EU Standard Contractual Clauses and Transfer Impact Assessment
The EU standard contractual clauses (SCCs) as an appropriate safeguard for transfers to third countries: the four modules, the constellations, the delegation model and how the clauses are concluded. Plus the mandatory transfer impact assessment (TIA) in three stages, with risk-based considerations, periodic review and the treatment of the chain of processors.
The EU standard contractual clauses (SCCs) are, in practice, the most important instrument for establishing an adequate level of protection for a transfer to an unsafe third country (appropriate safeguard under Article 46 GDPR). They are concluded between the data exporter in the EU and the data importer in the third country. Since the CJEU's judgment in Schrems II, concluding the clauses alone is not sufficient: a transfer impact assessment (TIA) must always be added.
Key takeaways
- The basis is the European Commission's 2021 standard contractual clauses (Implementing Decision (EU) 2021/914). Earlier versions have been invalid since 27 December 2022.
- The clauses cover four modules for different constellations and may not be amended in substance.
- In addition to concluding the clauses, a transfer impact assessment must always be carried out: the documented examination of whether the law and practice in the destination country prevent compliance with the clauses.
- The TIA proceeds in three stages: problematic legal provisions, their application in practice, supplementary measures.
- The TIA must be reviewed periodically, as a rule at the latest after 24 months, and whenever there is specific cause.
1. Overview of the EU standard contractual clauses
The standard contractual clauses are a model contract provided by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021). They contractually align the data importer with the level of protection under the GDPR and oblige both parties to follow a defined approach to access requests from public authorities in the third country.
The model contract may not be amended in substance. What has to be completed are the annexes containing the details of the parties, the categories of data subjects and of transferred data, the purposes of the processing, the technical and organizational measures and the sub-processors. In addition, a number of optional provisions and choices have to be settled within the clauses.
Where the data importer in the third country concludes the clauses as a processor, the standard contractual clauses already contain the provisions on processing on behalf of a controller required by Article 28 GDPR. A separate data processing agreement is then no longer necessary.
The standard contractual clauses for transfers to third countries (Implementing Decision (EU) 2021/914) are not to be confused with the model contract for processing on behalf of a controller under Article 28 GDPR (Implementing Decision (EU) 2021/915), which was adopted on the same day. In the case of a transfer to a processor in a third country under Module 2, the content required for processing on behalf of a controller is already included in the standard contractual clauses; an additional data processing agreement would then be superfluous.
2. Constellations and modules
The standard contractual clauses combine four case constellations, referred to as modules, in a single set of contractual terms. What is decisive are the roles of the exporter and the importer.
| Module | Data exporter (EU) | Data importer (third country) |
|---|---|---|
| Module 1 | Controller | Controller |
| Module 2 | Controller | Processor |
| Module 3 | Processor | Sub-processor |
| Module 4 | Processor | Controller |
Whether the importer is a controller or a processor depends on who determines the purposes and means of the processing.
One constellation of considerable practical importance is the delegation model: where a processor in the EU engages a sub-processor in a third country, the EU processor can conclude the standard contractual clauses under Module 3 with that sub-processor. The controller then only needs a data processing agreement with the EU processor and does not itself conclude the clauses with the recipient in the third country. The controller nevertheless remains responsible under data protection law and must ensure that the requirements for the transfer to a third country, including the TIA, are met (see section 5).
Where the data importer in the third country is itself subject to the GDPR (Article 3 GDPR), for example a parent company of a corporate group that targets the EU market, the current standard contractual clauses do not fully fit, in the view of the European Commission. The Commission is preparing supplementary clauses for such cases; until they are available, the adequacy decision (for certified US recipients) or the existing clauses may be considered.
3. Concluding the standard contractual clauses
A number of practical rules apply to the conclusion of the clauses:
- The clauses can be agreed as a separate contract, as an annex to the service agreement or as part of the general terms and conditions.
- Conclusion in electronic form is sufficient; the clauses do not impose any particular formal requirements.
- The clauses can be agreed by reference to the European Commission's implementing decision, without reproducing the full text.
- The service agreement must not contain provisions that contradict the clauses, such as an exclusion of liability for breaches of the standard contractual clauses.
