Standard Contractual Clauses
Standard Contractual Clauses are pre-written contract terms that companies can insert into agreements to protect personal data when it is sent to another country. They are designed to help ensure that data continues to receive appropriate protection even when it flows to a recipient in a country that does not automatically provide equivalent safeguards. In the EU context, they are model clauses that have been pre-approved by the European Commission.
Standard Contractual Clauses (SCCs) are standardized contractual provisions, pre-approved by the European Commission, that organizations may adopt to provide appropriate safeguards for transfers of personal data from the European Economic Area (EEA) to recipients located in third countries. Under the EU General Data Protection Regulation, they operate as one of the transfer mechanisms available under Article 46, specifically Article 46(2)(c), and function by imposing binding contractual obligations on the parties (for example, transferring and receiving entities) rather than by relying on an adequacy determination for the destination country. SCCs are a transfer instrument under the GDPR and should be distinguished from other safeguards such as binding corporate rules or adequacy decisions; the specific clause sets are periodically revised, and organizations should verify which version applies to a given transfer and confirm requirements against the current official text of the European Commission and the applicable regulation. Note that other jurisdictions (for example, the United Kingdom) maintain their own transfer instruments, so the EU SCCs do not necessarily satisfy non-EU transfer requirements. Application to specific transfers is fact-dependent and may require professional judgment; this entry is informational and not legal advice.
Why it matters
International data transfers are a routine but legally sensitive part of modern business, and the GDPR generally restricts personal data from leaving the European Economic Area unless appropriate safeguards are in place. Where the destination country has not received an adequacy decision from the European Commission, organizations need another lawful basis for the transfer. Standard Contractual Clauses are among the most widely used of these mechanisms because they can be adopted contractually without waiting for a country-level adequacy determination, making them a practical default for cross-border flows to many jurisdictions.
The stakes are significant because getting transfers wrong can expose an organization to enforcement action and can require halting data flows that underpin core operations, from cloud hosting to customer support. SCCs allow personal data subject to the GDPR to flow to recipients outside the EEA by imposing binding contractual obligations on the parties, which is why they feature so prominently in vendor agreements, intra-group arrangements, and cloud service contracts. Because they operate through contract rather than through a government-to-government adequacy finding, the responsibility for correct implementation rests with the contracting parties.
It is important to treat SCCs as one instrument among several rather than a universal solution. The specific clause sets are periodically revised, and the EU SCCs do not necessarily satisfy transfer requirements in other jurisdictions such as the United Kingdom, which maintains its own instruments. Organizations should confirm which version applies to a given transfer and verify requirements against the current official text of the European Commission and the applicable regulation.
Who it's relevant to
Inside SCCs
Common questions
Answers to the questions practitioners most commonly ask about SCCs.

