Skip to main content
The state of ai impact assessment
Category: Cross-Border Transfers

Standard Contractual Clauses

Also known as: SCCs, SCC, model contract clauses, EU Standard Contractual Clauses
Simply put

Standard Contractual Clauses are pre-written contract terms that companies can insert into agreements to protect personal data when it is sent to another country. They are designed to help ensure that data continues to receive appropriate protection even when it flows to a recipient in a country that does not automatically provide equivalent safeguards. In the EU context, they are model clauses that have been pre-approved by the European Commission.

Formal definition

Standard Contractual Clauses (SCCs) are standardized contractual provisions, pre-approved by the European Commission, that organizations may adopt to provide appropriate safeguards for transfers of personal data from the European Economic Area (EEA) to recipients located in third countries. Under the EU General Data Protection Regulation, they operate as one of the transfer mechanisms available under Article 46, specifically Article 46(2)(c), and function by imposing binding contractual obligations on the parties (for example, transferring and receiving entities) rather than by relying on an adequacy determination for the destination country. SCCs are a transfer instrument under the GDPR and should be distinguished from other safeguards such as binding corporate rules or adequacy decisions; the specific clause sets are periodically revised, and organizations should verify which version applies to a given transfer and confirm requirements against the current official text of the European Commission and the applicable regulation. Note that other jurisdictions (for example, the United Kingdom) maintain their own transfer instruments, so the EU SCCs do not necessarily satisfy non-EU transfer requirements. Application to specific transfers is fact-dependent and may require professional judgment; this entry is informational and not legal advice.

Why it matters

International data transfers are a routine but legally sensitive part of modern business, and the GDPR generally restricts personal data from leaving the European Economic Area unless appropriate safeguards are in place. Where the destination country has not received an adequacy decision from the European Commission, organizations need another lawful basis for the transfer. Standard Contractual Clauses are among the most widely used of these mechanisms because they can be adopted contractually without waiting for a country-level adequacy determination, making them a practical default for cross-border flows to many jurisdictions.

The stakes are significant because getting transfers wrong can expose an organization to enforcement action and can require halting data flows that underpin core operations, from cloud hosting to customer support. SCCs allow personal data subject to the GDPR to flow to recipients outside the EEA by imposing binding contractual obligations on the parties, which is why they feature so prominently in vendor agreements, intra-group arrangements, and cloud service contracts. Because they operate through contract rather than through a government-to-government adequacy finding, the responsibility for correct implementation rests with the contracting parties.

It is important to treat SCCs as one instrument among several rather than a universal solution. The specific clause sets are periodically revised, and the EU SCCs do not necessarily satisfy transfer requirements in other jurisdictions such as the United Kingdom, which maintains its own instruments. Organizations should confirm which version applies to a given transfer and verify requirements against the current official text of the European Commission and the applicable regulation.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for governing cross-border data flows rely on SCCs as a core transfer mechanism when data leaves the EEA to a country without an adequacy decision. They typically need to confirm which clause version applies, document the basis for a given transfer, and distinguish SCCs from other safeguards such as binding corporate rules or adequacy decisions.
Legal counsel and contract negotiators
Because SCCs are incorporated into agreements as binding contractual provisions, counsel negotiating vendor, intra-group, or cloud service contracts frequently work with them. They should verify that the correct, current clause set is used and assess whether EU SCCs alone address the transfer, noting that other jurisdictions such as the United Kingdom maintain their own instruments.
Cloud and technology vendors
Service providers that receive personal data outside the EEA, including cloud platforms, commonly offer SCCs to their customers so that GDPR-subject data can flow to them under appropriate safeguards. Both providers and their customers have obligations under the clauses that need to be understood and implemented.
Compliance officers and auditors
Those assessing an organization's data transfer practices need to confirm that SCCs are in place where required, that the applicable version is current, and that the arrangement is properly documented. Because clause sets are periodically revised, verification against the latest authoritative source is part of ongoing compliance monitoring rather than a one-time exercise.

Inside SCCs

Standardized data protection clauses
Pre-approved contractual terms that parties incorporate into agreements to provide safeguards for personal data transferred outside the jurisdiction of origin. In the EU context, SCCs are adopted by the European Commission and function as one recognized transfer mechanism under the GDPR.
Modular structure
The current EU SCCs are generally structured to address different transfer scenarios (for example, controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller), allowing parties to select the module that reflects their respective roles. Practitioners should verify the applicable modules against the current official text.
Obligations of the data exporter and importer
Provisions allocating responsibilities between the party transferring the data and the party receiving it, which may include data protection commitments, security measures, and cooperation duties. The specific obligations depend on the module and role selected.
Data subject rights and third-party beneficiary provisions
Terms that generally allow individuals whose data is transferred to invoke certain clauses and seek remedies, even though they are not signatories to the contract.
Supplementary measures and transfer impact assessment context
SCCs alone may not be sufficient where the law of the importer's jurisdiction undermines the protections. Parties are generally expected to assess the circumstances of the transfer and, where necessary, adopt additional safeguards. The precise expectations continue to evolve in enforcement and guidance.
Governing terms and liability provisions
Clauses addressing matters such as liability between the parties, applicable governing terms, and mechanisms for handling breaches, subject to the specific version in use.

