BCRs provide appropriate safeguards that allow personal data to be transferred within the corporate group to countries outside the European Economic Area ("EEA"), while ensuring that the data continues to receive a level of protection essentially equivalent to that required under EU data protection law – in other words, the same core protections travel with the data.

Rubrik, Inc. and its subsidiaries (the "Rubrik Group") have adopted two complementary sets of BCRs. Controller BCRs ("BCR-C") cover personal data for which a Rubrik Group entity acts as controller – for example, data about Rubrik's own employees and business contacts. Processor BCRs ("BCR-P") cover personal data that Rubrik processes on behalf of its customers, as a processor. Rubrik's BCR-C and BCR-P were approved on 30 June 2026 by the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).

Together, the BCR-C and BCR-P provide a lawful basis for cross-border transfers of personal data across the Rubrik Group and give data subjects clear, enforceable rights over how their personal data is handled, wherever in the world it is processed.

Controller Binding Corporate Rules

Governs personal data for which a Rubrik Group entity is responsible as a controller.

Processor Binding Corporate Rules

Governs personal data that Rubrik processes on behalf of its customers as a processor.

FAQ