Where the clauses are merely incorporated by reference, the incorporation should expressly specify the applicable module, the optional clauses and the annexes.
Before this wording is adopted, every option must be adapted to the specific case; the square brackets must be replaced by the actual details.
Typical pitfalls when concluding the clauses
- The list of sub-processors is incomplete (missing hosting providers or group companies) or imprecise (only the provider's name, without the specific entity).
- Key points are not set out in writing, such as the restriction to data centers in the EU or the exclusion of onward exports to third countries.
- The main contract contains an exclusion of liability that covers breaches of the standard contractual clauses.
- Standard contractual clauses are concluded even though the recipient is certified under the Data Privacy Framework and no additional safeguard would therefore be necessary.
4. Transfer Impact Assessment (TIA)
4.1 Background and obligation
In Schrems II, the CJEU held that concluding the standard contractual clauses alone is not sufficient. The data exporter must additionally assess whether the law and practices in the destination country prevent compliance with the clauses, in particular through disproportionate access rights of public authorities.
The TIA is this case-by-case assessment. It must be documented; reference can be made to further materials such as publicly available documents or legal opinions. Transfers of the same kind can be combined in a single assessment, and for individual assessment questions reference can be made to other assessments already carried out. Under the standard contractual clauses, the data recipient in the third country is obliged to assist with the assessment.
The following questions are particularly suitable for obtaining the necessary information from the data importer:
- Has the data importer received requests from authorities for access to or disclosure of the data concerned to date, and how were they answered?
- Does the data importer's legal representative confirm that there is no voluntary cooperation with security authorities regarding the release of the data?
- How are the data encrypted, both in transit and at rest?
- Do onward transfers to sub-processors or third parties take place?
- What technical, organizational and contractual protective measures exist beyond the standard contractual clauses?
Answers given by the data importer should, where possible, be confirmed by its legal representative.
4.2 Stage 1: Problematic legal provisions in the destination country
It must be assessed whether the destination country has legal provisions or practices that allow public authorities disproportionate access to the transferred data and thereby impair the effectiveness of the clauses. Provisions are problematic if they do not respect the essence of the fundamental rights of the EU Charter of Fundamental Rights or go beyond what is necessary and proportionate in a democratic society (measured against the objectives listed in Article 23(1) GDPR, such as national security or criminal prosecution).
What is decisive is whether the provisions are relevant to the specific transfer, that is, whether they apply to this type of data and this sector of the economy. The factors to be taken into account include the purposes of the processing, the type of entities involved, the sector, the categories of data, the location of storage or remote access, the data format and possible onward transfers. This stage requires an assessment of the legal situation in the third country. Possible sources are information provided by the data importer as well as public, relevant, objective, reliable and verifiable sources.
4.3 Stage 2: Application in practice
Where problematic legal provisions exist, the second stage is to assess whether they are applied in practice to the data actually transferred. If it can be demonstrated that the provisions are not applied in practice, the level of protection may still be ensured.
The evidentiary requirements are high: for the assumption that problematic legal provisions are not applied, the European Data Protection Board requires public, relevant, objective, reliable and verifiable sources. The Board does not accept a general balancing of risks based solely on the parties' case-specific considerations. Supervisory authorities take a critical view of this risk-based approach, so that relying on it alone entails a legal risk.
4.4 Stage 3: Supplementary measures
Where problematic legal provisions exist and their application cannot be ruled out, supplementary measures must be defined. They must specifically counteract the problematic provisions and can be contractual, organizational or technical in nature.
Mere transport encryption and encryption of stored data are not sufficient where the data recipient can access the data in plain text and, because of problematic provisions, must grant access to public authorities. This concerns cloud services in particular, as well as maintenance and support access. What is then required is an approach that gives the data importer no access to the plain-text data and no access to the decryption keys (zero-knowledge or end-to-end encryption), or pseudonymization in which the additional information needed to attribute the data is not accessible to the recipient. Such measures often cannot be implemented in practice, because the importer needs access to plain-text data in order to provide the service; a residual risk then regularly remains, and the company must decide whether to accept it.
