Standard Contractual Clauses (SCCs)

Pre-approved EU contract text you bolt onto a vendor agreement so personal data can legally leave Europe. Fill in the annexes, never edit the clauses.

the EU transfer clausesboilerplate for sending data abroadSCCsmodel clausesstandard contractual clauses SCCthe annex my vendor sent me to signEU standard contract for data transferswhat do I sign to send data to a US vendor

See it

Live demo coming soon

What it is

The European Commission publishes fixed contract language that, once signed by both sides, supplies the safeguards GDPR demands for moving personal data out of the EEA. The 2021 set replaced the old 'model clauses' and is modular: pick module 1 (controller to controller), 2 (controller to processor), 3 (processor to processor), or 4 (processor to controller) based on the roles on each side. Most SaaS vendors staple them to their DPA already countersigned, so 'signing SCCs' usually means accepting their DPA.

The real work lives in the annexes, not the clauses. Annex I names the parties, the data subjects, the data categories, and the purposes. Annex II lists your actual technical and organizational security measures. Annex III lists subprocessors. Leaving those blank, or writing 'as described in the agreement', is the most common way an SCC package dies in enterprise review.

Two gotchas. You cannot edit the clause text: wrap commercial terms around it if you like, but change the body and the mechanism is void. And SCCs are not automatically sufficient after Schrems II: you owe a transfer impact assessment first, and supplementary measures like strong encryption with keys held in the EEA only where that assessment shows the clauses alone will not hold up against the destination country's law. A UK restricted transfer takes either the UK's own International Data Transfer Agreement as a standalone contract, or the UK Addendum bolted onto the EU SCCs. The Addendum is one of the two options, not a universal extra.

Ask AI for it

Assemble a Standard Contractual Clauses package for a transfer from an EU customer to a US SaaS vendor. Do not draft, paraphrase, or regenerate the clause text: use the official 2021 European Commission text verbatim from the published decision, and if you do not have that text in front of you, say so instead of reproducing it from memory. Your job is the elections and the annexes. Identify which of the four modules applies and say why, then make the docking-clause and optional-clause choices explicit. Annex I: parties, transfer description (categories of data subjects, personal data, any sensitive data, frequency, nature and purpose, retention) and the competent supervisory authority. Annex II: the technical and organizational measures actually in place, taken from the facts I supply, covering encryption in transit and at rest, key management, least-privilege access control, logging, pseudonymization, backup and restore, and subprocessor vetting. Annex III: the subprocessor list with locations. Every fact I have not supplied becomes a bracketed TODO rather than a plausible-sounding invention. Add a one-page transfer impact assessment, and add UK documents (the International Data Transfer Agreement or the UK Addendum, whichever we choose) only if there is an actual UK restricted transfer here.

You might have meant

cross border data transferdata processing agreementgdprsubprocessordata controller and data processor

Go deeper