Binding corporate rules

The EU gold standard privacy framework

Our privacy program is based on binding corporate rules (BCRs), considered as the “gold standard” privacy compliance framework as they are the only international data transfer mechanism that carries individual regulatory approval.

Our BCRs have been approved by the Office of the Data Protection Ombudsman, the Finnish supervisory authority. BCRs are explicitly recognized by GDPR as a mechanism for providing appropriate safeguards for third country data transfers.  

This means that the level of protection afforded to your personal data by the GDPR is not compromised when Nokia and its group companies transfer that data internationally to countries whose national laws do not provide the same level of protection as the EU/EEA.

Whether Nokia is acting as a controller or a processor of personal data, the relevant BCRs will ensure that we meet the strict data protection and privacy requirements we have committed to.  

“Privacy and the protection of personal data enables trust in our technology, our business, and our operations. For us, respecting privacy is not only about being compliant with laws, but also fundamental to our values as a trustworthy and ethical company. Becoming the first Finnish company to obtain BCRs is clearly an important milestone for us, and one that demonstrates the trust and respect regulators have for our privacy standards”
Esa Niinimäki, Chief Legal Officer of Nokia
Esa Niinimäki
Chief Legal Officer of Nokia