The New EU Standard Contractual Clauses

After a period of public consultation and a joint opinion rendered by the EDPB and the EDPS, MyData-Trust is very happy to finally be able to discover the new Standard Contractual Clauses (SCCs). On June 4, the European Commission published the new SCCs. These clauses are “revised data transfer tools with stronger legal and privacy safeguards to enable companies to transfer Europeans’ data securely around the world.”[1] 

The goal was to avoid a potential “Schrems III”. 

SCCs 

The SCCs came into question after the EU Court of Justice asked privacy bodies to suspend and ban transfers made through SCCs outside the EU if data protection in other countries could not be guaranteed. The European Commission issued modernised SCCs under the GDPR for data transfers from controllers or processors in the EU/EEA to controllers or processors established outside the EU/EEA. These modernised SCCs will replace the three sets of SCCs that were adopted under the previous Data Protection Directive 95/46.  

The new SCCs are modular in nature to allow companies to address more than one type of transfer using the same framework and also add and remove parties in the future. In addition, new transfers “options” have been included, which will make it possible to cover some common types of data transfers for which there was no officially, compliant option in the past, such as exports by EU processors. As of December 27, 2022, the grace period for implementing the new SCCs ended, and all legacy clauses are now invalid.  

What should you now? 

The 18-month transition period for replacing legacy SCCs expired on December 27, 2022. As of today, organisations must use the modernised 2021 SCCs for any new or existing international data transfers outside the EU/EEA. 

In addition, all transfers relying on SCCs are subject to the obligations stemming from the Schrems II ruling. This includes conducting a Transfer Impact Assessment (TIA) to evaluate the laws and practices of the third country and to determine whether supplementary measures (technical, contractual, and organisational) are needed to ensure adequate protection.  

Since 2023, the EU–U.S. Data Privacy Framework has provided a new adequacy mechanism for transfers to certified U.S. entities. However, transfers to all other third countries must still rely on SCCs and appropriate safeguards under Article 46 GDPR. 

Supervisory authorities across the EU now routinely request: 

  • Written TIAs, including legal analysis of foreign surveillance laws; 
  • Descriptions of risk mitigation measures, including encryption or pseudonymisation; 
  • Documentation of internal transfer governance processes; 
  • Clear records showing that data subjects’ rights are preserved and actionable. 

Organisations failing to provide this documentation may be subject to investigation or enforcement action, especially in high-risk sectors such as health, finance, or cloud services. 

 Where to find the documents  

SCCs for international transfers 

SCCs for controllers and processors in the EU/EEA 

We can help you 

Our team is available to help you to identify what needs to be implemented and set the priorities. 

If you have any questions regarding the SCCs, the scope, the Data Protection Officer or Representative, the Competent Supervisory Authority or about Data Transfers, please contact us. MyData-Trust team will put all their efforts to support and sustain your activities involving personal data. 

In 2025, we support organisations through services tailored to today’s regulatory demands, including Transfer Impact Assessments (TIAs), technical documentation reviews, contractual clause updates, legal basis assessments for international transfers, and data flow mapping. 

Contact us to define a secure and scalable data transfer strategy adapted to your operations. 

[1] Reynders Speech 

[/vc_row]

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)