4.5 Risk-based considerations
At the second stage and when assessing the residual risk, various considerations are relied on in practice. They require weighing in the individual case and, in some instances, follow-up questions to the data importer. The mere presence of individual points does not automatically mean that problematic legal provisions are not applied in practice.
- Location of storage: Are the data physically located within the EU, the EEA or a safe third country?
- Sensitivity and volume of data: Are special categories of data, communications data, location data or financial data transferred, or only basic contact and user data?
- Format: Does the format make automated access more difficult (unstructured data, paper form, pseudonymized or encrypted data)?
- Frequency and duration: Is this a one-off, short-term transfer rather than a continuous one?
- Relevance for public authorities: Are the data irrelevant to national security, criminal prosecution or similar areas, making access unlikely?
- Previous access requests: Have there been requests from public authorities, and how were they answered?
- Contractual guarantees and protective measures: Are there assurances or technical and organizational measures beyond the clauses that reduce the risk of access?
- Processing chain: Are there onward transfers to further recipients in the third country?
- Alternatives: Is there an alternative that does not involve a transfer to an unsafe third country?
Special categories of data that are transferred must be handled with particular care (see Special categories of personal data).
For transfers to the United States to a recipient that is not certified under the Data Privacy Framework, the data protection guarantees introduced with the framework can nevertheless be taken into account as a positive factor. They are based on an Executive Order of 7 October 2022 (including a redress mechanism and restricted access by US security authorities) and apply irrespective of whether the individual recipient is certified.
4.6 Periodic review
The TIA is not a one-off exercise. It must be reviewed periodically and whenever there is specific cause, for example where the legal situation or the access practice of public authorities in the destination country changes, as a rule at the latest after 24 months. The date of the next review must be documented.
If the company has reason to believe that the data recipient is no longer able to comply with its obligations under the clauses, or if the recipient breaches them, remedial measures must be considered. If no such measures are available, the transfer must be suspended. In line with the clauses, a right of termination exists in these cases.
5. The TIA in the chain of processors
Where the company engages a processor in the EU that transfers the data to a sub-processor in a third country (delegation model, see section 2), the company, as controller, remains responsible for the case-by-case assessment of that transfer as well. The scope of the assessment can be determined according to risk; a systematic submission and review of all contracts between the processor and its sub-processors is not required. The company can rely on information provided by the processor and build on it; the TIA prepared by the processor can be adopted or supplemented.
As a rule, the company carries out the case-by-case assessment itself. Where that is not possible, approaches involving greater risk may be considered:
- Obligation to prepare and hand over the TIA, combined with a plausibility check: The EU processor is contractually obliged to carry out a TIA and to hand it over. The company then at least performs a plausibility check, for example whether the legal situation in the destination country was assessed and whether the TIA does more than merely repeat the security concept.
- Obligation combined with an indemnity: If the processor is not willing to hand over the TIA, this indicates an increased risk that should be accepted only where few and non-sensitive data are involved. Additional contractual assurances are then called for, such as warranties that a positive TIA exists, together with assumptions of liability and indemnities.
If the processor does not hand over its TIA, the company can comply with its accountability obligation only to a limited extent. It is possible that no full TIA exists at all. This approach should remain the exception.
Article 46 GDPR
Transfers subject to appropriate safeguards.
CJEU, Schrems II (C-311/18)
Basis of the TIA obligation: Privacy Shield invalid, standard contractual clauses only with an additional assessment.
EDPB Recommendations 01/2020
Measures that supplement transfer tools (TIA methodology, use cases, sources).
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Derogations under Article 49 GDPR
When personal data may be transferred to an unsafe third country without appropriate safeguards: consent, performance of a contract, legal claims, public interest, vital interests and registers under Article 49 GDPR, as well as the catch-all ground of compelling legitimate interests. Strict interpretation, limitation to occasional transfers, documentation and transparency obligations.
EU-US Data Privacy Framework (DPF)
The adequacy decision for the United States applies only to recipients certified under the EU-US Data Privacy Framework. How the certification is verified, what consequences it has, why no transfer impact assessment is required and how the transfer can be safeguarded contractually.