Data Protection & Privacy
Rubrik's Binding Corporate Rules
Binding Corporate Rules ("BCRs") are internal data protection rules adopted by a corporate group. They must be approved by the competent lead supervisory authority under Article 47 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), following an opinion from the European Data Protection Board.
BCRs provide appropriate safeguards that allow personal data to be transferred within the corporate group to countries outside the European Economic Area ("EEA"), while ensuring that the data continues to receive a level of protection essentially equivalent to that required under EU data protection law – in other words, the same core protections travel with the data.
Rubrik, Inc. and its subsidiaries (the "Rubrik Group") have adopted two complementary sets of BCRs. Controller BCRs ("BCR-C") cover personal data for which a Rubrik Group entity acts as controller – for example, data about Rubrik's own employees and business contacts. Processor BCRs ("BCR-P") cover personal data that Rubrik processes on behalf of its customers, as a processor. Rubrik's BCR-C and BCR-P were approved on 30 June 2026 by the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).
Together, the BCR-C and BCR-P provide a lawful basis for cross-border transfers of personal data across the Rubrik Group and give data subjects clear, enforceable rights over how their personal data is handled, wherever in the world it is processed.
Controller Binding Corporate Rules
Governs personal data for which a Rubrik Group entity is responsible as a controller.
Processor Binding Corporate Rules
Governs personal data that Rubrik processes on behalf of its customers as a processor.