instead, and how the approval runs. It is a draft — the consultation closed on 2 March 2026 and the final version has not yet been published — but it is the fullest statement we have found of what the EEA authorities expect to see, and the scope clarifications in its opening pages are useful on their own.
- Published by
- European Data Protection Board (EDPB). We have no relationship with the EDPB and this is not an endorsement in either direction.
- Type
- Draft Recommendations under Art. 70(1)(i) GDPR, in three parts: an introduction settling scope and status questions; the standard application form (Part 1 applicant information, Part 2 with annexes, submitted in stages to the BCR Lead); and a 12-section tabular referential of the elements and principles a BCR-P must contain — each row stating what must appear in the BCR-P itself, what is instead presented to the BCR Lead in the application, and the GDPR basis. On publication of the final version it will repeal and replace WP257 rev.01 (the 2018 elements-and-principles table) and WP265 (the 2018 standard application form), while in substance building on them.
- Versions & language
- Version 1 — a draft, adopted for public consultation 15 January 2026. Consultation closed 2 March 2026. The final version has not been published — re-checked on the EDPB’s own consultation page on 23 September 2026, where the document still sits under public consultations. The Recommendations state they become effective only on publication of the final version, so WP257 rev.01 and WP265 remain the operative documents until then. English.
- Jurisdiction
- EU / EEA. BCRs are an Art. 46(2)(b) / Art. 47 GDPR transfer tool; approval sits with a lead EEA supervisory authority, with an EDPB opinion under Art. 64. Not a UK instrument — UK BCRs are a separate regime approved by the ICO under UK GDPR Art. 47, and these Recommendations do not apply to them. Groups holding parallel EU and UK BCRs will meet this text on the EU side.
- Primary audience
- DPOs and privacy counsel in processor groups (SaaS, outsourcing, managed services) holding or contemplating BCR-P; controllers doing vendor due diligence where a supplier relies on group BCRs; anyone maintaining a transfer-tool inventory.
- Topic tags
- international transfers · Chapter V · BCR-P · Art. 47 · Art. 28 · sub-processors · supervisory authority approval
- Availability
- Free, no registration, direct PDF from edpb.europa.eu.
Why it matters
The scope clarifications in the opening pages answer questions that come up in ordinary vendor negotiations, and they answer them on the record.
- When BCR-P actually cover a transfer. They apply where group members within GDPR scope act as processors for a controller outside the group, and pass the data to group members in third countries as sub-processors. They are expressly not suitable for a direct transfer from the external controller to a third-country group entity — that needs a different Art. 46 tool. If a supplier answers a due-diligence question with “we have BCRs”, this is the paragraph that says whether that answer reaches your transfer.
- One agreement fewer per sub-processor. The BCR-P are designed to meet Art. 28(4) GDPR, so a group member processing under them does not need to sign a separate sub-processing agreement with each group sub-processor — though controller instructions must still flow down, and the Art. 28(3) processing agreement between the external controller and the group must still be signed, and should reference the BCR-P and make them enforceable by the controller.
- What approval does and does not mean. Approval confirms the Art. 47 requirements are met; it is not a compliance assessment of the underlying processing, and — worth having in writing — case-by-case supplementary-measures assessments under the Recommendations 01/2020 line remain the responsibility of the exporting processor and the instructing controller. The exporter implements, the controller verifies, and neither is assessed as part of BCR-P approval.
- What is coming for existing holders. Once final, existing BCR-P holders must align through their annual update, generally without a fresh approval; new and in-flight applications are expected to meet the new requirements, with transition dates left as placeholders for the final text.
The referential itself then works through the full expected contents across twelve sections — binding nature and third-party beneficiary rights, scope, effectiveness (training, audit — including that DPOs should not be the ones auditing BCR-P compliance where that would create a conflict of interests), the cooperation duty, the data protection safeguards, data subject rights, tools for compliance, local laws and government access requests, termination, non-compliance, and the mechanisms for reporting and recording changes.
The commercial line is straightforward and runs both ways. For processor groups, an approved BCR-P is a sales asset — one approved instrument in place of transfer paperwork negotiated deal by deal. For controllers, knowing the scope rule means a vendor’s “we have BCRs” gets the right follow-up question in the meeting rather than a discovery later. Either way, the expectations are now in one document instead of three, and reading them costs nothing — and we hope you find it useful.
Read alongside the EDPB Guidelines 01/2025 on Pseudonymisation — pseudonymisation is a recurring candidate supplementary measure for transfers — and the CNIL Security of Personal Data guide, a practical catalogue of the security measures a BCR-P has to describe.
