Abtin Consulting Group – Binding Corporate Rules (BCR) Program
Abtin Consulting Group (“we” or “the Company”) has developed a program entitled Binding Corporate Rules (BCR) to ensure an adequate level of protection for personal data processed within the framework of our domestic and international activities. This program forms part of our commitment to comply with Iranian national regulations (such as the Personal Data Protection Law) as well as international data protection standards, including the EU General Data Protection Regulation (GDPR) and its provisions related to international data transfers.
Scope and Applicability
This program applies to all units of Abtin Consulting Group, including branches, offices, subsidiaries, and joint ventures that process personal data, particularly when data is transferred outside the jurisdiction of Iran or in the context of international operations.
The program comprises two main components: BCR for Data Controllers and BCR for Data Processors.
General Data Protection Principles
We are committed to processing personal data solely based on the following principles:
- Lawfulness, fairness, and transparency: Data must be processed on a legal basis, fairly, and in a transparent manner.
- Purpose limitation: Data shall be collected and used only for clearly defined and lawful purposes.
- Data minimization: Only the data necessary for the intended purpose shall be collected.
- Accuracy: Personal data must be accurate and kept up-to-date.
- Security and confidentiality: Appropriate technical and organizational measures are in place to prevent unauthorized access, disclosure, alteration, or destruction.
- Limited retention: Data should not be retained longer than necessary for the intended purpose, unless otherwise required by law.
International Data Transfers
When personal data is transferred from Iran to countries not recognized by competent international authorities as providing an “adequate” level of protection, Abtin Consulting Group is committed, under the BCR framework, to implementing additional contractual and organizational safeguards to ensure an appropriate level of protection, in line with GDPR Articles 46 and 47.
Data Subject Rights
Any individual whose data is processed by us has the right to:
- Access their personal data
- Request correction or deletion
- Restrict processing
- Receive a portable copy of their data
For such requests, individuals may contact the Data Protection Officer (DPO).
Data Breach and Complaint Handling
In the event of a data security breach or any suspected non-compliance with this program, a process is in place for notification, internal investigation, corrective measures, and reporting to the relevant authorities.
Training, Audits, and Compliance
Abtin Consulting Group is committed to providing training to all employees, contractors, and subsidiaries, conducting periodic audits, and continuously reviewing the policies of this program. This approach follows global best practices; for example, PwC emphasizes that BCRs should include effectiveness tools such as training, audits, and complaint handling.
Contact and Inquiries
Any questions regarding this program or your rights may be directed via email to: info@abtinadvisors.com