Skip to main content
Category: Data Transfers

Modular Standard Contractual Clauses

Also known as: Modular SCCs, Modular SCCs, New SCCs, 2021 SCCs
Simply put

Modular SCCs are a set of pre-approved contract terms published by the European Commission that organizations can use to lawfully transfer personal data outside the EU to countries without an adequacy decision. Rather than being separate contracts for each situation, they are built as a single set with interchangeable modules, so parties select the parts that fit their particular transfer scenario. This modular design also allows arrangements involving more than two parties.

Formal definition

The Modular SCCs refer to the standard contractual clauses adopted by the European Commission (published in June 2021) as a transfer tool for personal data to third countries lacking an adequacy decision. According to the Commission, this single set replaced three earlier sets of SCCs that had covered two transfer scenarios, consolidating them into one instrument with a modular structure spanning four transfer scenarios. Per the evidence, the four scenarios include controller-to-controller, controller-to-processor, and additionally safeguards for processor-to-controller and processor-to-processor transfers. Parties select and combine the applicable module(s) to match their processing relationship, and the modular architecture is intended to accommodate arrangements with more than two parties. Practitioners should note that use of SCCs generally requires accompanying transfer risk assessment and, where necessary, supplementary measures; transfer tools and adequacy frameworks evolve, so the current official text and any related guidance should be verified. This entry describes the EU SCCs; UK transfer arrangements are governed separately and are out of scope here.

Why it matters

Transfers of personal data from the EU to countries that lack an adequacy decision cannot generally proceed without an appropriate safeguard in place. Modular SCCs are one of the most widely used transfer tools because they are pre-approved by the European Commission, meaning organizations do not have to negotiate bespoke terms or seek individual regulatory authorization for each transfer. For businesses that rely on cross-border data flows, whether to affiliates, vendors, or cloud providers outside the EU, the SCCs provide a practical contractual basis to support such transfers.

The 2021 modular design matters because it consolidated three earlier sets of SCCs, which had covered two transfer scenarios, into a single instrument covering four scenarios. This consolidation reduced fragmentation and, per the Commission, extended coverage to relationships that the older clauses did not adequately address, including processor-to-controller and processor-to-processor transfers. The modular structure also accommodates arrangements involving more than two parties, which reflects the layered vendor and sub-processor chains common in modern data processing.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy teams are typically responsible for identifying which transfers require a safeguard, selecting the correct module for each relationship, and ensuring that a transfer risk assessment and any supplementary measures accompany the clauses. The modular structure means they must map each processing relationship accurately to avoid selecting the wrong scenario.
Legal and contracting teams
In-house counsel and commercial lawyers negotiate and incorporate the SCCs into vendor, intra-group, and customer agreements. Because the 2021 set now covers four scenarios, including processor-to-processor and processor-to-controller transfers, legal teams need to determine which module applies and how the clauses interact with existing data processing terms.
Compliance and vendor management functions
Teams managing third-party and sub-processor relationships use the SCCs to support transfers within complex processing chains. The modular design's ability to accommodate more than two parties is particularly relevant where multiple entities in different roles participate in a single arrangement.
Organizations relying on cross-border data flows
Any controller or processor transferring personal data from the EU to a third country without an adequacy decision may need the SCCs as a lawful transfer basis. Such organizations should treat the clauses as one part of a broader assessment rather than a standalone solution, and should verify the current official text given that transfer frameworks evolve.

Inside Modular SCCs

Modular Structure
The Standard Contractual Clauses adopted by the European Commission are designed in a modular format, allowing parties to select the module that reflects their specific transfer scenario rather than using a single fixed template.
Transfer Scenario Modules
The clauses are typically organized to address distinct relationships between the exporting and importing parties, generally covering controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers. Parties should select and complete the module corresponding to their actual roles.
General Clauses and Docking Option
The framework generally includes clauses applicable across modules, and commonly a mechanism allowing additional parties to accede to the clauses over time. Practitioners should verify the exact provisions against the current official text.
Annexes
The clauses are typically completed with annexes describing the parties, the details of the transfer (categories of data subjects and personal data, purposes, retention), and the technical and organisational security measures. These require case-specific completion.
Role in Transfer Compliance
Modular SCCs function as a transfer tool intended to provide appropriate safeguards for transfers of personal data to third countries. They are one mechanism among several and are generally used where no adequacy decision covers the transfer. Their sufficiency is subject to a transfer risk assessment and, where needed, supplementary measures.

