Skip to main content
Category: Data Transfers

Commission Implementing Decision (EU) 2021/914

Also known as: Implementing Decision 2021/914, 2021 Standard Contractual Clauses, New SCCs, EU SCCs (2021)
Simply put

Commission Implementing Decision (EU) 2021/914, adopted by the European Commission on 4 June 2021, sets out standard contractual clauses (SCCs) that organizations can use as a contract-based safeguard when transferring personal data to countries outside the EU. These pre-approved clauses are one of the tools intended to help ensure that transferred data continues to receive an appropriate level of protection. Whether they are sufficient in a given case generally depends on a broader assessment of the circumstances of the transfer.

Formal definition

Commission Implementing Decision (EU) 2021/914 of 4 June 2021 is the instrument by which the European Commission adopted a modernized set of standard contractual clauses for the transfer of personal data to third countries. As a Commission-approved transfer tool, the SCCs provide a contractual mechanism that parties may rely on as an appropriate safeguard for cross-border transfers of personal data. In practice, use of these clauses is typically accompanied by a case-by-case assessment of the transfer and, where required, supplementary measures; the adequacy of the SCCs in a specific transfer is context-dependent and subject to assessment. Note that transfer mechanisms, adequacy decisions, and related guidance evolve over time, and practitioners should verify the current official text and applicable regulatory guidance. The precise GDPR article references, transition timelines, and module structure of the clauses are not established by the evidence provided here and should be confirmed against the official Decision. This entry concerns the EU instrument; the position under the UK GDPR is governed by separate UK arrangements and is out of scope of this Decision.

Why it matters

Transfers of personal data to countries outside the EU are a routine feature of modern operations, from cloud hosting to intra-group support functions, yet such transfers are only permitted where an appropriate safeguard or other lawful basis for transfer is in place. Commission Implementing Decision (EU) 2021/914 matters because it provides one of the principal contract-based tools organizations can use to structure these transfers, offering a set of clauses that have been pre-approved by the European Commission rather than requiring parties to negotiate bespoke protections from scratch.

Because these clauses are a recognized transfer tool, they are widely embedded in commercial and intra-group arrangements involving third-country recipients. However, their presence in a contract does not, on its own, guarantee that a given transfer is adequately protected. In most cases, reliance on the clauses is expected to be accompanied by an assessment of the circumstances of the specific transfer and, where necessary, additional measures. Treating the clauses as a self-executing compliance solution, rather than as one component of a broader assessment, is a common source of risk.

The area is also one that evolves. Transfer mechanisms, adequacy decisions, and associated regulatory guidance change over time, and the position under the UK GDPR is governed by separate UK arrangements that fall outside this Decision. Practitioners should therefore verify the current official text and applicable guidance rather than relying on a fixed snapshot, and should confirm article references, module structure, and any transition timelines against the official Decision itself.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy teams responsible for mapping and governing international data flows will encounter these clauses as a core transfer tool. They should treat incorporation of the clauses as one element of a broader transfer assessment rather than a standalone solution, and should keep track of evolving guidance and the current official text.
Commercial and technology lawyers
Lawyers drafting or reviewing contracts with recipients located outside the EU will need to understand where and how the clauses fit into an agreement, and should confirm article references, module structure, and any timelines against the official Decision rather than relying on summaries.
Compliance leads in organizations transferring data to third countries
Those overseeing compliance programs that involve cloud hosting, intra-group support, or vendor arrangements outside the EU should recognize that the clauses provide a contractual safeguard whose adequacy is context-dependent and, in most cases, requires an assessment of the specific transfer and potentially supplementary measures.
Organizations operating under both EU and UK regimes
Businesses subject to both the EU GDPR and UK GDPR should note that this Decision concerns the EU instrument; the position under the UK GDPR is governed by separate UK arrangements and is out of scope of this Decision, so parallel mechanisms may need to be considered.

Inside Commission Implementing Decision (EU) 2021/914

Standard Contractual Clauses (SCCs)
This Commission Implementing Decision adopted a set of standard contractual clauses that serve as a transfer tool for personal data to third countries under the GDPR. They provide a set of pre-approved contractual safeguards that parties can incorporate to help meet the requirements for transfers to countries not covered by an adequacy decision.
Modular structure
The clauses are generally organized in a modular format intended to address different transfer scenarios, such as controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller relationships. Practitioners select and complete the module corresponding to their actual roles; readers should verify the specific modules and their wording against the current official text.
Transfer tool, not adequacy
The clauses function as an appropriate safeguard for transfers rather than as an adequacy decision. Their availability and adequacy for a given transfer are subject to assessment of the circumstances of the transfer, including the legal framework of the destination country.
Supplementary measures context
Use of these clauses generally sits alongside a case-by-case assessment of whether supplementary measures (technical, organizational, or contractual) are needed to ensure a level of protection essentially equivalent to that within the EU. Transfer tools and supplementary measures evolve, so this position should be treated as context-dependent.
Relationship to controller/processor obligations
Certain modules of the clauses can address matters that overlap with processing arrangements, but the clauses as a transfer tool should not be conflated with a Data Processing Agreement under Article 28; whether a single instrument satisfies both functions depends on how it is drafted and on the applicable requirements.

