Home/Binding Corporate Rules

Binding Corporate Rules

Overview

Our Binding Corporate Rules (BCRs) are internal policies adopted by Kazt Logistics that govern the international transfer of personal data within our corporate group. These rules ensure that all entities within our organization process personal data with the same high standard of protection, regardless of the country in which the data is processed.

Purpose and Scope

BCRs serve as a legally binding mechanism under the GDPR (Article 47) to authorize transfers of personal data from entities in the European Economic Area to our affiliates in countries that have not received an adequacy determination from the European Commission.

These rules apply to:

  • All wholly-owned subsidiaries and branch offices of Kazt Logistics
  • All employees, contractors, and agents who process personal data on our behalf
  • All categories of personal data processed within our corporate group

Core Principles

Lawfulness & Fairness

All data processing is conducted lawfully, fairly, and transparently, with a valid legal basis for every processing activity.

Purpose Limitation

Personal data is collected for specified, explicit purposes and not further processed in a manner incompatible with those purposes.

Data Minimization

We collect only the personal data that is adequate, relevant, and limited to what is necessary for the intended purpose.

Storage Limitation

Personal data is retained only for as long as necessary to fulfill the purpose of collection or as required by law.

Data Subject Rights

Under our BCRs, all data subjects retain the following rights regardless of where their data is processed within our corporate group:

  • Right to be informed about the processing of their personal data
  • Right of access to their personal data
  • Right to rectification of inaccurate data
  • Right to erasure (right to be forgotten)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

Accountability and Governance

Each entity within our corporate group is responsible for ensuring compliance with these BCRs. We have appointed a Group Data Protection Officer (DPO) who oversees implementation, conducts regular audits, and serves as the primary point of contact for data protection authorities and data subjects.

Complaint Handling

Data subjects who believe their rights have been violated may submit a complaint to our DPO. Complaints are acknowledged within 72 hours and investigated within 30 business days. If the complaint is upheld, we will take appropriate corrective action and, where applicable, notify the relevant supervisory authority.

Contact Our Data Protection Officer

For questions about our BCRs or to file a complaint, email track@kaztlogistics.com or write to: Data Protection Officer, Kazt Logistics, .

Liability

Under our BCRs, Kazt Logistics accepts liability for any damage suffered by a data subject due to unlawful processing of personal data by any entity within our corporate group, in accordance with Article 82 of the GDPR.

Audit and Review

Our BCRs are reviewed annually and updated as necessary to reflect changes in legal requirements, business operations, or best practices. The most recent review was conducted in January 2026.

Last updated: 15 January 2026