Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
ADP has adopted EU-approved Binding Corporate Rules as the legal mechanism governing cross-border transfers of personal data among ADP Group Companies worldwide, including transfers to entities outside the EU and EEA.
This analysis describes what ADP's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The BCR framework establishes the legal basis for ADP's cross-border personal data transfers under GDPR and UK GDPR, covering data flows across ADP's operations in more than 140 countries. The document states that ADP extended its BCR definition to include the UK following Brexit by decision of its General Counsel.
Interpretive note: Whether ADP's extension of its BCR definition to include the UK by General Counsel decision satisfies UK GDPR international transfer requirements is not established by this document and depends on ICO regulatory guidance.
ADP deleted the cookie preference management tool that previously allowed users to understand and control which cookies were placed on their devices, including functional, analytics, and advertising cookies. The removal eliminates the transparency mechanism through which users could consent to or opt out of different cookie categories. The practical effect depends on whether ADP has replaced this functionality elsewhere or whether cookies continue to be placed without equivalent granular user control.
View change record →Under this framework, personal data of individuals interacting with ADP may be transferred to and processed by ADP Group Companies in countries outside the EU and EEA, with the BCR serving as the stated lawful transfer mechanism. The policy notes that additional countries may be added to the EEA definition by General Counsel decision published on adp.com.
Cross-platform context
See how other platforms handle Binding Corporate Rules International Data Transfer Mechanism and similar clauses.
Compare across platforms →Monitoring
ADP has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"ADP has adopted Binding Corporate Rules (BCR) as a Data Controller. BCR are a legally binding set of internal rules, recognized by the European Union (EU) Data Protection Authorities (DPAs), to ensure a consistent approach to privacy and data protection across Group Companies with the same parent, including those located outside of the EU.Excerpt from ADP's Privacy Statement
REGULATORY LANDSCAPE: The BCR framework engages GDPR Chapter V (international data transfers), which requires an adequacy decision, standard contractual clauses, or approved BCR as a lawful transfer mechanism. The UK's International Data Transfer Agreement (IDTA) framework governs UK transfers post-Brexit. ADP's extension of its BCR definition to include the UK by General Counsel decision, rather than through a separate IDTA or UK BCR approval, may warrant evaluation under UK GDPR transfer requirements. Relevant enforcement authorities are EU national data protection authorities and the UK Information Commissioner's Office (ICO). GOVERNANCE EXPOSURE: Medium. BCR approval by EU DPAs provides a recognized lawful transfer mechanism. However, the document states that additional countries may be added to the EEA definition 'by decision of the General Counsel,' which is an internal corporate mechanism rather than a regulatory approval process. The adequacy of this extension mechanism for UK and potentially other country transfers should be assessed. JURISDICTION FLAGS: UK transfers require compliance with UK GDPR and the ICO's international transfer framework; the adequacy of ADP's General Counsel extension of BCR scope to cover the UK should be confirmed with the ICO's published BCR register. Swiss transfers may require separate assessment under the Swiss Federal Act on Data Protection (nFADP). CONTRACT AND VENDOR IMPLICATIONS: Organizations engaging ADP as a data processor for EU or UK employee data should confirm that ADP's BCR approval covers their specific data processing activities and geographic scope. The list of ADP Group Companies bound by the BCR (referenced at www.adp.com/-/media/adp/privacy/pdf/A2CoBDC.pdf) should be reviewed to confirm coverage of all relevant entities. COMPLIANCE CONSIDERATIONS: Legal teams should verify whether the BCR approval documented by ADP covers the specific categories of personal data and processing activities relevant to their engagement, including any special categories of data. The ICO's register of approved BCRs should be cross-referenced to confirm UK coverage. Any engagement involving processing of EU or UK employee data by ADP should include a data processing agreement referencing the BCR as the transfer mechanism.
The BCR framework establishes the legal basis for ADP's cross-border personal data transfers under GDPR and UK GDPR, covering data flows across ADP's operations in more than 140 countries. The document states that ADP extended its BCR definition to include the UK following Brexit by decision of its General Counsel.
Under this framework, personal data of individuals interacting with ADP may be transferred to and processed by ADP Group Companies in countries outside the EU and EEA, with the BCR serving as the stated lawful transfer mechanism. The policy notes that additional countries may be added to the EEA definition by General Counsel decision published on adp.com.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ADP.