Binding corporate rules must be approved by the Agency and be legally binding on and enforced by every relevant group member and employee, confer enforceable rights on data subjects, and contain at least the group structure, the transfers and destinations, their binding nature, the application of the principles, the data subjects' rights and remedies (including complaint to the Agency, judicial protection and compensation), acceptance of liability by the Montenegrin member for breaches by members abroad, how data subjects are informed, the tasks of the DPO or responsible person, complaint procedures, verification mechanisms including audits reported to the DPO and the board and available to the Agency, change reporting, cooperation with the Agency, reporting of foreign legal requirements with substantial adverse effect, and appropriate training.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.