# Opinion 3/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the FrieslandCampina Group

- Type: Guidance
- Source: EDPB
- Identifier: opinion-32026-draft-decision-dutch-supervisory-en
- Date: 2026-03-12
- Original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-32026-on-the-proposal-for-a-european-biotech_en
- Canonical: https://overview.legal/posts/53754
- Topics: Social Media, Controllers, International Transfer, Personal Data, Codes of Conduct, Human Resources, Processors, Employees, Processing, Supervisory Authorities

## Summary

EDPB, Opinion 3/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the FrieslandCampina Group

## Full text

Opinion 3 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the FrieslandCampina Group Adopted on 15 January 2026 1 | 2 | The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter “ GDPR ”), Having regard to the European Economic Area (hereinafter “ EEA ”) Agreement and in particular to Annex XI and Protocol 37 thereof, as amended by the Decision of the EEA joint Committee No 154/2018 of 6 July 2018 1 , Having regard to the judgment of the Court of Justice of the European Union Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems , C - 311/18 of 16 July 2020, Having regard to EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data of 18 June 2021, Having regard to EDPB Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR) of 20 June 2023 (hereinafter “the Recommendations”), Having regard to Articles 10 and 22 of its Rules of Procedure. Whereas: (1) The main role of the European Data Protection Board (hereinafter the “ EDPB ”) is to ensure the consistent application of the GDPR throughout the EEA. To this effect, it follows from Article 64(1)(f) GDPR that the EDPB shall issue an opinion where a supervisory authority (hereinafter “SA”) aims to approve binding corporate rules ( hereinafter “ BCRs ”) within the meaning of Article 47 GDPR. (2) The EDPB welcomes and acknowledges the efforts the companies make to uphold the GDPR standards in a global environment. Building on the experience under Directive 95/46/EC, the EDPB affirms the important role of BCRs to frame international transfers and it s commitment to support the companies in setting - up their BCRs. This opinion aims towards this objective and takes into account that the GDPR strengthened the level of protection, as reflected in the requirements of Article 47 GDPR, and conferred to th e EDPB the task to issue an opinion on the competent SA’s draft decision aiming to approve BCRs. This task of the EDPB aims to ensure the consistent application of the GDPR, including by the SAs, controllers, and processors. (3) Pursuant to Article 46(1) GDPR, in the absence of a decision pursuant to Article 45(3) GDPR, a controller or processor may transfer personal data to a third country or international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. A group of undertakings or group of enterprises engaged in a joint economic 1 References to “Member States” made throughout this opinion should be understood as references to “EEA Member States”. 3 | activity may provide such safeguards by the use of legally binding BCRs, which expressly confer enforceable rights on data subjects and fulfil a series of requirements (Article 46 GDPR). The implementation and adoption of BCRs by a group of undertakings is intended to provide guarantees that apply uniformly in all third countries and, consequently, independently of the level of protection guaranteed in each third country. The specific requirements listed in the GDPR are the minimum items BCRs shall specify (Article 47(2) GDPR). The BCRs are subject to approval from the competent SA (hereinafter “ the BCR Lead ”), in accordance with the consistency mechanism set out in Article 63 and Article 64(1)(f) GDPR, provided that the BCRs meet the conditions set out in Article 47 GDPR, together with the requirements set out in the EDPB Recommendations 1/2022 on the Applic ation for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR), adopted on 20 June 2023, which su persede the working documents WP256 rev.01 and WP264 of the Article 29 Working Party 2 . (4) This opinion only covers the EDPB’s consideration that the BCRs submitted for the required opinion afford appropriate safeguards in that they meet all requirements of Article 47 GDPR and the Recommendations. Accordingly, this opinion and the SAs’ review do not address elements and obligations of the GDPR mentioned in the BCRs at issue other than those related to Article 47 GDPR. This also applies to any supplementary measures that an exporter subject to the GDPR may be required to adopt, depending on th e circumstances of the transfer, in order to ensure compliance with the commitments taken in the BCRs. (5) The EDPB recalls that, in accordance with the judgment of the Court of Justice of the European Union C - 311/18 , it is the responsibility of the data exporter subject to the GDPR, if needed with the help of the data importer, to assess whether the level of protection required by EU law is respected in the third country concerned, in order to determine if the guarantees provided by BCRs can be complied with in practice, taking into consideration the possible interference created by the third country legis lation with the fundamental rights. If this is not the case, the data exporter subject to the GDPR, if needed with the help of the data importer, should assess whether they can provide supplementary measures to ensure an essentially equivalent level of pro tection as provided in the EU. (6) Taking into account the specific characteristics of BCRs provided for by Article 47(1) and (2) GDPR, each application should be addressed individually and is without prejudice to the assessment of any other BCRs. The EDPB recalls that BCRs should be custom ised to take account of the structure of the group of companies that they apply to, the processing they undertake, and the policies and procedures that they have in place to protect personal data 3 . 