Common questions

Answers to the questions practitioners most commonly ask about Modular SCCs.

Do the modular SCCs replace the need for any assessment before transferring personal data outside the EEA?
No. Executing the modular SCCs is generally one part of a lawful transfer, but it does not by itself remove the obligation to assess whether the clauses can be complied with in practice. Following the Schrems II line of case law, exporters are typically expected to evaluate the law and practice of the destination country and consider whether supplementary measures are needed. The SCCs are a transfer tool, not a standalone guarantee of compliance, and the outcome depends on the circumstances of each transfer.
Are the modular SCCs a single fixed contract that all parties sign in the same way?
No. The instrument is described as modular because it is designed to be configured to the specific transfer scenario rather than used as one uniform text. Parties generally select the module that reflects their respective roles in the transfer, and different relationships may call for different configurations. Treating the clauses as a single undifferentiated form risks selecting terms that do not match the actual roles of the parties, which should be assessed case by case.
How do parties determine which module applies to their transfer?
Module selection generally turns on the roles of the exporter and importer in the specific transfer, such as whether each party is acting as a controller or a processor. Parties should typically map their actual processing roles before choosing a module, because a mismatch between the selected module and the real-world relationship can undermine the intended coverage. Where roles are complex or layered, a role-by-role analysis of the data flow is advisable rather than assuming a default configuration.
Can the modular SCCs be combined with other contractual arrangements, such as a data processing agreement?
In many cases the clauses are used alongside other contractual documentation, and certain modules address controller-to-processor relationships that may overlap in subject matter with processing terms required under Article 28. Parties typically need to ensure that the different instruments are consistent and do not conflict, and that any required processing terms are properly addressed. The precise interaction should be confirmed against the current official text and the specific documents in use.
What should parties consider when completing the annexes or appendices to the clauses?
The clauses generally require the parties to specify details of the transfer, such as the categories of data, the purposes, and relevant technical and organisational measures. Completing these sections accurately is important because they define the scope of what is covered and inform any transfer assessment. Parties should treat these details as substantive rather than administrative, and keep them aligned with the actual processing, updating them if the transfer changes.
How should organisations handle onward transfers and additional parties over time?
Where data may be transferred onward or where further entities join, parties typically need to consider whether and how additional parties can be brought within the clauses and whether onward transfer conditions are met. This is often handled through the mechanisms provided in the clauses for adding parties and governing subsequent transfers. Because arrangements can evolve, organisations should periodically review whether their configuration still reflects the current data flows and verify requirements against the official text.

Common misconceptions

Signing SCCs alone is sufficient to make any international transfer lawful.
SCCs provide a set of contractual safeguards, but their use generally requires a case-by-case assessment of the destination country's laws and practices, and supplementary measures may be needed where the assessment identifies gaps. Adequacy of protection is context and risk dependent rather than guaranteed by execution of the clauses.
There is a single SCC template that applies to every transfer relationship.
The clauses are modular, and parties must select the module matching their actual roles (for example controller-to-processor versus controller-to-controller). Using the wrong module can misalign obligations with the parties' real relationship.
SCCs and Binding Corporate Rules are interchangeable, or SCCs are the same as a Data Processing Agreement.
SCCs are a distinct transfer tool; Binding Corporate Rules are a separate mechanism for intra-group transfers, and an Article 28 processor contract addresses the controller-processor relationship rather than serving as a transfer safeguard. Some SCC modules can incorporate processor-agreement content, but the instruments should not be treated as equivalent. Verify current requirements against the official text.

Best practices

Identify the actual roles of each party (controller or processor, importer or exporter) before selecting a module, and ensure the chosen module reflects the real-world data flow.
Complete the annexes accurately and specifically, detailing the parties, categories of data subjects and personal data, purposes, retention, and the technical and organisational security measures rather than leaving generic placeholders.
Conduct and document a transfer risk assessment of the destination jurisdiction, and adopt supplementary measures where the assessment indicates the SCCs alone may not ensure adequate protection.
Use the accession or docking mechanism, where available, to bring additional parties into the clauses in a controlled way, and keep records of who has acceded.
Confirm that any processor-related obligations are addressed appropriately, recognising that a transfer tool is distinct from an Article 28 processor contract even where content overlaps.
Verify the current official text and any relevant regulator guidance before relying on the clauses, since transfer tools, adequacy positions, and expectations around supplementary measures can evolve over time.