Standard Contractual Clauses 2021: modules, TIA and how to use them
The 2021 Standard Contractual Clauses are the most common contractual tool for sending personal data from the EEA to a third country. This page explains how to pick a module and what the clauses require, based on Decision (EU) 2021/914 and the Commission's Q&A.
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
Four modules for four transfer scenarios
The earlier clauses only covered controller to controller and controller to processor transfers. The modernised SCCs cover Controller to Controller (Module 1), Controller to Processor (Module 2), Processor to Processor (Module 3) and Processor to Controller (Module 4).
The parties keep the general clauses and those of the relevant module, and the Q&A says that modules and options that do not apply should be deleted. The text itself may not be altered beyond choosing modules and options, filling in square brackets and completing the annexes; otherwise the clauses can no longer be used as a transfer basis unless approved by a national authority as ad hoc clauses.
The optional docking clause (Clause 7) lets new parties join the contract later, for example a sub-processor adhering under Module 3.
Transfer impact assessment and government access
In line with the Schrems II judgment, Clause 14 requires the parties to assess, before concluding the SCCs, whether the laws and practices of the destination country could prevent the importer from complying with the clauses. The Q&A calls this a "transfer impact assessment".
The assessment may draw on reliable information on how the law is applied in practice, the existence or absence of requests in the same sector and, under strict conditions, documented practical experience.
Under Clause 15.1, the importer must promptly notify the exporter, and where possible the individuals concerned, if it receives a legally binding request from a public authority to disclose the transferred data.
Questions fréquentes
When were the old SCCs repealed?
Decisions 2001/497/EC and 2010/87/EU were repealed with effect from 27 September 2021. For an additional 15 months, contracts concluded before that date could keep relying on them, provided the processing remained unchanged and appropriate safeguards were ensured.
Which law governs the SCCs?
For Modules 1, 2 and 3 it must be the law of an EU Member State or EEA country; for Module 4 it may be the law of a non-EEA country. In all cases the chosen law must allow third-party beneficiary rights for data subjects.
Can the SCCs be used with an importer already subject to the GDPR?
No. The Commission's Q&A answers that these SCCs cannot be used for transfers to controllers or processors whose processing is directly subject to the GDPR, referring to Article 1 of Decision (EU) 2021/914.
Does Module 4 always require a transfer impact assessment?
Not when an EEA processor returns data it received from its non-EEA controller to that controller. The Q&A explains that Section III contains a specific exception for this case, so there is no need to carry out a transfer impact assessment (Clause 14) or to comply with the obligations on access by public authorities (Clause 15).
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfersClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-gdpr-official-texts-data-transfers": {
"url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.