Skip to main content
  • GDPR
  • Contracts

Standard contractual clauses: picking the right module and documenting the transfer

Signing the SCCs has not been enough since Schrems II. What to add, which module applies to your configuration, and what an acceptable transfer impact assessment looks like.

· 4 min read · AzerOps

The standard contractual clauses adopted by the European Commission in 2021 are the most used instrument for governing personal data transfers outside the European Union. They are also the most poorly applied, for a simple reason: many organisations sign them and stop there.

Picking the right module

Decision 2021/914 contains four modules. Using the wrong one makes the whole thing inoperative.

Module 1 — controller to controller. Rare in an IT services relationship.

Module 2 — controller to processor. This is the standard case: you entrust a non-EU provider with processing data for which you remain responsible. It is the one you will use in nearly all development, maintenance or managed services contracts.

Module 3 — processor to sub-processor. Applies when your provider itself uses a non-EU third party. You must verify that this module has been signed downstream, otherwise the chain breaks at the second link.

Module 4 — processor to controller. A particular, infrequent situation.

What must be added to the clauses

The Schrems II ruling established that the clauses alone are not enough where the destination country's law allows local authorities access to data that would empty those clauses of effect. Two further items must therefore be produced.

The transfer impact assessment. A document examining the destination country's legislation on government access to data, the existence of effective judicial remedies for data subjects, and the practical likelihood that an access request would target your data. A serious two-page report is worth more than thirty generic ones.

Supplementary measures. They must concretely reduce the identified risk. The most effective, in descending order:

  • Do not transfer the data at all. Remote access to an environment that stays in an EU region, with no local copy: legally the transfer still exists, but the exposure is greatly reduced.
  • Pseudonymisation in development. The provider works on data that cannot identify a person without a mapping table that stays with you.
  • Encryption with client-side key management. If the keys never leave the European Union, access to encrypted data has little value.
  • Logging and a challenge undertaking. The provider commits to informing you of any access request and to challenging it as far as local law allows.

The documentation that stands up to a regulator

Three items must exist, dated and signed:

  1. The clauses themselves, in the right module, with the annexes completed — description of processing, technical measures, list of sub-processors. An empty annex is a non-compliance.
  2. The transfer impact assessment, dated, citing the sources consulted.
  3. The description of the supplementary measures actually implemented, verifiable.

The most common mistake

Unfilled annexes. The standard clauses are a template: their legal value rests on the annexes, which describe your own processing. A contract reproducing the Commission's text with blank annexes, or annexes filled with one generic sentence, is worth nothing under scrutiny.

The second most common mistake is forgetting to update. The sub-processor list changes, technical measures evolve, the authorised staff are no longer the same. Provide for an annual review, and write it into the contract.

Related articles

Twenty minutes is enough to know whether we are useful

No sales deck. You describe the need, we say whether it is in scope, at what price and on what timeline. If it is not for us, we say so during the call.