Common questions

Answers to the questions practitioners most commonly ask about Commission Implementing Decision (EU) 2021/914.

Do the Standard Contractual Clauses adopted under this Decision automatically make an international transfer lawful on their own?
No. The SCCs are a transfer tool under the GDPR's Chapter V framework, but adopting them does not, by itself, guarantee that a transfer is lawful. Following the case law that led to the 2021 clauses, the data exporter and importer are generally expected to assess the circumstances of the transfer, including the legal regime in the destination country, and to consider whether supplementary measures are needed to ensure a level of protection essentially equivalent to that within the EEA. The SCCs also do not replace the need for a valid Article 6 legal basis for the underlying processing. You should verify the current requirements against official EDPB guidance and the operative text.
Are these Standard Contractual Clauses the same thing as a Data Processing Agreement under Article 28?
Not exactly, although they overlap. The Decision provides SCCs primarily as a transfer mechanism for personal data leaving the EEA to third countries lacking an adequacy decision. Separately, Article 28 requires a controller-processor contract (often called a DPA) governing processing regardless of where it occurs. The 2021 SCCs include a module intended to satisfy certain Article 28 requirements in the transfer context, but relying on that module does not automatically mean every Article 28 obligation is met for purely domestic or intra-EEA processing. You should treat the transfer function and the Article 28 controller-processor function as distinct and confirm which instrument each arrangement needs.
How do I select the correct module within the Standard Contractual Clauses?
The Decision sets out a modular structure addressing different transfer relationships, generally distinguishing scenarios such as controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. In most cases you first characterise the roles of the exporting and importing parties for the specific data flow, then apply the module matching that relationship, completing the relevant annexes. Because a single commercial arrangement can involve more than one relationship, more than one module may be relevant. Confirm the current module descriptions against the operative text of the Decision.
What information typically needs to be completed in the annexes?
The clauses generally require the parties to specify details of the transfer in supporting annexes, which typically cover matters such as the identities and roles of the parties, the categories of data subjects and personal data, the purposes and nature of the processing, retention periods, and technical and organisational security measures. Where a processor is involved, information about sub-processors is generally addressed. Accurate and complete annexes are important because they define the scope of the commitments. Check the exact annex requirements against the current text before finalising.
How should the SCCs interact with a transfer risk assessment and supplementary measures?
In most cases the SCCs are used alongside, rather than instead of, an assessment of the transfer. Following the case law underpinning the 2021 clauses, exporters are generally expected to evaluate whether the law and practice of the destination country could undermine the protection the clauses promise, and to consider supplementary technical, contractual, or organisational measures where a gap is identified. The clauses themselves contain undertakings relevant to this analysis. The specifics of what a defensible assessment requires can evolve and may vary in emphasis between regulators, so consult current EDPB guidance.
Can I amend the wording of the Standard Contractual Clauses to fit my contract?
Generally the protective effect of the SCCs depends on using them without changes that would contradict or dilute the clauses or undermine the rights of data subjects. Parties typically may complete the annexes, select the applicable modules and options, and add other commercial terms provided those additions do not conflict with the clauses. Materially altering the core wording generally risks invalidating reliance on the mechanism. Verify the amendment constraints against the operative text of the Decision, as this is a point where careful reading matters.

Common misconceptions

Signing these SCCs makes any international transfer automatically lawful and fully compliant.
The clauses are a transfer tool that provides safeguards, but their effectiveness is subject to assessment of the specific transfer, including the destination country's legal framework and whether supplementary measures are needed. They do not, on their own, guarantee compliance in every case.
These EU SCCs apply directly and identically to transfers under the UK regime.
This is an EU Commission instrument. The UK operates its own regime with its own transfer mechanisms, and the position can diverge. Practitioners should verify which instrument is required for transfers involving the UK against the current official texts.
These SCCs are the same thing as a Data Processing Agreement and cover all Article 28 requirements by default.
The clauses are primarily a transfer safeguard and should not be conflated with an Article 28 Data Processing Agreement. Whether they also address processor obligations depends on the module used and the drafting; the two functions are distinct.

Best practices

Identify the actual roles of each party (controller or processor) before selecting a module, and complete the module that matches the real-world processing relationship.
Do not treat the clauses as a standalone guarantee of lawfulness; conduct and document a case-by-case assessment of the transfer, including the destination country's legal framework.
Assess whether supplementary technical, organizational, or contractual measures are needed, and treat that assessment as subject to change as guidance and transfer tools evolve.
Clarify whether a separate Article 28 Data Processing Agreement is still required, since these clauses as a transfer tool should not be assumed to cover all processor obligations.
Confirm which instrument applies for transfers involving the UK or other jurisdictions, given that regimes can diverge from the EU position.
Verify the current wording, modules, and any amendments against the official published text rather than relying on a prior snapshot, as transfer mechanisms are updated over time.