Skip to content

Standard contractual clauses: when do you use them?

Decide when EU standard contractual clauses are needed, choose the correct transfer module, assess Clause 14 and complete the annexes before signing.

Two pairs of hands sort blank contracts into olive trays beneath WHEN YOU NEED STANDARD CONTRACTUAL CLAUSES, with cards for FOUR MODULES, CLAUSE FOURTEEN CHECK, DOCKING CLAUSE and NO ADEQUACY DECISION.
By AI Priority Map Editorial

Quick Answer: Standard contractual clauses safeguard personal data transfers to a third country without an adequacy decision. Use the 2021 clauses only after identifying the transfer, exporter and importer roles, choosing the matching module, assessing destination laws under Clause 14 and completing the annexes. They do not replace every other transfer or processing duty 1,2.

Summary in a mind map

Standard contractual clauses: when do you use them?
│
├─ Confirm the transfer
│   ├─ Personal data goes to a third-country recipient
│   ├─ Adequacy is checked before Article 46
│   └─ The 2021 decision must fit the importer
│
├─ Build the contract
│   ├─ Select one of four role-based modules
│   ├─ Assess destination law under Clause 14
│   └─ Complete the annexes before signature
│
└─ Maintain the parties
    ├─ Dock a new party only with agreed accession
    ├─ Annex I.A marks the joining party
    └─ Old 2001 and 2010 transitions have ended

Decide whether SCCs are the right tool

Imagine a small EU software agency appointing a service provider outside the EU/EEA to handle customer support records. The agency's first question is not where to find a signature template. It is whether personal data will be transferred, who exports and imports it, whether the destination has an adequacy decision, and which legal roles the parties hold for this flow. Only then can it decide whether Commission standard contractual clauses (SCCs) are a suitable safeguard 1,2.

Article 46(1) GDPR addresses transfers to a third country or international organisation where there is no adequacy decision. It calls for appropriate safeguards together with enforceable rights and effective legal remedies for data subjects. Article 46(2)(c) names standard data protection clauses adopted by the Commission among the safeguards that can be used without specific supervisory authority authorisation. The clauses are therefore one legal route, not the definition of every international transfer 1.

The 2021 Commission decision says its annexed clauses provide appropriate safeguards for specified transfers from a controller or processor processing data subject to the GDPR to a controller or sub-processor whose processing of that data is not subject to the GDPR. That scope matters. A contract cannot become the right transfer tool merely because both parties call it an SCC. The agency must map the actual data flow and the importer's position before choosing the 2021 form 2.

First testIf the answer is yesIf the answer is no
Is there a transfer of personal data to a third-country recipient?Identify exporter, importer and flow.Do not apply transfer SCCs merely to a domestic service arrangement.
Is an adequacy decision available for this transfer?Assess that route before selecting Article 46 safeguards.Consider an Article 46 safeguard such as SCCs.
Does the 2021 decision's role and scope fit?Choose the module and complete the transfer terms.Consider Article 46(2) alternatives: binding corporate rules, an approved code of conduct with enforceable commitments, or approved certification with such commitments 1.

Article 46 also requires enforceable rights and effective legal remedies. Choosing an instrument therefore does not eliminate the need to describe the real transfer and meet that instrument's conditions 1,2.

When the transfer needs another route

An adequacy decision changes the starting point. Article 46's safeguards address the absence of such a decision. If a particular transfer is covered by adequacy, the business should not describe SCCs as the indispensable reason that transfer can happen. If adequacy is absent, it still must ask whether the 2021 decision covers this exporter, importer and processing relationship. Both questions precede signature 1,2.

There is a second distinction between a transfer contract and a service contract. The Commission decision states that its transfer clauses provide safeguards for international transfers. Its recitals say the clauses can sit in a wider contract so long as added terms do not contradict them or prejudice data subjects' rights. The agency might therefore have a commercial supply agreement and a transfer schedule, but neither document's title settles the Article 46 analysis 2.

A third-country company can also be inside the GDPR's territorial scope for some activities. The 2021 decision describes the transfer clauses as usable where the importer's processing is not subject to the GDPR. That is why the agency should not infer applicability from the supplier's country alone. It should identify the actual processing to be covered. The Commission's explanation of the 2021 clauses likewise describes transfers to controllers or processors outside the EU/EEA and not subject to the GDPR 2,3.

