Standard Contractual Clauses
Definition
Standard Contractual Clauses
Standard contractual clauses are model terms published by a regulator that, when adopted unchanged, provide a lawful safeguard for transferring personal data to another country. The wording is fixed — the parties fill in annexes rather than negotiate the body itself.
That fixed quality is the point — a safeguard that each buyer redrafted would provide no consistency, so the approved text is taken as it stands.
Modern versions are modular. Separate modules cover controller to controller, controller to processor, processor to processor and processor to controller transfers.
Adoption alone is rarely sufficient. Most regulators expect a documented assessment of the destination country to sit alongside the signed clauses.
Key takeaways
- The operative text cannot be amended, only completed through its annexes.
- Modules match the roles of the exporter and importer in the particular transfer.
- A destination assessment is normally required in addition to signing.
- The United Kingdom uses its own instrument and an addendum to the European version.
How it works
The parties select the module matching their roles, complete the annexes describing the data, the purposes and the technical measures, and sign. The operative clauses themselves stay untouched.
The legal basis is explicit. Transfers may rely on “standard data protection clauses specified in regulations” made by the relevant authority and in force at the time of the transfer.
| Component | What it contains | Who completes it |
|---|---|---|
| Operative clauses | Fixed obligations and rights | Nobody; adopted as published |
| Module selection | Controller or processor roles | Both parties jointly |
| Annex on the transfer | Data categories, purposes, retention | The exporter, in detail |
| Annex on measures | Technical and organisational controls | The importer, specifically |
| Destination assessment | Local law and practice review | The exporter, documented |
The measures annex is where most agreements are weak — generic statements about encryption satisfy nobody, and a regulator reading the annex should be able to picture the actual control.
The European versions were rebuilt in 2021. The Commission “issued modernised standard contractual clauses” on 4 June 2021, replacing three older sets adopted under the previous directive.
The United Kingdom diverged after leaving the European Union. Its regulator publishes guidance on the safeguards permitted, “including the UK IDTA, Addendum and UK BCRs”, which are not identical to the European instruments.
Incorporation matters as much as signature. The clauses should be attached as a schedule and expressly incorporated by the main agreement, rather than referenced in a recital that nobody updates when the service changes.
Examples
Standard clauses appear in almost every offshore outsourcing contract, usually as a schedule nobody reads. The four cases below show the annexes deciding the outcome.
A European buyer signs the controller-to-processor module with an offshore provider. The data processing agreement incorporates the clauses as a schedule, with annexes completed per service.
A provider passes work to its own supplier and uses the processor-to-processor module. The sub-processor clause requires the same terms to flow down, so the chain stays intact.
A buyer completes the measures annex with one sentence about encryption. A regulator reviewing an incident finds the annex uninformative, and the buyer bears the consequence.
A UK buyer signs European clauses without the addendum. The transfer lacks a valid safeguard under UK law, and the paperwork has to be redone.
Related terms
Several instruments permit international transfers, and they are not interchangeable. The entries below separate the off-the-shelf contract from the group scheme and from the surrounding regime.
- GDPR: the regulation that creates the safeguard mechanism these clauses implement.
- GDPR outsourcing: how the regime applies specifically to outsourced delivery.
- Right to audit clause: the verification right the clauses themselves already contain in part.
- Master services agreement: the commercial contract the privacy schedule sits beneath.
- Offshore outsourcing: the delivery model that makes the clauses necessary in the first place.
FAQ
Can the clauses be edited?
No. The operative text must be adopted as published, or the safeguard fails. Commercial terms can be added separately provided they do not contradict it.
Which module applies to outsourcing?
Usually controller to processor, where the buyer decides purposes and the provider acts on instructions. Provider-to-supplier flows use the processor-to-processor module.
Are the clauses enough on their own?
Generally not. A documented assessment of the destination country, and supplementary measures where needed, are expected alongside the signature.
Do UK transfers use the same document?
No. The United Kingdom has its own transfer agreement and an addendum that adapts the European version, so the correct instrument depends on the exporting jurisdiction.
What goes in the technical measures annex?
Specific controls: encryption in transit and at rest, access management, logging, retention and deletion practice. Generic assurances are treated as no answer at all.
Do the clauses need updating over time?
Yes. Annexes should be revised whenever the data, the purposes or the sub-processor chain changes materially.
Compare providers on their transfer paperwork in the Outsource Accelerator directory.







Independent