2 The Working Party on the Protection of Individuals with regard to the Processing of Personal Data instituted by Article 29 of Directive 95/46/EC . The following documents, which were endorsed by the EDPB, are now superseded by the EDPB Recommendations: Article 29 Working Party’s Working Document setting up a table with the elements and principles to be fo und in Binding Corporate Rules ( WP 256 rev.01 ) and Article 29 Working Party’s Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfers of Personal Data ( WP 264 ). 3 This view was expressed by the Article 29 Working party in Working Document Setting up a framework for the structure of Binding Corporate Rules, adopted on 24 June 2008 , WP154. 4 | (7) The opinion of the EDPB shall be adopted, pursuant to Article 64(3) GDPR in conjunction with Article 10(2) of the EDPB Rules of Procedure, within eight weeks after the Chair has decided that the file is complete. Upon decision of the EDPB Chair, this perio d may be extended by a further six weeks, taking into account the complexity of the subject matter. (8) Finally, the EDPB highlights that any documentation submitted may be subject to access to documents requests in accordance with the SAs’ national laws and with Regulation 1049/2001 4 , applicable to the EDPB pursuant to Article 76 (2) GDPR. Has adopted the following opinion: 1 Summary of the facts 1 In accordance with the cooperation procedure as set out in the EDPB Document Setting Forth a Co o peration procedure for the approval of Binding Corporate Ru les for controllers and processors , the draft BCR - C of Koninklijke FrieslandCampina N.V. and its group companies (hereinafter the “ FrieslandCampina Group”) was reviewed by the NL SA as the BCR Lead. 2 The BCR Lead has submitted its draft decision regarding the draft BCR - C of the FrieslandCampina Group, requesting an opinion of the EDPB pursuant to Article 64(1)(f) GDPR on 24 November 2025 . The decision on the completeness of the file was taken on 8 December 2025 . 2 Assessment 3 The draft BCR - C of the FrieslandCampina Group covers the p rocessing by FrieslandCampina Group companies (acting as c ontroller ) of personal data that are (i) subject to data transfer rules under EEA d ata p rotection l aws (or were subject to said rules prior to their t ransfer outside the EEA), and (ii) are transferred to a FrieslandCampina Group c ompany outside the EEA . 5 4 Concerned data subjects include Employees (past and present), Dependents, Customers, Business Partners, Suppliers, Stakeholders, and Users, attendees and other individuals whose data is processed in the context of FrieslandCampina Group activities . 6 5 The draft BCR - C of the FrieslandCampina Group has been scrutinised according to the procedures set up by the EDPB. The SAs assembled within the EDPB have concluded that the draft BCR - C of the FrieslandCampina Group contains all the elements required under Article 47 GDPR and the Recommendations, in accordance with the draft decision of the BCR 4 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents . 5 Article 1.1 of the FrieslandCampina Privacy Code for Employee Data and Article 1.1 of the FrieslandCampina Third Party Privacy Code. 6 Article 1.1 of the FrieslandCampina Privacy Code for Employee Data and Article 1.1 of the FrieslandCampina Third Party Privacy Code; A nnex 1 of the FrieslandCampina Privacy Code for Employee Data and A nnex 1 of the FrieslandCampina Third Party Privacy Code . 5 | Lead submitted to the EDPB for an opinion. Therefore, the EDPB does not have any concerns that need to be addressed. 3 Conclusions 6 Taking into account the above and the commitments that the group members will undertake by signing the Intra - group agreement , the EDPB considers that the draft decision of the BCR Lead may be adopted as it is, since the draft BCR - C of the FrieslandCampina Group contains appropriate safeguards to ensure that the level of protection of natural persons guaranteed by the GDPR is not undermined when personal data is transferred to and processed by the group members based in third countries. The EDPB recalls tha t the approval of BCRs by the BCR Lead does not entail the approval of specific transfers of personal data to be carried out on the basis of the BCRs. Accordingly, the approval of BCRs may not be construed as the approval of transfers to third countries inc luded in the BCRs for which an essentially equivalent level of protection to that guaranteed within the EU cannot be ensured. 7 Finally, the EDPB also recalls the provisions contained within Article 47(2)(k) GDPR and the Recommendations providing the conditions under which the applicant may modify or update the BCRs, including updates to the list of BCRs group members. 4 Final remarks 8 This opinion is addressed to the BCR Lead and will be made public pursuant to Article 64(5)(b) GDPR. 9 According to Article 64(7) and (8) GDPR, the BCR Lead shall communicate its response to this opinion to the Chair within two weeks after receiving the opinion. 10 Pursuant to Article 70(1)(y) GDPR, the BCR Lead shall communicate the final decision to the EDPB for inclusion in the register of decisions which have been subject to the consistency mechanism. For the European Data Protection Board The Chair (Anu Talus)

