Standard Contractual Clauses 2021: modules, TIA and how to use them
The 2021 Standard Contractual Clauses are the most common contractual tool for sending personal data from the EEA to a third country. This page explains how to pick a module and what the clauses require, based on Decision (EU) 2021/914 and the Commission's Q&A.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
Four modules for four transfer scenarios
The earlier clauses only covered controller to controller and controller to processor transfers. The modernised SCCs cover Controller to Controller (Module 1), Controller to Processor (Module 2), Processor to Processor (Module 3) and Processor to Controller (Module 4).
The parties keep the general clauses and those of the relevant module, and the Q&A says that modules and options that do not apply should be deleted. The text itself may not be altered beyond choosing modules and options, filling in square brackets and completing the annexes; otherwise the clauses can no longer be used as a transfer basis unless approved by a national authority as ad hoc clauses.
The optional docking clause (Clause 7) lets new parties join the contract later, for example a sub-processor adhering under Module 3.
Transfer impact assessment and government access
In line with the Schrems II judgment, Clause 14 requires the parties to assess, before concluding the SCCs, whether the laws and practices of the destination country could prevent the importer from complying with the clauses. The Q&A calls this a "transfer impact assessment".
The assessment may draw on reliable information on how the law is applied in practice, the existence or absence of requests in the same sector and, under strict conditions, documented practical experience.
Under Clause 15.1, the importer must promptly notify the exporter, and where possible the individuals concerned, if it receives a legally binding request from a public authority to disclose the transferred data.
Frequently asked questions
When were the old SCCs repealed?
Decisions 2001/497/EC and 2010/87/EU were repealed with effect from 27 September 2021. For an additional 15 months, contracts concluded before that date could keep relying on them, provided the processing remained unchanged and appropriate safeguards were ensured.
Which law governs the SCCs?
For Modules 1, 2 and 3 it must be the law of an EU Member State or EEA country; for Module 4 it may be the law of a non-EEA country. In all cases the chosen law must allow third-party beneficiary rights for data subjects.
Can the SCCs be used with an importer already subject to the GDPR?
No. The Commission's Q&A answers that these SCCs cannot be used for transfers to controllers or processors whose processing is directly subject to the GDPR, referring to Article 1 of Decision (EU) 2021/914.
Does Module 4 always require a transfer impact assessment?
Not when an EEA processor returns data it received from its non-EEA controller to that controller. The Q&A explains that Section III contains a specific exception for this case, so there is no need to carry out a transfer impact assessment (Clause 14) or to comply with the obligations on access by public authorities (Clause 15).
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfersClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-gdpr-official-texts-data-transfers": {
"url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_…with your key. - Full details (responses, errors, JS and Python examples): developer docs.