To start this process, we would draft our desired corporate rules, which must comply with the Data Protection Directive’s requirements (there are several but they do not need to be delved into here). Next we would submit those rules to our lead data protection authority (Germany). Upon Germany’s approval, that data protection authority will circulate the approved rules to all other data protection authorities in the EU