skip to content

Under the GDPR, an EU subsidiary sends employee HR data to its US parent; which transfer mechanisms fit, and when are binding corporate rules worth it?

level: seniorimportance: should knowfreq 40%

answer

  1. same group, different legal entities
  2. DPF only if HR is covered
  3. module depends on who decides
  4. BCRs: approved once, group-wide
  5. derogations don't carry payroll

basics

~20 s

Under the GDPR an intra-group flow is still a transfer. It can rely on an HR-covering DPF listing, on SCCs chosen by role, or on Art. 47 BCRs, which pay off for groups with many entities and flows.

solid answer

~40 s

Parent and subsidiary are separate legal entities, so HR data sent to the US parent is a Chapter V **transfer**. Three routes fit a recurring flow. First, the **EU-US Data Privacy Framework**, if the parent is listed *and* its self-certification covers **HR data**. Second, the **2021 SCCs**: Module One if the parent decides purposes as a controller, Module Two if it runs the HR system on the subsidiary's instructions. Third, **binding corporate rules** under **Arts. 46(2)(b) and 47**: approved once by the competent supervisory authority through the consistency mechanism, legally binding on every group member and its employees, and giving data subjects enforceable rights. BCRs pay off for a large group with many entities and flows, and cover only intra-group transfers. **Art. 49** derogations do not fit routine HR flows.

go deeper

for a junior

Recall that separate group companies mean a transfer, and name the three workable routes: an HR-covering DPF listing, SCCs, and binding corporate rules.

for a middle

Choose the SCC module by the parent's role, and explain what Art. 47 requires for BCRs: approval, binding effect, enforceable rights, the 47(2) contents.

for a senior

Argue when BCRs beat bilateral SCCs for a group, and show that neither escapes third-country law: Clause 14 on one side, Art. 47(2)(m) on the other.

for a principal

Weigh the multi-year cost of BCR approval and upkeep against the flexibility and risk of dozens of module contracts across a changing group structure.

## Intra-group is still a transfer The GDPR regulates **controllers and processors**, which are legal persons. A corporate group is several of them. Art. 4(19) defines a **group of undertakings** as *"a controlling undertaking and its controlled undertakings"*, not as one entity. When an EU subsidiary sends its employees' data to a US parent, the recipient is a separate entity in a third country, so **Chapter V applies**. ## The options for a recurring HR flow | Route | Legal basis | Fits when | Watch out for | |---|---|---|---| | **EU-US Data Privacy Framework** | Art. 45; Decision (EU) 2023/1795 | the parent is on the DPF List **and** its self-certification covers HR data | HR coverage needs a specific declaration and commitment to cooperate with EU DPAs; annual re-certification | | **SCCs, Module One** | Art. 46(2)(c); Decision (EU) 2021/914 | the parent decides purposes and means, e.g. group-wide talent decisions | Clause 14 assessment of US law | | **SCCs, Module Two** | same | the parent processes on the subsidiary's instructions, e.g. hosting the HR platform | Module Two also carries Art. 28 processor terms | | **Binding corporate rules** | Arts. 46(2)(b), 47 | many group entities, many countries, many flows | approval effort; covers intra-group transfers only | | **Art. 49 derogations** | Art. 49(1) | exceptional cases, only where no Art. 45 or 46 route exists | not a basis for payroll or HR systems running every day | The role question decides the SCC module. Who decides *why* the data is processed? Recording that answer is as important as signing. ## What BCRs are **Art. 4(20)**: BCRs are *"personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity."* Under **Art. 47(1)** the **competent supervisory authority approves** them through the **Art. 63 consistency mechanism**, provided they: - are **legally binding** on, and enforced by, every member concerned, **including their employees**; - **expressly confer enforceable rights** on data subjects; - meet the **Art. 47(2)** content requirements. Art. 47(2) sets fourteen minimum elements, points (a) to (n). The ones that shape engineering and operations: 1. **(b)** the transfers covered: categories of data, types of processing, purposes, data subjects, and the third countries; 2. **(d)** application of the principles, including purpose limitation, minimisation, storage limits, security and **onward transfers** to bodies not bound by the BCRs; 3. **(f)** an **EU-established member accepts liability** for breaches by non-EU members, exempt only if it proves that member was not responsible; 4. **(j)** verification mechanisms, including **data protection audits**, with results sent to the board of the controlling undertaking; 5. **(m)** mechanisms to report to the authority any **third-country legal requirements** likely to substantially undermine the BCR guarantees; 6. **(n)** data protection **training** for staff with permanent or regular access. Point (m) matters after Schrems II. BCRs, like SCCs, are not immune to a destination's surveillance law. The group must track and report conflicts. ## When BCRs are worth it **Worth it:** a multinational with dozens of entities where HR, CRM and IT support data move in many directions. One approved framework replaces a web of bilateral module contracts, and it becomes the group's operating standard. **Not worth it:** a single subsidiary sending one HR feed to one parent. The approval process and ongoing audit and reporting duties outweigh signing Module One or Two, or relying on an HR-covering DPF listing. **Not enough on their own:** BCRs cover only transfers **within the group**. The group's outside vendors in third countries still need SCCs or another route. ## Why not just ask employees to consent? **Art. 49(1)(a)** explicit consent is a derogation. It applies only in the absence of adequacy or Art. 46 safeguards (Art. 49(1)), and here SCCs and BCRs are available. A continuous HR feed is also not the *occasional* transfer Recital 111 has in mind. Whether employee consent can be valid at all is a separate question for the consent rules. For transfers, the structural point settles it: a routine flow needs Art. 45 or Art. 46.

  • Under the GDPR, do approved BCRs remove the need to assess US law for the parent?
    Not entirely. Art. 47(2)(m) requires the BCRs to include mechanisms for reporting to the supervisory authority any third-country legal requirements likely to have a substantial adverse effect on the BCR guarantees. Groups therefore still track destination law and act on conflicts, much as SCC users do under Clause 14.
  • Under GDPR Art. 47, what liability does the EU member accept?
    Art. 47(2)(f) requires the controller or processor established in a Member State to accept liability for breaches of the BCRs by any member not established in the Union. It is exempt, in whole or in part, only if it proves that member was not responsible for the event giving rise to the damage.

saying these in an interview costs you the question

  • Transfers inside one corporate group are exempt from Chapter V.
  • A parent's DPF listing automatically covers employee HR data.
  • BCRs also cover the group's transfers to outside vendors abroad.
  • BCRs take effect once the group's board adopts them.
  • Employee consent under Art. 49 is a sound basis for a daily HR feed.