Standard contractual clauses, usually abbreviated as SCCs, are contract texts issued by the European Commission. They serve one purpose: to allow personal data to be transferred to a country for which no adequacy decision exists. By signing them, the recipient contractually commits to safeguards equivalent to those of the GDPR. For companies working with providers outside the European area, they are the most important tool for lawful transfers.
The current version
The clauses in use today are based on a Commission implementing decision of June 2021. It replaced the older versions, which existing contracts could continue to use until the end of 2022. The new clauses are modular so they fit different constellations, and include a docking clause through which further parties can join later.
The four modules
Which module applies depends on the parties' roles. Module one governs transfers between two controllers, such as two companies each using data for their own purposes. Module two governs transfers from a controller to a processor — the most common case, for example when a company uses a cloud service. Module three covers onward transfers from a processor to a sub-processor. Module four covers the rarer case of a processor transferring data back to its controller. Several modules can be combined in one contract.
What may and may not be changed
The clauses must be adopted verbatim. Additions are allowed as long as they do not contradict the clauses or lower the level of protection. The annexes must be completed: they describe the parties, the data transferred, purposes and recipients, and the technical and organisational measures. In practice these annexes are often treated carelessly, even though they record the actual substance of the transfer.
The transfer impact assessment
In its 2020 Schrems II judgment, the Court of Justice of the EU made clear that a contract alone is not enough if the destination country's law undermines it — for example through broad access powers for public authorities. Anyone using standard contractual clauses must therefore assess whether the recipient can actually comply with them in the destination country. This is usually called a transfer impact assessment. If it reveals gaps, supplementary measures are needed, such as encryption where the recipient has no access to the keys. If the risk cannot be reduced sufficiently, the transfer must not take place.
Standard contractual clauses in Switzerland
Swiss data protection law likewise requires appropriate safeguards for transfers to countries without adequate protection. The Federal Data Protection and Information Commissioner has recognised the EU standard contractual clauses as a basis, provided they are adapted to Swiss circumstances. This includes taking the Swiss act into account as applicable law, naming the FDPIC as the competent authority and allowing data subjects to assert their rights in Switzerland as well. In practice this is done through a Swiss addendum to the EU clauses, so one contract covers both legal orders.
How they differ from a data processing agreement
Standard contractual clauses and data processing agreements are often confused. A data processing agreement governs how a provider may process data on your behalf and is needed even within the EU. Standard contractual clauses govern whether data may be transferred to a third country. Module two of the clauses does contain the essential content of a processing agreement, but many providers conclude both as one combined set of contracts. What matters is that both questions are answered in the end.
When you don't need them
Transfers to countries with an adequacy decision do not require standard contractual clauses. Data therefore flows from the EU to Switzerland and from Switzerland to the EU without them. For US providers certified under the relevant Data Privacy Framework, the certification is the basis. Many US providers nevertheless include standard contractual clauses in their contracts as a fallback in case the framework falls away.
The process in five steps
First, record all transfers to third countries, including sub-processors a provider uses itself. Second, determine the roles for each transfer and choose the right module. Third, complete the annexes concretely — which data, which purposes, which measures — rather than adopting generic wording. Fourth, carry out and document the transfer impact assessment, including supplementary measures where needed. Fifth, add the Swiss addendum if the revFADP also applies, and set a review date, for instance when a provider announces new sub-processors or the legal situation in the destination country changes.
This process is not a one-off project. Providers change data centres, new tools are added, frameworks change. Whoever maintains the overview of transfers can respond to each of these changes quickly.
Common mistakes in practice
Typical weaknesses are a wrongly chosen module, empty or generic annexes, a missing transfer impact assessment and sub-processors in third countries that nobody has recorded. Equally common is a missing Swiss addendum at companies subject to both the GDPR and the revFADP.
How we work with them
In data protection projects at Innopulse we check, per provider, where data is actually processed, whether an adequacy decision or certification applies and — where not — whether standard contractual clauses with the right module, completed annexes and the Swiss addendum are in place. We leave the legal assessment of contested transfers to a specialised law firm; our job is to make sure the facts for it are complete and orderly.
