Legal

Standard Contractual Clauses 2021: modules, TIA and how to use them

The 2021 Standard Contractual Clauses are the most common contractual tool for sending personal data from the EEA to a third country. This page explains how to pick a module and what the clauses require, based on Decision (EU) 2021/914 and the Commission's Q&A.

Ask your question

Free account required

Each question stands alone · 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

Four modules for four transfer scenarios

The earlier clauses only covered controller to controller and controller to processor transfers. The modernised SCCs cover Controller to Controller (Module 1), Controller to Processor (Module 2), Processor to Processor (Module 3) and Processor to Controller (Module 4).

The parties keep the general clauses and those of the relevant module, and the Q&A says that modules and options that do not apply should be deleted. The text itself may not be altered beyond choosing modules and options, filling in square brackets and completing the annexes; otherwise the clauses can no longer be used as a transfer basis unless approved by a national authority as ad hoc clauses.

The optional docking clause (Clause 7) lets new parties join the contract later, for example a sub-processor adhering under Module 3.

Transfer impact assessment and government access

In line with the Schrems II judgment, Clause 14 requires the parties to assess, before concluding the SCCs, whether the laws and practices of the destination country could prevent the importer from complying with the clauses. The Q&A calls this a "transfer impact assessment".

The assessment may draw on reliable information on how the law is applied in practice, the existence or absence of requests in the same sector and, under strict conditions, documented practical experience.

Under Clause 15.1, the importer must promptly notify the exporter, and where possible the individuals concerned, if it receives a legally binding request from a public authority to disclose the transferred data.

Frequently asked questions

When were the old SCCs repealed?

Decisions 2001/497/EC and 2010/87/EU were repealed with effect from 27 September 2021. For an additional 15 months, contracts concluded before that date could keep relying on them, provided the processing remained unchanged and appropriate safeguards were ensured.

Which law governs the SCCs?

For Modules 1, 2 and 3 it must be the law of an EU Member State or EEA country; for Module 4 it may be the law of a non-EEA country. In all cases the chosen law must allow third-party beneficiary rights for data subjects.

Can the SCCs be used with an importer already subject to the GDPR?

No. The Commission's Q&A answers that these SCCs cannot be used for transfers to controllers or processors whose processing is directly subject to the GDPR, referring to Article 1 of Decision (EU) 2021/914.

Does Module 4 always require a transfer impact assessment?

Not when an EEA processor returns data it received from its non-EEA controller to that controller. The Q&A explains that Section III contains a specific exception for this case, so there is no need to carry out a transfer impact assessment (Clause 14) or to comply with the obligations on access by public authorities (Clause 15).

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-gdpr-official-texts-data-transfers": {
      "url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.