Standard Contractual Clauses (SCCs) Explained (2026)

By Recording Law Editorial TeamReviewed May 19, 202620 min read
Standard Contractual Clauses (SCCs) Explained (2026)

Frequently Asked Questions

What are Standard Contractual Clauses (SCCs)?

Standard Contractual Clauses are pre-approved contractual terms adopted by the European Commission under GDPR Article 46(2)(c). They create binding data protection obligations between a data exporter in the EEA and a data importer outside the EEA. The current version, adopted in June 2021 (Implementing Decision 2021/914), replaced older clauses from 2001/2004 and 2010. SCCs are the most widely used legal mechanism for international data transfers from the EU.

What are the four SCC modules and when do you use each one?

Module 1 (Controller-to-Controller) applies when an EU controller transfers data to a non-EEA controller. Module 2 (Controller-to-Processor) covers EU controllers engaging processors outside the EEA, such as cloud providers. Module 3 (Processor-to-Processor) applies when an EU-based processor engages a sub-processor outside the EEA. Module 4 (Processor-to-Controller) covers EU processors returning data to non-EEA controllers. A single SCC agreement can incorporate multiple modules for parties with different roles across different processing activities.

What is a Transfer Impact Assessment (TIA)?

A Transfer Impact Assessment evaluates whether the laws and practices of the destination country provide protection essentially equivalent to EU standards. Clause 14 of the 2021 SCCs requires parties to complete a TIA before transferring data. The assessment examines the destination country's surveillance laws, government access frameworks, and available legal remedies. If the TIA identifies risks, organizations must implement supplementary measures (technical, contractual, or organizational) to bridge the protection gap.

Are the old SCCs still valid?

No. The European Commission set a mandatory transition deadline of December 27, 2022, by which all organizations had to replace old SCCs (the 2001/2004 controller-to-controller clauses and the 2010 controller-to-processor clauses) with the 2021 version. Any data transfers still relying on the old SCCs after that date lack a valid legal basis under the GDPR.

Can SCCs be used for transfers to the United States?

Yes. SCCs remain a valid mechanism for transfers to the US, whether or not the recipient is certified under the EU-US Data Privacy Framework (DPF). For transfers to DPF-certified organizations, SCCs can serve as a backup. For transfers to non-certified US organizations, SCCs are typically the primary transfer mechanism. A Transfer Impact Assessment must evaluate US surveillance laws, particularly FISA Section 702 and Executive Order 12333, and appropriate supplementary measures must be implemented.

What is the UK equivalent of EU SCCs?

The UK has two options: the International Data Transfer Agreement (IDTA), a standalone contract approved by the ICO in March 2022, and the UK Addendum to the EU SCCs, which adapts existing EU SCCs for UK law. EU SCCs alone cannot be used for transfers governed by UK GDPR. Organizations must also complete a Transfer Risk Assessment following ICO guidance. The UK's Data (Use and Access) Act 2025 (Royal Assent June 19, 2025) changed the UK transfer standard; the ICO published updated guidance on January 15, 2026 and plans to update the IDTA and Addendum during 2026.

What supplementary measures can organizations implement alongside SCCs?

Supplementary measures fall into three categories. Technical measures include end-to-end encryption (where only the exporter holds the decryption key), pseudonymization, and split processing. Contractual measures require importers to challenge government access requests and provide transparency reports. Organizational measures include access controls, data minimization, and regular audits. The EDPB has emphasized that technical measures preventing access to readable data are the most effective safeguard in high-risk jurisdictions. Contractual and organizational measures alone cannot compensate for a destination country's legal framework that permits compelled government access to data.

How often must Transfer Impact Assessments be updated?

The SCCs require ongoing compliance, not a one-time assessment. Organizations must reassess their TIAs when circumstances change materially, such as new surveillance legislation in the destination country, changes to sub-processing arrangements, new government practices, or relevant court rulings. The EDPB recommends establishing a regular monitoring process for legal developments in all destination countries. The EDPB's 2025 Guidelines 02/2024 on Article 48 GDPR added an additional risk factor to assess: the importer's legal obligations when third-country government authorities demand access to the personal data.

What are the new SCCs for GDPR-subject importers, and when will they be available?

The European Commission is developing a new set of SCCs specifically for transfers to controllers and processors outside the EEA whose processing is already directly subject to the GDPR under Article 3(2), for example because they target EU residents. The 2021 SCCs are not suitable for this scenario because they assume the importer is not subject to the GDPR. The Commission planned a public consultation for Q4 2024 and a draft for adoption in Q2 2025. As of May 2026, a formal implementing decision had not been published in the Official Journal. Organizations should monitor the Commission's SCCs page for the formal adoption announcement.

How do SCCs compare to Binding Corporate Rules (BCRs)?

SCCs are contractual clauses used for individual transfer relationships; they can be used by any organization and require no prior approval from a supervisory authority. Binding Corporate Rules are intra-group policies approved by a lead supervisory authority under GDPR Article 47. BCRs cover all intra-group transfers within the approved scope without case-by-case SCC agreements, making them efficient for large multinationals, but obtaining approval typically takes one to three years and substantial legal resources. BCRs cannot be used for transfers to external parties; SCCs remain necessary for those. The two mechanisms are complementary.

Do I need SCCs for transferring data from the EEA to the UK?

No. The European Commission's adequacy decision for the UK covers EEA-to-UK transfers, meaning no SCC or other Article 46 mechanism is required for those transfers. The adequacy decision was renewed on December 19, 2025 and is valid until December 27, 2031. However, UK-based organizations transferring data outside the UK to non-adequate countries still need the UK IDTA or UK Addendum (the UK equivalents of EU SCCs) for those outbound transfers.

