Skip to Content
Policy

Data Protection Policy

JDU Consulting is committed to protecting the privacy of its clients, employees and partners. In order to do so, JDU Consulting has adopted Binding Corporate Rules (BCR) as its global data protection policy.

JDU Consulting BCR apply to all JDU Consulting entities and their employees, ensuring a strong standard of protection for all personal data processed by JDU Consulting , whether on its own behalf and on behalf of its clients.

The EU Binding Corporate Rules (EU BCR) for Controller & Processor activities – initially approved by the European Data Protection Authorities in March 2016 and subsequently updated in January 2019 to comply with the General Data Protection Regulation (GDPR).

JDU Consulting EU BCR were most recently updated in April 2023 in light of the so-called Schrems II decision. Indeed, in order to align with the additional obligations stemming from this decision, the European Data Protection Board (EDPB) – which is composed of representatives from EU national data protection authorities – is in the process of updating the BCR requirements. In the meanwhile, JDU Consulting has been working with its Lead data protection authority, the CNIL, to start the process of updating its BCRs to comply with the upcoming requirements. The public version of JDU Consulting ’s EU BCRs reflects this work.

The UK Binding Corporate Rules (UK BCR) for Controller & Processor activities – Following Brexit, and to comply with UK data protection legislation, JDU Consulting submitted an application for UK BCR to the Information Commissioner Office (ICO) – the UK Data Protection Authority – which was approved in March 2022.

In addition to being JDU Consulting ’s global data protection policy, BCR allow JDU Consulting to safely transfer personal data among entities of the Group, in compliance with the EU General Data Protection Regulation (GDPR) and UK  General Data Protection Regulation (UK GDPR).  

JDU Consulting EU & UK Controller BCR (BCR-C) apply to and cover the processing and transfers of personal data carried out by JDU Consulting entities acting as data controller  i.e. where JDU Consulting is processing and transferring data between entities of the Group as part of its own operations.

JDU Consulting EU & UK Processor BCR (BCR-P) apply to and cover the processing and transfers of personal data carried out by JDU Consulting as a data processor i.e. where JDU Consulting is processing and transferring personal data to deliver services to its Clients. More specifically and as provided under the draft EDPB Recommendation 1/2022 (adopted on Nov. 2022) “BCR-P apply to data received from a controller that is not a member of the Group, and which are then processed by the concerned Group members as processors and/or sub-processors.”