← IP, GDPR & Cybersecurity

GDPR · International transfers

Standard contractual clauses for international data transfers

When personal data is transferred to a recipient in a third country without an applicable adequacy decision, the Commission’s standard contractual clauses can provide appropriate safeguards. Signing the PDF alone does not complete the analysis: the correct module must be selected, the annexes completed and the effectiveness of protection assessed in the context of the country and service.

Decision 2021/914 transfer impact assessment supplementary measures
InstrumentSCC 2021/914, using the appropriate module
AnalysisCountry, laws, practices and authorities’ access
OperationalAnnexes, security, subprocessors and reassessment
01

First, identify the transfer

Server location is not the only criterion. Remote access from a third country, technical support, subprocessors and disclosure to a separate entity may create a transfer requiring analysis.

For each flow, the exporter, importer, roles, data categories, individuals, purpose, frequency and destination are established. If an adequacy decision applies to the recipient and transfer, SCCs may not be necessary; otherwise, the appropriate Chapter V instrument is analysed.

02

Selecting the module and completing the annexes

Decision 2021/914 contains modules for controller–controller, controller–processor, processor–processor and processor–controller relationships. An incorrect selection creates obligations misaligned with the actual roles.

  • The parties: entities, contacts, roles and signatures.
  • The transfer: data, individuals, frequency, purpose and retention.
  • The authority: identification of the competent supervisory authority.
  • Security: specific technical and organisational measures, not slogans.
  • Subprocessors: the list and authorisation or notification mechanism.
  • Options: the module’s clauses completed without altering mandatory protections.
03

Transfer Impact Assessment and supplementary measures

The exporter assesses whether the laws and practices of the importer’s country may prevent compliance with the SCCs, considering the nature of the transfer and objective, verifiable information. The importer must cooperate by providing information about the relevant framework and experience.

Where necessary, technical, contractual or organisational measures are added: encryption with keys controlled in the EEA, pseudonymisation, minimisation, transparency and procedures for authorities’ requests. If protection cannot be ensured, the transfer must not begin or continue.

04

Monitoring changes and onward transfers

The list of subprocessors, support countries and service characteristics may change. The exporter must follow notifications and reassess the transfer when new information emerges about laws, practices or security.

The importer cannot transfer data onwards without complying with the module’s conditions and Chapter V. The agreement must allow suspension, return or deletion if safeguards cease to work.

05

How we work together

  1. 01
    Collecting information

    We establish the processes, systems, providers, data categories, roles and existing documents relevant to the international transfer and SCCs.

  2. 02
    Risk and legality analysis

    We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.

  3. 03
    Documents and workflow

    We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.

  4. 04
    Controlled implementation

    We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.

QUESTIONS

Frequently asked questions

Do I need SCCs if the provider is in the EU?

Not for a relationship confined to entities and access within the EEA, but subprocessors and access from third countries must be checked. A DPA may still be necessary.

Can SCCs be amended?

They may be incorporated into a contract and supplemented with additional safeguards, but must not be amended in a way that contradicts the standard protections or individuals’ rights.

Is a TIA mandatory?

It must be assessed whether the country’s laws and practices permit compliance with the SCCs. The document is commonly called a TIA and must be tailored to the particular transfer.

Need SCCs and documentation for an international transfer?

Send your documents for a legal assessment and a solution tailored to your commercial objective.