Updates

Audit-and-evolve refresh. Expanded from ~2,410 to ~4,800 words. Added: new H2 "Quick Answer" (AEO-optimized lede section); new H2 "The Pending SCCs for GDPR-Subject Importers" (Article 3(2) gap, Commission development status, not yet formally adopted as of May 2026); new H2 "SCCs, Adequacy Decisions, and Binding Corporate Rules Compared" (comparison table); new H2 "Recent Developments (2024 to 2026)". Updated sections: DPF section expanded with General Court Latombe dismissal (Sept. 3, 2025) and CJEU appeal pending (filed Oct. 31, 2025); UK mechanisms section updated for Data (Use and Access) Act 2025 (Royal Assent June 19, 2025) and ICO January 2026 guidance update; Common Challenges section added fifth challenge (Article 3(2) transfers). Added enforcement Watch Out callout: Meta 1.2B euro fine (EDPB Binding Decision 1/2023) and Dutch DPA Uber 290M euro fine (2024). Added EDPB Guidelines 02/2024 on Article 48 GDPR (final, June 5, 2025). UK adequacy renewal noted (Dec. 19, 2025, valid to 2031). Fixed malformed UK GDPR internal link in KeyTakeaways. Added Schrems II full case citation. FAQ expanded from 8 to 11 pairs. Citations expanded from 6 to 12. Added UpdatesLog component. Previous review: 2026-03-28.

Expanded to cover: (1) General Court's September 3, 2025 dismissal of the Latombe DPF challenge and the pending CJEU appeal filed October 31, 2025; (2) UK Data (Use and Access) Act 2025 (Royal Assent June 19, 2025) and the ICO's January 2026 updated guidance on international transfers; (3) the European Commission's pending development of new SCCs for GDPR Article 3(2) importers (not yet formally adopted as of May 2026); (4) landmark enforcement: Meta's 1.2 billion euro fine (May 2023) and the Dutch DPA's 290 million euro Uber fine (2024); (5) EDPB Guidelines 02/2024 on Article 48 GDPR (final version adopted June 5, 2025) on responding to third-country authority data requests; (6) UK adequacy decision renewal on December 19, 2025, valid until 2031. Previous review: 2026-03-28.

Sources and References

  1. The current EU SCCs were adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.(eur-lex.europa.eu).gov
  2. The CJEU ruled in Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems, Case C-311/18, ECLI:EU:C:2020:559, 16 July 2020 (Schrems II), upholding SCCs as a valid transfer mechanism in principle but requiring exporters to verify whether the importing country's legal framework(eur-lex.europa.eu).gov
  3. The EDPB Recommendations 01/2020 on supplementary measures (finalized June 2021) outline a six-step process for TIAs.(edpb.europa.eu).gov
  4. The Meta/Facebook 1.2 billion euro fine was issued by the Irish DPA following EDPB Binding Decision 1/2023 (13 April 2023). The DPA found Meta's transfers of Facebook user data to the US via SCCs lacked sufficient supplementary measures to compensate for US surveillance laws.(edpb.europa.eu).gov
  5. The Dutch DPA (Autoriteit Persoonsgegevens) imposed a 290 million euro fine on Uber for transfers of drivers' personal data to the US without a valid transfer mechanism. This is the third fine the Dutch DPA has imposed on Uber.(edpb.europa.eu).gov
  6. The EU General Court dismissed the Latombe annulment challenge to the EU-US Data Privacy Framework on 3 September 2025. Latombe filed an appeal to the CJEU on 31 October 2025. The appeal is pending.(noyb.eu)
  7. The UK Data (Use and Access) Act received Royal Assent on 19 June 2025. Schedule 7 of the Act amended the standard for international transfers from 'not undermined' to 'not materially lower' than UK GDPR protection (the 'data protection test'). The ICO published updated international transfers guida(ico.org.uk).gov
  8. The ICO plans to update the IDTA and Addendum in the course of 2026 to reflect DUAA amendments. Organizations should continue to use the current versions of the IDTA and Addendum until then.(ico.org.uk).gov
  9. The European Commission is in the process of developing new SCCs for transfers to controllers and processors outside the EEA whose processing is directly subject to GDPR under Article 3(2). Public consultation was planned for Q4 2024 with a draft expected for Q2 2025. As of May 2026, the Commission'(commission.europa.eu).gov
  10. The EDPB adopted final Guidelines 02/2024 on Article 48 GDPR (data transfers to third-country authorities) on 5 June 2025. The guidelines clarify that judgments or decisions from third-country authorities cannot automatically be recognized or enforced in the EU, and that organizations must assess ea(edpb.europa.eu).gov
  11. The existing 2021 SCCs are limited to transfers where the data importer's processing is NOT subject to the GDPR. They are unsuitable for the scenario where both exporter and importer are subject to the GDPR — because the clauses would partly duplicate and partly deviate from obligations that already(commission.europa.eu).gov
  12. The EDPB urged the European Commission to prepare new SCCs covering the scenario where both the data exporter and the data importer are subject to the GDPR, emphasizing that these SCCs should not replicate GDPR obligations but should focus on elements specifically related to the risks of the importe(edpb.europa.eu).gov
  13. UK ICO - Transfer Risk Assessments(ico.org.uk).gov
  14. UK Data Protection Act 2018(legislation.gov.uk).gov
  15. European Commission - SCCs for International Transfers(commission.europa.eu).gov
  16. EDPB: Binding Decision 1/2023 on Meta Platforms Ireland (Facebook transfers to US)(edpb.europa.eu)
Share: