Binding Corporate Rules (BCRs) — DPC as Lead and Art. 47 GDPR requirements
Binding Corporate Rules (BCRs) offer multinational groups a lawful transfer path for personal data from Ireland (EEA) to non-EEA affiliates under Chapter V of the GDPR.
Article 47 GDPR – BCR substance Article 47 GDPR mandates that the competent supervisory authority approve BCRs following the coherence mechanism in Article 63. BCRs must be:
- legally binding and enforced across all group members, including employees;
- expressly confer enforceable rights on data subjects;
- include each of the elements listed in Article 47(2), such as group structure and contact details; categories and purposes of transfers; enforceability; protection of data subjects’ rights; onward transfers; and liability and redress mechanisms.
Source: Article 47 GDPR
DPC’s role as Lead Authority As Ireland hosts many multinational headquarters, the Data Protection Commission (DPC) regularly serves as Lead Supervisory Authority (LSA) for BCR applications. The DPC evaluates the submission, consults other supervisory authorities via the Article 64 / Article 63 EDPB cooperation process, and issues a national approval decision once GDPR criteria are satisfied.
In 2023, the DPC acted as LSA for 26 approved Controller and Processor BCRs across 18 groups. Of those, four BCRs (Controller and Processor for Autodesk Ireland Operation Unlimited and Informatica Ireland EMEA UC) received approval within that year. The DPC continues to supervise annual BCR updates.
Source: DPC Annual Report 2023, p. 73
Real‑world example – Shopify According to the DPC’s 2025 Annual Report, Shopify International Limited applied for separate Controller and Processor BCRs with the DPC as lead. The DPC assessed the application, invited other EU authorities to object, received none, and proceeded. Following iterative feedback, it recommended amendments aligned with EDPB WP 263 rev 1 and WP 257 recommendations. The EDPB issued positive Article 64 opinions (17/2025 and 18/2025) in September 2025. The DPC issued final national approval in October 2025.
Source: DPC Annual Report 2025, pp. 98–99
Practical implications for practitioners For multinationals headquartered in or running EEA operations via Ireland, choosing the DPC as LSA for BCRs makes operational sense. The process demands careful documentation of internal structures, data flows, enforcement measures, redress, audits, training, and liability. Regular engagement during the iterative review and cooperation procedure expedites approval, but plan multi-month lead times. Shopify and other major corporates have successfully navigated this process most recently in 2025.
Source: Article 47 GDPR Source: DPC Annual Report 2023, p. 73 Source: DPC Annual Report 2025, pp. 98–99
Note: Broken links for the 2023 and 2025 DPC Annual Reports have been replaced with working official URLs. No material legal or procedural changes regarding BCR approvals or the DPC’s lead authority role were identified in this update.
Standard Contractual Clauses (SCCs) — DPC Guidance, TIA Requirements, and Post-Schrems II Enforcement in Ireland
Standard Contractual Clauses (SCCs) are the primary legal mechanism for transferring personal data from Ireland to non-EEA countries without an EU adequacy decision, under Article 46(2)(c) GDPR. The Data Protection Commission (DPC) refers organizations to the European Commission’s 2021 model SCCs (Commission Implementing Decision (EU) 2021/914), covering four transfer scenarios: controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. The DPC emphasizes the need to select the correct module for the transfer context and complete all mandatory annexes, following the EU SCC template and guidance. The DPC is the relevant supervisory authority named in the Irish context (see Annex I.C references).
Following the CJEU’s Schrems II decision (C-311/18), the DPC has made clear that Irish data exporters must assess, before transferring data under SCCs, whether the laws and practices of the destination country ensure the SCCs' protections can be effectively fulfilled. This is commonly referred to as a Transfer Impact Assessment (TIA). Where the assessment raises doubts about essential equivalence, supplementary measures—technical, organizational, or contractual—are required. If effective supplementary measures are not realistically possible, the exporter should not proceed with the transfer. This practical obligation is reflected in DPC guidance, which references the recommendations and methodology of the European Data Protection Board (EDPB) for such assessments and supplementary measures.
The DPC provides ongoing guidance but does not specify a rigid checklist beyond the requirements set by the European Commission and EDPB. It expects organizations to document their assessment, measures taken, and to be prepared to demonstrate compliance in the event of a complaint, audit, or inquiry. The DPC also informs organizations about the impact and requirements stemming from the Schrems II litigation and CJEU conclusions.
For official guidance, SCC templates, and updates on litigation and enforcement, consult the DPC’s resource pages below. These are updated as EU guidance and case law evolve.
Source: DPC — Transfers of personal data to third countries or international organisations Source: DPC — SCC Litigation (Schrems II) official CJEU case documents
Note: The URLs for the DPC's international transfer guidance and Schrems II litigation documentation have been updated to reflect current working addresses. No material changes to the legal substance or DPC expectations have occurred since the last update.
