Modular Standard Contractual Clauses
Modular SCCs are a set of pre-approved contract terms published by the European Commission that organizations can use to lawfully transfer personal data outside the EU to countries without an adequacy decision. Rather than being separate contracts for each situation, they are built as a single set with interchangeable modules, so parties select the parts that fit their particular transfer scenario. This modular design also allows arrangements involving more than two parties.
The Modular SCCs refer to the standard contractual clauses adopted by the European Commission (published in June 2021) as a transfer tool for personal data to third countries lacking an adequacy decision. According to the Commission, this single set replaced three earlier sets of SCCs that had covered two transfer scenarios, consolidating them into one instrument with a modular structure spanning four transfer scenarios. Per the evidence, the four scenarios include controller-to-controller, controller-to-processor, and additionally safeguards for processor-to-controller and processor-to-processor transfers. Parties select and combine the applicable module(s) to match their processing relationship, and the modular architecture is intended to accommodate arrangements with more than two parties. Practitioners should note that use of SCCs generally requires accompanying transfer risk assessment and, where necessary, supplementary measures; transfer tools and adequacy frameworks evolve, so the current official text and any related guidance should be verified. This entry describes the EU SCCs; UK transfer arrangements are governed separately and are out of scope here.
Why it matters
Transfers of personal data from the EU to countries that lack an adequacy decision cannot generally proceed without an appropriate safeguard in place. Modular SCCs are one of the most widely used transfer tools because they are pre-approved by the European Commission, meaning organizations do not have to negotiate bespoke terms or seek individual regulatory authorization for each transfer. For businesses that rely on cross-border data flows, whether to affiliates, vendors, or cloud providers outside the EU, the SCCs provide a practical contractual basis to support such transfers.
The 2021 modular design matters because it consolidated three earlier sets of SCCs, which had covered two transfer scenarios, into a single instrument covering four scenarios. This consolidation reduced fragmentation and, per the Commission, extended coverage to relationships that the older clauses did not adequately address, including processor-to-controller and processor-to-processor transfers. The modular structure also accommodates arrangements involving more than two parties, which reflects the layered vendor and sub-processor chains common in modern data processing.
Who it's relevant to
Inside Modular SCCs
Common questions
Answers to the questions practitioners most commonly ask about Modular SCCs.