The Commission says it is developing additional SCC sets for transfers to controllers or processors outside the EU whose own processing is directly subject to the GDPR. For such an importer, do not treat the 2021 set as automatically fitting merely because the destination lacks adequacy 3.

Where the facts are unsettled, the agency should pause the transfer-route decision rather than copy a standard paragraph into procurement paperwork. It can still collect the necessary facts: which records move, where they go, who receives them, and for what service. That information is useful whether SCCs are ultimately selected or another legal route applies. The record prevents the first legal question from being hidden inside an unsigned annex 1,2.

Choose one of four modules

The 2021 clauses combine general provisions with a modular structure. Controllers and processors choose the module that matches their roles and responsibilities for the transfer. Four role combinations cover controller to controller, controller to processor, processor to processor and processor to controller. A firm should select the combination for a particular flow, rather than paste all modules into one schedule and hope the correct text somehow applies 2.

The software agency may be a controller for its own customer relationships while acting as a processor when it handles records for another company's service. The same legal entity can therefore be on a different side of a role pair in another data flow. A role assessment at company level alone is too coarse. The transfer record should name the exporter and importer for the flow, their roles and the module selected on that basis 2.

Exporter roleImporter roleModule to select
ControllerControllerModule One
ControllerProcessorModule Two
ProcessorProcessorModule Three
ProcessorControllerModule Four

The module choice is a substantive part of the contract, not a formatting preference. Each route assigns obligations to parties with different roles. If the agency sends support records as a processor but selects controller-to-processor terms, the paperwork misdescribes the data flow. Clarify the roles with the controller or processor guide. The article on building governance in from day one places that decision within a broader management approach.

The firm should also distinguish multiple flows with the same supplier. Some information may be sent for the agency's own business; other information may be processed for a client. Describing both simply as "customer data" hides the role difference. A short transfer table with a row per flow is more reliable than a single supplier-level label. It also gives the eventual Clause 14 assessment a defined scope 2.

Assess the destination under Clause 14

Clause 14 asks the parties to warrant that they have no reason to believe the laws and practices in the third country of destination prevent the importer from fulfilling the clauses. It expressly includes requirements to disclose personal data and measures authorising access by public authorities. This is not satisfied by selecting the correct module. The parties need a reasoned view of the destination and the transfer to support the warranty they are making 2.

For the software agency, the assessment begins with the identified support records, the recipient, the destination and the service. A vague assessment of "international transfers" would not show whether the relevant local laws and practices affect this importer and data flow. Equally, a document that discusses only cybersecurity while ignoring public authority access would not address a matter Clause 14 specifically names. The agency can ask its supplier for information, but both parties make the contractual warranty 2.

Clause 14(b) requires the parties to consider three elements before that warranty 2:

  1. The transfer's specific circumstances: chain length, actors, channels, onward transfers, recipient, purpose, categories and format of data, sector and storage location.
  2. Relevant destination laws and practices, including disclosure requirements or public-authority access, in light of those circumstances.
  3. Relevant contractual, technical or organisational supplementary safeguards.

The importer must make its best efforts to give the exporter relevant information under Clause 14(c). Both parties must document the assessment and make it available to the competent supervisory authority on request under Clause 14(d). Annex footnote 12 lets the parties rely on documented experience of past public-authority disclosure requests, or their absence, over a representative period, such as internal records certified at senior-management level, but only alongside other relevant, objective elements 2.

This assessment is distinct from selecting an Article 46 instrument. Article 46 explains why an appropriate safeguard is needed when adequacy is absent; Clause 14 tests a condition of relying on this particular set of clauses for the selected transfer. Keeping the two questions separate makes the file reviewable. A reviewer can see first why SCCs were selected, then why the parties could make the destination-law warranty 1,2.

Add a party with the docking clause

Clause 7 is optional, so docking is available only if the signed clauses include it 2. With the existing parties' agreement, a new entity completes the Appendix and signs Annex I.A. It has no rights or obligations under those clauses for the period before becoming a party. The route supports a growing transfer chain without pretending a later signature governed earlier conduct 2.

If the agency adds a second supplier after the original SCC arrangement was signed, it should first identify the new supplier's role and the transfer it will receive. Then it can ask whether the existing parties agree to accession and complete the required documents. Merely adding a name to a vendor list does not satisfy the clause's signature and Appendix requirements. Nor does the mechanism automatically determine the right module for the new flow 2.

The absence of retroactive rights or obligations is a practical timing warning. A company should not allow a new recipient to start receiving data and plan to "dock" it later as if the later signature covers the past. The contract states the opposite. Accession can simplify future participation, but the date of becoming a party remains material to what the clauses cover 2.

European Commission SCCs replaced 2001 and 2010

The Commission issued the modernised transfer SCCs on 4 June 2021. They replaced the earlier sets adopted under the former data protection directive. The transition for contracts concluded before 27 September 2021 under Decisions 2001/497/EC or 2010/87/EU did not last indefinitely. Article 4(4) of the 2021 decision deemed those contracts to provide appropriate safeguards only until 27 December 2022, and only if the processing operations remained unchanged 2,3.

The date is now historical, but old forms still appear in shared drives and supplier folders. The agency should identify any current transfer whose file still relies on those decisions. It should distinguish a superseded attachment from a current signed arrangement. If the old text remains the asserted safeguard, the former transition cannot be cited as continuing authority in 2026. The question is what valid transfer basis the firm now has for the actual flow 2.

This review should focus on active transfers, not merely document names. A contract can include a newer schedule while an old PDF remains in the folder, or it can be labelled "updated" while still carrying obsolete clauses. The decision's dates make the issue concrete: a pre-September 2021 contract had a conditional grace period ending in December 2022. A later contract did not inherit an open-ended right to use the old sets 2.

The historic change also explains the modular design. The Commission describes the 2021 clauses as modernised for transfers from EU/EEA controllers or processors to recipients outside the EU/EEA who are not subject to the GDPR. The decision's recitals discuss more complex processing chains and participation by multiple parties. A review that updates the year in a heading but ignores the new structure would miss the point of the replacement 2,3.

Complete the annexes before signature

The decision provides fields for the actual parties, transfer and safeguards. Complete them against the proposed service, rather than attaching an empty Appendix 2.

AnnexFields to complete under the 2021 decision
I.A — List of partiesName; address; contact person's name, position and contact details; relevant transfer activities; signature and date; controller or processor role 2.
I.B — Description of transferData-subject and data categories; sensitive data where applicable; frequency; processing nature and purposes; retention period; and, for transfers to processors or sub-processors, subject matter, nature and duration. Include the actual data flow 2.
I.C — Competent authorityIdentify the competent supervisory authority 2.
II — Technical and organisational measuresDescribe measures in specific, not generic, terms 2.
III — List of sub-processorsComplete for Modules Two and Three where sub-processors need specific prior authorisation (Clause 9(a), Option 1) 2.

The transfer description should match the systems and locations used in practice. If technical staff describe a different destination or processing chain, resolve that difference before signing. Annex I.A also matters when another party docks later, because Clause 7 requires the new party's signature there 2.

A worked supplier decision

Consider a support supplier outside the EU/EEA receiving customer records from the agency as controller. If the destination has no adequacy decision and the 2021 decision fits the importer's processing, the agency selects Module Two, controller to processor. It fills Annex I.B with the categories of customers and records, transmission frequency, nature and purpose of the processing, retention period and, because the supplier is a processor, the subject matter and duration of the processing, rather than writing only “support data” 1,2.

For Clause 14, the parties record the support chain's actors, transmission channel, storage location, data categories and purpose, then examine relevant destination law and supplementary measures. The importer supplies relevant information; both parties retain the assessment. If the signed set includes optional Clause 7, a later supplier can join with agreement, a completed Appendix and an Annex I.A signature 2.

The resulting file has a defined Module Two transfer, the Annex I.B particulars and a documented Clause 14 assessment. It gives a reviewer actual parties, data and safeguards to compare against the signed terms 2.

In words, the tree branches like this: establish whether there is a third-country transfer; if not, transfer SCCs are not the route. If there is adequacy, examine that route. Without adequacy, check whether the 2021 decision fits the parties and processing, choose the module, assess Clause 14 and finish the annexes before signing 1,2.

What the clauses cannot decide

The clauses address the international transfer safeguard, while a supplier may have separate processing obligations 1,2. An order processing automation workflow is one example whose supplier data flow deserves its own transfer row. If a supplier outside the EU/EEA runs an automated decision tool on transferred records, the clauses cover only the transfer; whether a decision about a person in the UK is lawful is covered in the UK decision-making guide. For UK marketing contacts, the UK business email guide helps examine the communication that produces the records before any international transfer is assessed.

If the agency cannot establish the importer's position or make the Clause 14 warranty, it should record the gap and resolve it before claiming that the clauses make the transfer lawful. A missing fact is not a reason to change the legal threshold. The same caution applies to a half-completed Appendix. The contract's standard language does not fill the factual parts automatically 2.

What to do next

Create one row per active international data flow. Note the exporter, importer, roles, destination, adequacy position and the reason an Article 46 route is needed. For a transfer fitting the 2021 decision, select the applicable module, document the Clause 14 assessment and complete the annexes before signature. Check any legacy 2001 or 2010 clauses against the transition that ended on 27 December 2022 1,2.

If the agency needs accountability documents alongside this work, GDPR Accountability Documentation creates a tailored record of processing and, where the agency's questionnaire answers call for it, a processor agreement for each vendor the agency declares. The transfer route, the Clause 14 assessment and the completed SCCs still require their own decision on the actual data flow.

Frequently Asked Questions

Are standard contractual clauses needed for every overseas supplier?
No. First decide whether personal data is transferred to a recipient in a third country and whether an adequacy decision covers that transfer. Article 46 provides safeguards, including Commission standard clauses, in the absence of adequacy. The 2021 transfer clauses are designed for specified exporter and importer roles and an importer whose relevant processing is outside the GDPR's scope. The supplier's address alone does not settle those questions [1][2].
Can a company sign the clauses without a transfer assessment?
No. Clause 14 requires the parties to consider the transfer's circumstances, relevant destination laws and practices, and any supplementary safeguards before they warrant compliance. The importer must make its best efforts to provide relevant information. Clause 14(d) requires both parties to document that assessment and make it available to the competent supervisory authority on request. A signature alone supplies none of this evidence [2].
Which of the four SCC modules should a business choose?
Choose the module that reflects the exporter and importer roles in the particular transfer. The 2021 clauses use a modular approach so controllers and processors select the applicable combination rather than signing every module. An organisation acting as a controller for one flow and a processor for another may need different selections. The roles must be established for each flow before completing the annexes [2].
Can a new supplier join an existing SCC arrangement?
Yes, if the signed set includes the optional Clause 7 docking clause and the parties agree. The new entity completes the Appendix and signs Annex I.A. It then becomes a party from accession; the clause says rights and obligations do not arise for the period before it joined. That makes accession possible without treating earlier activity as retrospectively covered by the new signature [2].
Are the 2001 and 2010 transfer clauses still enough?
No. For contracts concluded before 27 September 2021 under Decisions 2001/497/EC or 2010/87/EU, the transitional safeguard lasted only until 27 December 2022, provided processing operations remained unchanged. The Commission issued the modernised 2021 clauses on 4 June 2021. A firm relying on an old form today should review and replace that basis rather than cite the expired transition [2][3].
What belongs in the SCC annexes before signature?
Complete Annex I.A with the parties, I.B with the transfer, and I.C with the competent authority. Annex II must describe technical and organisational measures in specific, not generic, terms. Annex III lists sub-processors for Modules Two and Three where the parties chose specific authorisation under Clause 9(a). These are the decision's actual fields; a generic placeholder cannot identify which parties, data flow and safeguards the signed clauses cover [2].
Did the EDPB issue guidance on these European Commission SCCs?
The 2021 Commission decision records that the European Data Protection Supervisor and European Data Protection Board were consulted and delivered a joint opinion on 14 January 2021, identified as EDPB-EDPS Joint Opinion 2/2021. That recital establishes consultation, not the content of separate EDPB guidance on applying these clauses. A business should use the decision's own clauses and annexes for the contract described here [2].

Sources

  1. 1.Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) — EUR-Lex · 2016
  2. 2.Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council — EUR-Lex · 2021
  3. 3.Standard Contractual Clauses (SCC) — European Commission · 2021

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.