Transfers based on Adequacy Decisions — Art. 45 GDPR, List of Adequate Jurisdictions, and Application in Ireland
Transfers of personal data from Ireland to a country outside the European Economic Area (EEA) may take place without additional safeguards when the European Commission has adopted a formal adequacy decision for the destination under Article 45 GDPR. An adequacy decision confirms that the third country, territory, or organization ensures a level of protection for personal data that is "essentially equivalent" to that guaranteed within the EEA.
Legal basis and adequacy list Under Article 45(1) GDPR, a transfer to a recipient in an adequate jurisdiction requires no further authorization from the Irish Data Protection Commission (DPC) or additional contractual measures. The Commission maintains an up-to-date list of adequate countries, territories, and specific sectors on its official website. As of July 2026, countries with adequacy decisions include Andorra, Argentina, Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, United Kingdom, Uruguay, South Korea, and the United States (participants in the EU–US Data Privacy Framework, DPF).
The most recent adequacy decision is for the EU–US DPF, adopted July 10, 2023. Irish data exporters can rely on the DPF to transfer personal data to US organizations certified under the Framework. Data importers must be listed as active participants on the official US DPF register for the transfer to qualify.
The DPC, as Ireland’s supervisory authority, directs organizations to reference the Commission's adequacy list and verify status before relying on Art. 45. The DPC does not require notification or registration of transfers relying solely on adequacy. Should the Commission suspend or repeal an adequacy decision, organizations must promptly shift to another transfer mechanism (e.g., SCCs or BCRs) to maintain compliance.
For practical steps, DPC guidance and the European Commission link below remain definitive. Practitioners should re-check adequacy status regularly due to potential geopolitical and regulatory changes.
Source: European Commission — Adequacy Decisions Source: DPC — International Transfers
Article 49 GDPR Derogations — Emergency, Occasional and One-off Transfers from Ireland
Article 49 GDPR — Derogations for Specific Situations
Where a transfer of personal data from Ireland to a third country (outside the EEA) cannot rely on an adequacy decision (Art. 45) or appropriate safeguards (Art. 46, e.g., SCCs or BCRs), Article 49 GDPR provides narrowly scoped fallback mechanisms. The Data Protection Commission (DPC) — in line with the European Data Protection Board (EDPB) — stresses that these derogations are exceptions for genuinely occasional or emergency cases, not for routine or ongoing transfers.
Main derogations under Article 49(1) GDPR:
- Explicit consent — The data subject has given explicit consent to the proposed transfer after being informed of the possible risks (Art. 49(1)(a)). The DPC requires that such consent be specific, informed, and freely given, with heightened obligations for clear explanation of the risks.
- Contract performance — The transfer is necessary for performance of a contract between the data subject and the controller, or for pre-contractual measures at the request of the data subject (Art. 49(1)(b)). This basis is strictly limited to occasional transfers directly tied to the contract; internal or back-office purposes are excluded.
- Important reasons of public interest — The transfer is necessary for important reasons of public interest recognized in EU or Irish law (Art. 49(1)(d)); interpreted narrowly.
- Legal claims — The transfer is necessary for the establishment, exercise or defence of legal claims (Art. 49(1)(e)), covering both court and administrative proceedings.
- Vital interests — The transfer is necessary to protect the vital interests of the data subject or another person, where the data subject is incapable of giving consent (Art. 49(1)(f)).
Additional strict derogation — compelling legitimate interests If none of the above derogations apply, and the transfer is not repetitive, is limited in scope, and concerns the compelling legitimate interests of the controller (which are not overridden by interests or rights of the data subject), Art. 49(1) second paragraph allows the transfer under very restrictive conditions. The controller must document the assessment, inform the DPC, and notify the data subject with details of the transfer and the compelling interests pursued. This derogation is genuinely exceptional.
Practical enforcement and documentation requirements The DPC has enforced strict limits on derogations: in its 2025 TikTok enforcement decision, the DPC found that recurring or large-scale transfers cannot lean on these exceptions — such use must be truly occasional and justified by evidence (see DPC TikTok Inquiry April 2025). Documentation of the decision-making process, risk information provided to data subjects, and transfer records are required under Art. 30 and 49 GDPR and corresponding DPC guidance. Data subjects must always be informed of the risks where a transfer takes place under a derogation (Recital 111 GDPR).
Always consult the DPC’s online guidance and enforcement actions for up-to-date practice.
Source: DPC — Transfers of personal data to third countries or international organisations Source: GDPR, Art. 49, EUR-Lex Source: DPC Inquiry into TikTok Technology Ltd, April 2025
Note: Source URLs updated August 2026 for accuracy. No material legal or procedural change identified in the underlying regulations or guidance since the previous version, only link correction.