## Cited law provisions (20)

### GDPR — gdpr-art-45-par-3-nl

De Commissie kan, na de beoordeling van de vraag of het beschermingsniveau adequaat is, door middel van een uitvoeringshandeling besluiten dat een derde land, een gebied of één of meerdere nader bepaalde sectoren in een derde land, of een internationale organisatie een passend beschermingsniveau in de zin van lid 2 van dit artikel waarborgt. De uitvoeringshandeling voorziet in een mechanisme voor periodieke toetsing, minstens om de vier jaar, waarbij alle relevante ontwikkelingen in het derde land of de internationale organisatie in aanmerking worden genomen. In de uitvoeringshandeling worden het territoriale en het sectorale toepassingsgebied vermeld, alsmede, in voorkomend geval, de in lid 2, punt b), van dit artikel genoemde toezichthoudende autoriteit(en). De uitvoeringshandeling wordt vastgesteld volgens de in artikel 93, lid 2, bedoelde onderzoeksprocedure.

### GDPR — gdpr-art-46-par-1-nl

Bij ontstentenis van een besluit uit hoofde van artikel 45, lid 3, mag een doorgifte van persoonsgegevens aan een derde land of een internationale organisatie door een verwerkingsverantwoordelijke of een verwerker alleen plaatsvinden mits zij passende waarborgen bieden en betrokkenen over afdwingbare rechten en doeltreffende rechtsmiddelen beschikken.

### GDPR — gdpr-art-47-par-1-nl

De bevoegde toezichthoudende autoriteit keurt in overeenstemming met het in artikel 63 bedoelde coherentiemechanism bindende bedrijfsvoorschriften goed, op voorwaarde dat deze:

### GDPR — gdpr-art-47-par-2-nl

In de in lid 1 bedoelde bindende bedrijfsvoorschriften worden minstens de volgende elementen vastgelegd:

### GDPR — gdpr-art-64-par-1-nl

Het Comité brengt een advies uit wanneer een bevoegde toezichthoudende autoriteit voornemens is een van onderstaande maatregelen vast te stellen. Hiertoe deelt de bevoegde toezichthoudende autoriteit het Comité het ontwerpbesluit mee indien het:

### GDPR — gdpr-art-64-par-3-nl

Het Comité brengt in de in de leden 1 en 2 bedoelde gevallen een advies uit over de aan het Comité voorgelegde aangelegenheid, mits het daarover niet eerder advies heeft uitgebracht. Dat advies wordt binnen acht weken vastgesteld met gewone meerderheid van de leden van het Comité. Die termijn kan met zes weken worden verlengd, rekening houdend met de complexiteit van de aangelegenheid. Met het in lid 1 bedoelde ontwerpbesluit, dat overeenkomstig lid 5 onder de leden van het Comité wordt verspreid, wordt een lid dat niet binnen een redelijke, door de voorzitter aangegeven termijn bezwaar heeft aangetekend, geacht in te stemmen.

### GDPR — gdpr-art-64-par-5-nl

De voorzitter van het Comité stelt onverwijld langs elektronische weg:

### GDPR — gdpr-art-64-par-7-nl

De in lid 1 bedoelde toezichthoudende autoriteit houdt maximaal rekening met het advies van het Comité en deelt de voorzitter van het Comité binnen twee weken na ontvangst van het advies langs elektronische weg door middel van een standaardformulier mee of zij haar ontwerpbesluit zal handhaven dan wel wijzigen alsmede, in voorkomend geval het gewijzigde ontwerpbesluit.

### GDPR — gdpr-art-70-par-1-nl

Het Comité zorgt ervoor dat deze verordening consequent wordt toegepast. Daartoe doet het Comité op eigen initiatief of, waar passend, op verzoek van de Commissie met name het volgende:

### GDPR — gdpr-art-1-nl

Onderwerp en doelstellingen

### GDPR — gdpr-art-10-nl

Persoonsgegevens betreffende strafrechtelijke veroordelingen en strafbare feiten of daarmee verband houdende veiligheidsmaatregelen mogen op grond van artikel 6, lid 1, alleen worden verwerkt onder toezicht van de overheid of indien de verwerking is toegestaan bij Unierechtelijke of lidstaatrechtelijke bepalingen die passende waarborgen voor de rechten en vrijheden van de betrokkenen bieden. Omvattende registers van strafrechtelijke veroordelingen mogen alleen worden bijgehouden onder toezicht van de overheid.

### GDPR — gdpr-art-29-nl

De verwerker en eenieder die onder het gezag van de verwerkingsverantwoordelijke of van de verwerker handelt en toegang heeft tot persoonsgegevens, verwerkt deze uitsluitend in opdracht van de verwerkingsverantwoordelijke, tenzij hij Unierechtelijk of lidstaatrechtelijk tot de verwerking gehouden is.

### GDPR — gdpr-art-46-nl

Doorgiften op basis van passende waarborgen

### GDPR — gdpr-art-47-nl

Bindende bedrijfsvoorschriften

### GDPR — gdpr-art-63-nl

Teneinde bij te dragen aan de consequente toepassing van deze verordening in de gehele Unie werken de toezichthoudende autoriteiten met elkaar en waar passend samen met de Commissie in het kader van het in deze afdeling uiteengezette coherentiemechanisme.

### GDPR — gdpr-art-76-nl

Vertrouwelijkheid

### GDPR — gdpr-art-47-par-2-pnt-k-nl

de procedures om die veranderingen in de regels te melden, te registreren en aan de toezichthoudende autoriteit te melden;

### GDPR — gdpr-art-64-par-1-pnt-f-nl

de goedkeuring beoogt van bindende bedrijfsvoorschriften in de zin van artikel 47.

### GDPR — gdpr-art-64-par-5-pnt-b-nl

de, naargelang het geval, in de leden 1 en 2 bedoelde toezichthoudende autoriteit en de Commissie in kennis van het advies en maakt dat advies bekend.

### GDPR — gdpr-art-70-par-1-pnt-y-nl

houden van een openbaar elektronisch register van besluiten van toezichthoudende autoriteiten en gerechten over in het kader van het coherentiemechanisme behandelde aangelegenheden.

---
Generated by overview.legal · https://overview.legal/posts/53754 · 2026-08-22
