Standard Contractual Clauses (SCCs): How Businesses Legally Export EU Personal Data to Non-Adequate Countries

Written by: Prakhar Rai, Founder, My Legal Pal | Bar Council of India | LL.B, NLSIU Bangalore | Master of Business Laws | Advises on GDPR, UK GDPR, and cross-border data transfer compliance


Quick answer

The GDPR restricts moving personal data out of the EEA unless the destination has specific legal cover. Standard Contractual Clauses, the European Commission’s pre-approved contract text, are the mechanism most businesses actually use to get that cover, since only a small list of countries currently have a full adequacy decision. The clauses come in four modules depending on who’s exporting and who’s receiving, they’ve required a documented Transfer Impact Assessment since the 2020 Schrems II ruling, and they aren’t a UK GDPR transfer tool on their own, a UK exporter needs the ICO’s UK Addendum layered on top, or the standalone UK IDTA instead. Below is what each mechanism actually covers, when you need one versus when an adequacy decision already does the job, and where businesses most often get the paperwork wrong.


Why a data export mechanism is needed at all

Chapter V of the GDPR, Articles 44 to 49, restricts transferring personal data outside the European Economic Area unless the transfer meets one of a specific set of legal conditions. This isn’t about whether the data itself is sensitive. It applies to an ordinary customer database, an HR system, or a SaaS tool’s backend, the moment personal data of someone in the EEA is going to leave it, whether that’s a server migration to a US cloud provider, an outsourced support team in India, or a parent company’s HQ in Singapore.

The GDPR gives three broad routes to make that transfer lawful:

  1. An adequacy decision. The European Commission has formally determined that the destination country’s own data protection law offers an essentially equivalent level of protection to the GDPR. If your destination has one, you can transfer data there under largely the same conditions as moving it within the EEA, no extra contract needed for this purpose specifically.
  2. Appropriate safeguards, most commonly Standard Contractual Clauses, but also Binding Corporate Rules for intra-group transfers, or approved codes of conduct and certification mechanisms.
  3. Specific derogations under Article 49, narrow exceptions for one-off situations, explicit consent, necessity for a contract, or public interest grounds, not a mechanism a business should be building its ongoing operations around.

For the overwhelming majority of businesses moving data to a vendor, a subsidiary, or a service provider outside an adequate country, SCCs are the practical answer, and getting the details right matters more than most businesses assume, because an invalid transfer mechanism doesn’t just risk a fine, it can mean the underlying data processing itself has no lawful basis to rest on.


The 2021 Standard Contractual Clauses: which module applies to you

The European Commission adopted a new set of SCCs in June 2021 (Commission Implementing Decision (EU) 2021/914), replacing the older 2001 and 2010 clauses. If your business, or a vendor you rely on, is still running data transfers on the pre-2021 clauses, that paperwork is no longer valid and needs replacing, not updating.

The 2021 clauses are modular, a single document with four possible configurations depending on the relationship between exporter and importer:

  • Module 1: Controller to controller. Both parties independently decide the purpose and means of processing. A common example: your EU business shares customer data with an independent partner outside the EEA who will use it for their own purposes.
  • Module 2: Controller to processor. You’re the controller in the EEA, and the importer outside the EEA processes the data strictly on your instructions, a payment processor, an email platform, an outsourced fulfilment vendor.
  • Module 3: Processor to sub-processor. You’re processing data on behalf of an EEA controller, and you’re passing some of that processing to a sub-processor outside the EEA.
  • Module 4: Processor to controller. You’re processing data on behalf of a non-EEA controller and transferring it back to them, less common, but relevant for certain outsourced-service arrangements.

Picking the wrong module isn’t a paperwork technicality. Each module carries a different allocation of liability, different audit and sub-processing rights, and different obligations if something goes wrong, so a controller-to-processor relationship signed on Module 1 language creates a genuine mismatch between what the contract says and what’s actually happening with the data.


When you actually need SCCs, and when an adequacy decision already covers you

As of this writing, the European Commission’s adequacy decisions cover a specific, and changing, list of countries and territories, including Switzerland, the United Kingdom, Japan, South Korea, New Zealand, Canada (for commercial organisations only), Argentina, Uruguay, Andorra, and the Channel Islands and Isle of Man, along with the United States specifically through the EU-U.S. Data Privacy Framework. This list is not static. The Commission reviews adequacy decisions periodically, and a country can be added, or in principle have a decision withdrawn, so a business relying on an adequacy decision as its transfer basis should treat that as something to reconfirm periodically, not something to file away as permanently settled.

