Binding Corporate Rules
Binding corporate rules are legally binding rules adhered to by companies established in the EU, specifically for transfers of personal data outside the EU within a group of undertakings or enterprises. Such rules include all general data protection principles and enforceable rights to ensure appropriate safeguards for data transfers. ABN AMRO has such ‘Binding Corporate Rules’ in place to safeguard transfers of personal data within ABN AMRO Group.
Why Binding Corporate Rules?
The rules governing the protection of personal data are not the same in all countries. Consequently, the European legislator has set out rules in the GDPR on how international transfers of personal information may take place in order to ensure that the level of protection of individuals guaranteed in the GDPR is not undermined.
Binding Corporate Rules designed and approved according to the requirements of the GDPR constitute one of the mechanisms on which organisations can rely for the adequate transfer of personal data. These rules apply to the personal information of both clients and employees.
Approval by Data Protection Authorities
ABN AMRO's Binding Corporate Rules have been approved by the Dutch Data Protection Authority and the European Data Protection Board (EDPB).
Most recent Binding Corporate Rules
Please be referred to the most recent version of our Binding Corporate Rules (approved in 2026), including its Annexes, below:
Previous Binding Corporate Rules
Please be referred to two previous versions of our Binding Corporate Rules (BCR’s) below. The version from 2012 was approved by the authorized data protection authorities in accordance with the then applicable data protection legislation. The version from 2018 contains additions in accordance with the General Data Protection Regulation (GDPR). ABN AMRO provided this version as update to the Dutch data protection authority (Autoriteit Persoonsgegevens) at the moment the GDPR entered into force.