Common questions

Answers to the questions practitioners most commonly ask about SCCs.

Do Standard Contractual Clauses legally guarantee that a data transfer is compliant on their own?
No. SCCs are a contractual transfer mechanism, not a self-executing guarantee of compliance. Adopting the clauses is generally a necessary step for certain cross-border transfers, but it does not by itself establish an adequate level of protection. In most cases the parties must also assess the laws and practices of the destination jurisdiction and, where the SCCs alone do not ensure an essentially equivalent level of protection, implement supplementary measures. Whether a given transfer is lawful is fact-specific and depends on the circumstances of the transfer and the recipient country.
Are the EU SCCs and the UK's transfer tools the same thing?
No. They are distinct instruments issued under different legal regimes. The European Commission's SCCs are adopted under the EU GDPR framework, while the United Kingdom operates its own arrangements following its departure from the EU. Because the jurisdictions and their governing texts differ, clauses drafted for one regime do not automatically satisfy the other. Organizations transferring data out of both the EU and the UK should confirm which instrument applies to each transfer and verify the current requirements against the relevant authoritative source for each jurisdiction.
Which set of SCC modules or provisions should we use for a particular relationship?
The applicable module generally depends on the roles of the exporting and importing parties, such as controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller arrangements. Selecting the correct configuration requires first characterizing each party's role accurately, since controller and processor obligations differ. Because role determinations and module structures can be nuanced, the specific selection should be verified against the current official text and, where the facts are complex, assessed with professional judgment.
Can we modify the wording of Standard Contractual Clauses to fit our contract?
The core clauses are generally intended to be adopted without alteration that would contradict or undermine their protections. Parties can typically complete the required annexes and add commercial terms, provided those additions do not conflict with the clauses or reduce the safeguards they establish. Because the permissible scope of modification is defined by the instrument itself, readers should confirm what may and may not be changed against the latest authoritative version.
What steps generally accompany the SCCs beyond signing them?
Executing the clauses is usually one part of a broader process. Depending on the transfer, this may include completing the required annexes with details of the parties, the data, and the processing; conducting an assessment of the destination jurisdiction's legal environment; and implementing supplementary measures where needed. Documentation of these steps is often expected to demonstrate accountability. The precise expectations depend on the transfer's risk profile and should be verified against current guidance.
Do existing SCCs need to be reviewed or updated over time?
Yes, review is generally advisable. SCCs and the legal frameworks around them are periodically amended or superseded, and prior versions may cease to provide a valid basis for transfers after transition periods set by the relevant authorities. Changes to the processing, the parties, or the destination jurisdiction's laws may also affect whether the clauses and any supplementary measures remain adequate. Organizations should monitor the current authoritative sources and reassess their arrangements accordingly.

Common misconceptions

SCCs are a voluntary standard or best-practice framework.
SCCs are a legal transfer mechanism recognized under data protection law, not a voluntary standard like ISO/IEC 27001 or SOC 2. In the EU they are adopted by the European Commission and carry legal effect when used to legitimize a transfer under the GDPR. Signing them creates binding contractual obligations.
Executing SCCs by itself makes any international data transfer lawful.
SCCs are generally one component of a compliant transfer, not an automatic guarantee. Depending on the circumstances, parties may need to assess the legal environment of the destination and adopt supplementary measures. SCCs also do not remove the need to satisfy other applicable obligations under the relevant regime.
There is a single global set of SCCs that applies everywhere.
SCCs are jurisdiction-specific. The EU Commission's SCCs are distinct from other jurisdictions' analogous instruments, such as the UK's own transfer tools. One region's clauses cannot be assumed to satisfy another region's requirements, and versions are periodically amended or superseded.

Best practices

Identify each party's role (controller or processor) before selecting SCCs, and choose the module that accurately reflects that role rather than defaulting to a single template.
Confirm you are using the current, officially adopted version of the clauses for the relevant jurisdiction, and monitor for amendments or superseding instruments.
Do not rely on SCCs in isolation; assess the circumstances of the transfer and consider whether supplementary measures are needed given the destination jurisdiction.
Distinguish the EU SCCs from analogous mechanisms in other jurisdictions, such as the UK, and use the correct instrument for each transfer route.
Document the analysis supporting the choice of SCCs and any additional safeguards, so the reasoning can be produced during an audit or assessment.
Treat SCCs as informational contractual terms whose application to specific transfers requires professional judgment, and verify obligations against the latest authoritative source and, where appropriate, qualified counsel.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps