The European Commission’s 2021 Standard Contractual Clauses (SCCs) are a pre-approved Article 46 safeguard for certain transfers of personal data to third countries. They are not a blanket permission: parties must select the correct module, complete the clauses and annexes accurately, assess whether protection is effective in context, and implement supplementary measures where necessary.
First confirm that SCCs are the right tool
Before drafting, document:
- the data exporter and importer and their actual roles;
- whether a Chapter V transfer occurs;
- whether a current adequacy decision covers the transfer;
- whether another safeguard is used; and
- whether the 2021 SCCs fit the importer and scenario.
The Commission’s Q&A explains that the 2021 transfer SCCs were designed for transfers to importers whose relevant processing is not subject to the GDPR. The Commission has been developing additional clauses for transfers to importers already directly subject to the GDPR. Check the current Commission materials rather than forcing a module onto an incompatible scenario.
Article 49 derogations have specific conditions and are generally not a routine alternative to a durable transfer framework.
Choose the correct module
| Module | Exporter | Importer |
|---|---|---|
| 1 | Controller | Controller |
| 2 | Controller | Processor |
| 3 | Processor | Processor |
| 4 | Processor | Controller |
Role classification must reflect facts. For Modules 2 and 3, the SCCs incorporate relevant Article 28 requirements, but the parties still need accurate instructions, security measures, sub-processor arrangements and operational oversight.
Complete the package
Do not sign blank or generic annexes. Record:
- parties, contacts, roles and accession details;
- categories of individuals and personal data;
- sensitive data and applied restrictions or safeguards;
- transfer frequency, nature, purposes and retention;
- competent supervisory authority;
- technical and organisational security measures; and
- authorised sub-processors where applicable.
Use the docking clause carefully when adding parties and keep an executed, version-controlled package. Commercial terms may sit beside the SCCs, but they must not contradict the clauses or prejudice individuals’ rights.
Assess the transfer context
The parties must warrant they have no reason to believe that the destination’s laws and practices prevent the importer fulfilling the SCCs, based on the required assessment. The EDPB’s supplementary-measures recommendations set out a practical sequence:
- know and map transfers, including onward transfers;
- identify the relied-on transfer tool;
- assess whether the tool is effective in light of the destination’s law and practice and the transfer circumstances;
- adopt supplementary measures where needed;
- take any required formal procedural steps; and
- re-evaluate at appropriate intervals and when circumstances change.
Call the record a transfer assessment, transfer impact assessment or similar; the label matters less than complete, supportable reasoning.
Supplementary measures
Measures may be contractual, organisational and technical. Depending on the risk and access scenario, examples can include strong encryption with keys unavailable to the importer or relevant authorities, effective pseudonymisation, data minimisation, access restrictions, transparency commitments and procedures for government requests.
Extra contract promises cannot cure every conflict in destination law. If no combination provides essentially equivalent protection in practice, do not start the transfer or suspend/terminate it as the clauses require.
Operate and monitor the SCCs
Assign owners for:
- sub-processor and onward-transfer changes;
- government-access requests and notification limits;
- incidents and individual-rights assistance;
- changes in destination law or practice;
- security measure verification;
- adequacy or framework status where relevant; and
- suspension, deletion, return and termination.
Review is event-driven as well as periodic. A contract signed in 2021 is not self-maintaining.
UK transfers are different
The EU SCCs are not valid on their own for a restricted transfer under the UK GDPR. A UK exporter may need the UK IDTA or the UK Addendum to the EU SCCs and must follow current ICO guidance. A combined commercial relationship can require separate EU and UK transfer routes.
Our data protection services can map transfers, select modules and document assessments. A GDPR audit can test whether signed SCCs match actual systems, recipients and onward flows.
Sources and review
- European Commission: Standard Contractual Clauses for international transfers
- European Commission: 2021 SCC questions and answers
- EDPB Recommendations 01/2020 on supplementary measures
- ICO: UK IDTA and Addendum guidance
Reviewed on 8 August 2026. The guide distinguishes EU and UK mechanisms and avoids describing signature, adequacy or supplementary measures as automatic compliance.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.