The EU-U.S. Data Privacy Framework is worth a specific note, because it has a more contested recent history than most other adequacy decisions. It replaced the earlier Privacy Shield framework, which the Court of Justice struck down in the 2020 Schrems II decision. The DPF itself faced a direct legal challenge (the Latombe case) questioning the independence of the US Data Protection Review Court and the adequacy of safeguards around US intelligence agencies’ bulk data collection. The EU General Court dismissed that challenge in September 2025 and the DPF remains valid and in force, but the court’s reasoning explicitly noted the Commission’s ongoing duty to monitor the framework, and further legal challenge, including a possible appeal to the Court of Justice, hasn’t been ruled out. A US-facing transfer under the DPF is currently lawful, but it’s not the kind of mechanism to treat as beyond future scrutiny, and a business with meaningful exposure there should keep SCCs ready as a fallback rather than assuming the DPF is permanent.

If your destination country isn’t on the adequacy list, and it’s genuinely most of the world, SCCs (or Binding Corporate Rules, for the narrower case of transfers within a corporate group) are what makes the transfer lawful.


Schrems II and the Transfer Impact Assessment: SCCs alone aren’t enough anymore

Before July 2020, businesses often treated SCCs as a signature exercise, get the clauses signed, file them, move on. The Court of Justice’s Schrems II ruling changed that. The Court held that SCCs remain valid in principle, but an exporter can’t just rely on the contract text if the importing country’s own laws, particularly its surveillance and government-access laws, could undermine the protections the clauses promise in practice.

In practice, this means every SCC-based transfer now needs a documented Transfer Impact Assessment (TIA), examining:

  • The nature of the data being transferred and how sensitive it actually is.
  • The legal framework of the destination country, specifically whether government authorities there have broad access powers to the kind of data being transferred, and whether the importer would even be permitted to tell you if such a request were made.
  • Whether supplementary measures are needed on top of the SCCs themselves, encryption in transit and at rest with keys held outside the destination country’s reach, pseudonymisation, split processing, or contractual commitments from the importer to challenge overbroad government requests and notify the exporter where legally possible.

A TIA that concludes “the SCCs are sufficient on their own” without engaging with the destination country’s actual surveillance law is the single most common gap regulators and complainants have pointed to since Schrems II. This is also where the assessment for a data transfer to, say, India, China, or the US genuinely differs, each has different laws governing government access to data, and a template TIA copied across every destination country defeats the purpose of doing one at all.


SCCs vs. the UK’s IDTA and UK Addendum

Here’s where a large number of businesses trip up specifically: the 2021 EU SCCs, on their own, are not a valid transfer mechanism under UK GDPR. The UK left the EU’s regulatory orbit for data protection purposes after Brexit, and while UK GDPR is substantively similar to the EU version, its Article 46 transfer tools are separate instruments, issued by the UK’s Information Commissioner’s Office, not the European Commission.

For a UK-governed transfer, a business has two options:

The UK Addendum, a short document that sits alongside the EU SCCs and adapts them so the same underlying clauses also support a transfer governed by UK GDPR. This is the natural choice for a business that already uses EU SCCs for its EU-side transfers and wants one aligned set of documentation covering both the EU and UK legs of a data flow.

The UK International Data Transfer Agreement (IDTA), a standalone UK-specific instrument that doesn’t reference the EU SCCs at all. This suits a business operating primarily or exclusively under UK GDPR, without a parallel EU compliance programme to keep aligned.

Both were issued by the ICO and came into effect in 2022, and the ICO has signalled it plans to update both during 2026, so current versions remain valid for now, but a business relying on either should watch for that revision rather than treat the current text as permanently fixed. Note also that the UK adequacy decision, renewed by the European Commission in December 2025 and now running to December 2031, covers transfers from the EU to the UK, it doesn’t remove the UK’s own separate requirement for outbound transfers from the UK to elsewhere. A UK business sending data onward to, say, a US vendor still needs its own UK-specific transfer mechanism, the IDTA or the UK Addendum, regardless of what the EU side of the arrangement looks like.

For a UK-facing business building or reviewing this documentation under English law specifically, that’s precisely the kind of contract work our contract lawyers in London handle, distinct from, but closely related to, the EU-side SCC work described here.


A practical compliance checklist

Map the transfer before you paper it. Know exactly what data is moving, from where to where, and under which relationship (controller-to-controller, controller-to-processor, and so on), before drafting anything. This decides which SCC module actually applies.

Confirm you’re on the 2021 clauses, not the older 2001/2010 versions. Any SCC-based agreement signed before mid-2021 and never updated is very likely on outdated, legally superseded text.

Select the correct module, and don’t blend them. A single agreement covering multiple transfer relationships (say, both a controller-to-processor flow and a separate processor-to-sub-processor flow) generally needs the corresponding modules addressed distinctly, not one module’s language stretched to cover a relationship it wasn’t drafted for.

Do the Transfer Impact Assessment, and keep it on file. Not a generic statement that “the SCCs provide adequate protection,” but a specific assessment of the destination country’s surveillance and access laws, and a documented decision on whether supplementary measures are needed.

