Binding Corporate Rules

As one of the world’s foremost providers of consulting, technology and outsourcing services to a wide array of clients around the world, Capgemini is committed to protecting privacy and the Personal Data entrusted to it. As an international Group with companies in more than 40 countries, Capgemini needs to ensure that Personal Data flows freely and securely between the Capgemini Companies with an appropriate and uniform level of protection.

Capgemini is committed to protecting all personal data entrusted to it as part of its activities as a Data Controller and as a Data Processor. As an international group, it is important to Capgemini that information flows freely and securely. Providing an appropriate level of protection to the personal data being transferred within the group, is one of the reasons why Capgemini has chosen to implement these Binding Corporate Rules (BCR) which were first approved by the French data protection authority, the CNIL, in March 2016. This is all the more important as legal data protection and legal data security are crucial for each affiliate of Capgemini. The financial and reputational risks are high.