Binding Corporate Rules
Binding corporate rules are legally binding rules adhered to by companies established in the EU, specifically for transfers of personal data outside the EU within a group of undertakings or enterprises. Such rules include all general data protection principles and enforceable rights to ensure appropriate safeguards for data transfers. ABN AMRO has such ‘Binding Corporate Rules’ in place to safeguard transfers of personal data within ABN AMRO Group.
Why Binding Corporate Rules?
The rules governing the protection of personal data are not the same in all countries. Consequently, the European legislator has set out rules in the GDPR on how international transfers of personal information may take place in order to ensure that the level of protection of individuals guaranteed in the GDPR is not undermined. Binding Corporate Rules designed and approved according to the requirements of the GDPR constitute one of the mechanisms on which organisations can rely on for the adequate transfer of personal data. These rules apply to the personal information of both clients and employees.
Approval by Data Protection Authorities
ABN AMRO's Binding Corporate Rules have been approved by the Dutch Data Protection Authority and the European Data Protection Board (EDPB). Please be referred to the most recent version of our Binding Corporate Rules (2026), including its Annexes, below:
Binding Corporate Rules
ABN AMRO has internal rules that regulate the international exchange of personal information within the group. These rules are called Binding Corporate Rules.
Why Binding Corporate Rules?
The Binding Corporate Rules stem from the European Data Protection Directive. The rules governing the protection of personal information are not the same in all countries. Consequently, the European legislator has set out rules on how personal information is to be handled by international organizations. These rules apply to the personal information of both clients and employees. ABN AMRO's Binding Corporate Rules have been approved by the Dutch Data Protection Authority and the relevant European Data Protection Supervisors.
Please be referred to two versions of our Binding Corporate Rules (BCR’s) below. The first version from 2012 is approved by the authorized data protection authorities in accordance with the then applicable data protection legislation. The second version is an update with additions in accordance with the new General Data Protection Regulation (GDPR). ABN AMRO provided the second version as update to the Dutch data protection authority (Autoriteit Persoonsgegevens) at the moment the GDPR entered into force.