Skip to content
← All terms

Glossary · Privacy & regulation

SCCs (standard contractual clauses)

Standard contractual clauses (SCCs) are European Commission-approved contract templates that legalize personal-data transfers from the EU/EEA to countries without an adequacy decision by extending GDPR-equivalent protections.

GDPR restricts moving personal data outside the EU/EEA unless the destination offers an adequate level of protection. Where the European Commission hasn’t issued an adequacy decision for that country, organizations need an alternative safeguard, and SCCs are the most widely used one: a standardized contract, published by the Commission (the current set dates to June 2021), that the exporting and importing parties sign to bind the importer to GDPR-equivalent obligations regardless of local law.

The 2021 SCCs use a modular structure covering four transfer scenarios — controller to controller, controller to processor, processor to processor, and processor to controller — so one template set fits most real-world data flows. Since the Schrems II ruling, using SCCs alone isn’t automatically sufficient: exporters are expected to conduct a transfer impact assessment considering whether the importing country’s government surveillance laws could override the contractual protections, and to layer on supplementary technical measures (such as encryption the recipient cannot break) where warranted.

SCCs are one of several transfer mechanisms alongside adequacy decisions and certified frameworks like the EU-US Data Privacy Framework — organizations pick whichever applies to a given transfer, and a DPA will often reference SCCs by annex when the processor sits outside an adequate jurisdiction.

See also

Related terms