Check whether a UK leg exists, and cover it separately. If any part of the data flow is governed by UK GDPR, confirm whether you need the UK Addendum alongside your EU SCCs, or the standalone IDTA, don’t assume EU paperwork automatically covers it.

Revisit adequacy-based transfers periodically. A transfer that relies on an adequacy decision today, particularly to the US under the DPF, should be reviewed against the current state of that decision at reasonable intervals, not assumed permanent at the point of signature.

Keep your Article 30 records aligned with what you actually signed. Your data mapping and processing records should reference the specific transfer mechanism in place for each destination, so an audit or a regulator’s inquiry doesn’t turn up a mismatch between the documentation and the practice.


Mistakes that show up most often

Relying on old SCCs that were never migrated. The 2021 clauses replaced the earlier versions; agreements signed on the old text and never revisited are the single most common gap found during a vendor or acquisition due diligence review.

Treating the TIA as a formality rather than a genuine assessment. A one-line statement asserting adequacy of protection, without engaging with the destination country’s actual government-access laws, doesn’t meet the standard Schrems II set.

Assuming EU SCCs cover UK transfers. They don’t, on their own. This is the most frequent gap for businesses with a combined EU and UK footprint, who often paper the EU side correctly and simply forget the UK leg needs its own instrument.

Not tracking sub-processors. A Module 2 or Module 3 agreement typically requires the exporter’s knowledge, and often consent, before a new sub-processor is added downstream. Vendors add sub-processors more often than businesses actively track, and an unnoticed new sub-processor in a non-adequate country without its own coverage quietly breaks the chain.

Assuming an adequacy decision is permanent. The US Privacy Shield’s invalidation in 2020 is the clearest precedent for why this assumption is risky. An adequacy-based transfer today is lawful today; it’s not a substitute for having SCCs ready as a fallback for your higher-risk transfer relationships.


Frequently asked questions

Do I need Standard Contractual Clauses if I’m only transferring data to a country with an EU adequacy decision? No. If the destination country has a current adequacy decision, the transfer can generally proceed under broadly the same conditions as a transfer within the EEA, without SCCs being the specific mechanism relied on. It’s still worth confirming the adequacy decision is current, since this list is reviewed periodically and isn’t permanently fixed.

Which SCC module should a business use when sending customer data to an outsourced customer support vendor outside the EEA? Typically Module 2, controller-to-processor, since the vendor is processing the data on the exporting business’s instructions rather than for its own independent purposes. If the vendor is instead using the data for its own separate purposes beyond your instructions, that relationship is closer to Module 1, controller-to-controller, and needs different clauses entirely.

What is a Transfer Impact Assessment, and is it legally required? A Transfer Impact Assessment is a documented evaluation of whether the destination country’s laws, particularly around government and intelligence agency access to data, could undermine the protections the SCCs are meant to provide. Following the Court of Justice’s Schrems II ruling, this assessment is required for SCC-based transfers as a matter of practice, since SCCs alone are no longer treated as automatically sufficient without it.

Can a UK business use the EU’s 2021 Standard Contractual Clauses for its data transfers? Not on their own for a UK GDPR-governed transfer. The EU SCCs need the ICO’s UK Addendum attached to work as a valid UK transfer mechanism, or the business can use the standalone UK International Data Transfer Agreement instead. The EU SCCs by themselves cover only the EU side of a data flow.

Is the EU-US Data Privacy Framework a reliable long-term transfer mechanism? It’s currently valid and has survived its first direct legal challenge, the Latombe case, which the EU General Court dismissed in September 2025. However, given the fate of the earlier Privacy Shield framework and the possibility of further legal challenge to the DPF, a business with significant reliance on US transfers should still have SCCs prepared as a fallback rather than treating the DPF as a permanent arrangement.


Getting your transfer documentation right

SCCs, Transfer Impact Assessments, and the UK’s parallel instruments are contract and compliance documents that need to reflect your actual data flows, not a template pulled from a vendor’s website and signed without review. Our contract lawyers in the EU draft and review SCCs, Transfer Impact Assessments, and Data Processing Agreements against the specific transfer relationship and destination country involved, and for the UK leg of a combined EU-UK data flow, our contract lawyers in London handle the IDTA and UK Addendum side under English and UK GDPR requirements. If your privacy documentation more broadly needs a look, our GDPR, DPDPA, and CCPA-compliant privacy policy drafting service covers the notice obligations that typically need updating alongside your transfer mechanisms.

Related reading:


This article is general information, not legal advice. Adequacy decisions, the EU-U.S. Data Privacy Framework, and the UK’s IDTA and Addendum are all subject to ongoing legal challenge and revision. For advice on your organisation’s specific data transfer arrangements, speak to a qualified data protection lawyer. Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal, enrolled with the Bar Council of India, advising on GDPR, UK GDPR, and cross-border data transfer compliance.

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha