About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

SNR Denton Helps First Data Obtain Approval from European Regulators for its Binding Corporate Rules for Data Privacy

Subscribe to our newsletter

SNR Denton has successfully helped First Data Corporation, a global leader in electronic commerce and payment processing, obtain approval from European Data Protection regulators for its Binding Corporate Rules for data privacy (BCRs).

Today, the Information Commissioner’s Office granted authorisation of First Data’s BCRs, making it the eleventh company to obtain such authorization. First Data is one of only a handful of other companies worldwide who have completed this rigorous process to establish of the highest standards global data privacy practices. Its BCRs have been approved by the data protection authorities in 18 European Union member states.

The authorisation marks the culmination of a four-year project by First Data which was led on First Data’s side by John Atkins, First Data’s Chief Privacy Officer, and Tanya Madison Cunningham, Senior Counsel, Technology, Regulatory Compliance and Privacy.

SNR Denton’s team was led by Head of Technology Media and Telecoms sector, Scott Singer, assisted by associates Nicola Tutton and Tristan Jonckheer, all of whom work in SNR Denton’s dedicated UK Data Privacy Group, which has 4 partners and 12 lawyers in total, making it one of the largest in the UK.

Scott Singer commented: “Data Privacy is at the heart of First Data’s business, being a company which processes literally tens of billions of transactions every year. First Data’s determination to complete this process has come out of not just a desire to streamline its business, but more importantly, a wish to demonstrate its commitment to maintaining the highest standards of data privacy in everything it does.”

John Atkins, First Data’s Chief Privacy Officer, said: “First Data appreciates the superior guidance we received from SNR Denton during this process. Only a handful of companies have achieved BCR approval due to the rigorous nature of the process, and the advice and partnership provided by the SNR Denton team were invaluable.”

David Smith, Deputy Information Commissioner, said: “First Data should be commended for its commitment to the concept of binding corporate rules and for the respect for the privacy of individuals that this demonstrates. The ICO welcomes approaches from multi-national organisations that need to share personal information within their own group, but outside Europe and who want to use binding corporate rules to enable that.”

BCRs are a company-wide privacy policy to guarantee that a company’s practices are consistent with European data protection law. They are considered the platinum standard for compliance with the European Data Protection Directive. First Data’s BCRs will allow First Data to transfer personal data from the European Economic Area to its affiliates elsewhere in the world – something which is prohibited under the European Data Protection Directive unless adequate safeguards are in place. Following approval of the binding corporate rules by the European data protection regulators, First Data will now go through the formal process of approaching each of them for local authorization (the ICO’s having been the first such authorisation to be granted).

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: The ROI of Data Trust: Quantifying the Business Value of Data Observability

Data is the fuel that keeps modern financial institutions’ motors running but if that data can’t be trusted then the decisions made based upon it, or the uses to which its put, will be compromised. That’s especially important for data that’s fed into artificial intelligence models. If the data isn’t clean, accurate and complete, then...

BLOG

Reframing Corporate KYC: Encompass Targets Back-Book Exposure with Scalable EC Review

For many SME focussed banks, KYC investments have streamlined the onboarding journey but legacy KYC records – the back-book – often remain dormant until a regulatory inspection, or an enforcement case at a peer institution, forces a wholesale review. The challenge that follows is how to remediate at scale, with urgency, and without the need...

EVENT

TradingTech Summit London

Now in its 15th year the TradingTech Summit London brings together the European trading technology capital markets industry and examines the latest changes and innovations in trading technology and explores how technology is being deployed to create an edge in sell side and buy side capital markets financial institutions.

GUIDE

Regulatory Data Handbook 2026 – Fourteenth Edition

Welcome to the fourteenth edition of A-Team Group’s Regulatory Data Handbook. Supervisors increasingly expect firms to demonstrate which rules apply, which data supports each obligation, who owns the control and how exceptions are identified and resolved. Policies and implementation programmes must now be supported by records that can withstand regulatory scrutiny. This edition examines material...