Skip to content
teamed.

Glossary

Standard Contractual Clauses

Standard Contractual Clauses (SCCs) are pre-approved contract templates issued by the European Commission that give organisations a lawful basis for transferring personal data, including employee records, from the EU to a country that lacks an adequacy decision.

Reviewed by Teamed's in-house employment-law team·Last updated 28 July 2026

What is Standard Contractual Clauses?

Standard Contractual Clauses (SCCs) are model data protection terms published by the European Commission. Signing them commits the exporter and importer of personal data to protect it to a European standard, and they serve as a recognised legal mechanism for moving data out of the EU when the destination country has no adequacy decision.

They matter because the GDPR restricts transfers of personal data outside the European Economic Area. Where a country has not been judged to offer equivalent protection, an organisation needs an approved safeguard, and SCCs are the most widely used one. In employment, they commonly cover payroll, HR and benefits data flowing to a parent company or a service provider abroad.

The current SCCs date from 2021 and replaced older versions. Simply signing them is no longer enough on its own: organisations are also expected to assess the destination country's laws and add extra measures where needed, so the data really is protected in practice.

When do you need Standard Contractual Clauses?

When personal data leaves the European Economic Area for a country without an adequacy decision, and no other safeguard applies. Sending employee or customer data to a group company, cloud host or service provider in such a country typically calls for SCCs. If the destination already has adequacy, they are usually not required.

This makes SCCs a routine part of setting up any vendor or group data flow that reaches a non-adequate country.

What changed with the 2021 SCCs?

The 2021 clauses modernised and consolidated the older templates into a single, modular set covering more transfer scenarios, including processor-to-processor flows. They also reflected the Schrems II ruling by expecting parties to assess the destination country's surveillance laws. Organisations relying on the pre-2021 versions had to migrate to the new clauses.

Are SCCs enough on their own?

Not always. Since the Schrems II ruling, signing the clauses is only the starting point. Parties are expected to run a transfer impact assessment, checking whether the destination country's laws could undermine the protection, and to add supplementary measures, such as encryption, where the assessment shows a gap.

Key facts

2021 SCCs and migration deadline
The current Standard Contractual Clauses were adopted by the European Commission in June 2021 (Implementing Decision (EU) 2021/914). Contracts on the old clauses had to migrate to the 2021 version by 27 December 2022.Source: EUR-Lex, European Commission· verified 2026-07-28

Frequently asked questions

  • What are Standard Contractual Clauses in simple terms?
    They are ready-made contract terms, approved by the European Commission, that two organisations sign to allow personal data to move from the EU to a country without an adequacy decision. By signing, both sides promise to protect the data to a European standard, wherever it ends up being processed.
  • Do I still need SCCs if the recipient is in an adequate country?
    Usually not. If the European Commission has issued an adequacy decision for the destination country, data can flow there without SCCs, much as it would within the EU. SCCs are the fallback for the many countries that do not hold an adequacy decision.
  • What is a transfer impact assessment?
    It is a check, expected since the Schrems II ruling, of whether the destination country's laws, especially around government access to data, could weaken the protection the SCCs promise. If a risk is found, the parties add supplementary measures, such as strong encryption, before relying on the clauses.
  • How do SCCs relate to a data processing agreement?
    They serve different purposes and often sit side by side. A data processing agreement governs how a processor handles data on a controller's behalf. SCCs specifically legitimise moving that data across a border to a non-adequate country. A single vendor relationship may need both documents in place.

Related terms

Note

This is general information, not legal advice. Statutory rules vary by country and change over time.

Glossary

Have a global hiring question?

Ask a real person, or run the numbers yourself with the free calculators.

Talk to us about compliant data transfers

Last verified 2026-07-28