Transfer Impact Assessment template
Assess development and support transfers: data flows, SCCs, third-country law and safeguards. Includes editable TIA working templates in German and English.
The EU standard contractual clauses in Decision 2021/915 cover the controller–processor relationship. The SCCs in Decision 2021/914 address certain third-country transfers; Modules 2 and 3 also incorporate data-processing requirements. The appropriate instrument depends on the actual roles, access and data flows.
Sources checked on 10 September 2026. This guide explains the instruments for software development and support, and the facts a business needs to collect before contracting.
The Commission adopted two different sets of clauses in 2021. Implementing Decision (EU) 2021/915 concerns the contractual relationship between controllers and processors. By itself, it is not an instrument for safeguarding a third-country transfer.
Implementing Decision (EU) 2021/914 contains the standard contractual clauses for transfers to third countries. This guide concerns those SCCs. A search for a data processing agreement template and a search for transfer clauses therefore do not necessarily lead to the same document.
| Instrument | What it addresses | What else needs assessment |
|---|---|---|
| Article 28 GDPR DPA / EU 2021/915 | Processing personal data on a controller’s behalf | Legal basis, actual safeguards and, where relevant, an instrument for the third-country transfer |
| EU 2021/914 SCCs | Appropriate safeguards for transfers within their scope | Module, annexes and effectiveness for the particular transfer; Modules 2/3 include Article 28(3)/(4) |
| Transfer Impact Assessment | Assessment of actual protection for the transfer considered | Not a standalone substitute for the contract, legal basis or transfer instrument |
The EDPB identifies three cumulative criteria: the exporter is subject to the GDPR for the processing, it makes personal data available to another controller or processor, and that importer is outside the EEA or is an international organisation. Server location alone does not answer this question.
Where a separate supplier in a third country accesses personal data in a European system, that access may constitute a transfer. The EDPB treats an employee of the same organisation accessing its data during a business trip differently: there is no separate importer. Data protection and security duties nevertheless remain relevant. A company within the same group may itself be a separate entity.
The role depends on the processing, rather than the label in a proposal. A supplier may have different roles for different data flows. Where several modules are needed, the corresponding processing activities must be distinguishable.
The 2021/914 SCCs are designed for importers whose relevant processing is not already directly subject to the GDPR. Check that scope condition before relying on them. An address outside the EEA is not sufficient to select the instrument.
| Data exporter | Data importer | Module |
|---|---|---|
| Controller | Controller | Module 1 |
| Controller | Processor | Module 2 |
| Processor | Processor or sub-processor | Module 3 |
| Processor | Controller | Module 4 |
Modules 2 and 3 incorporate the requirements of Article 28(3) and (4) GDPR. Where used appropriately, an additional document is therefore not required simply to repeat those requirements. That does not mean an uncompleted SCC document constitutes a complete data processing agreement.
The subject matter, purpose and duration of processing, data categories, groups of data subjects, instructions and measures must fit the actual service. Additional provisions must not contradict the SCCs or prejudice data subjects' rights. Under Clause 5, the SCCs take precedence in the event of a contradiction.
Annex I describes the parties and the transfer and identifies the competent supervisory authority. Annex II sets out technical and organisational measures. Broad terms such as access controls or encryption do not adequately describe how the relevant measures are implemented.
For sub-processing, determine the authorisation option under Clause 9. Specific prior authorisation requires completion of the list in Annex III. General written authorisation requires an agreed list, advance notice of changes and the specified opportunity to object. Responsibilities and notification routes differ between Modules 2 and 3.
For development work, the records should show whether processing includes production data, test copies, error reports or support tickets. Describe deletion, return and removal of access so that the responsible people can implement them.
A hosting model described by T-NEX for an internal knowledge platform uses a customer-owned account and direct billing by the infrastructure provider. That assigns commercial responsibility. Data-protection roles also depend on who operates the application and which entities can access its data.
Assess the application, database, logs and support separately. Who may read content, who can grant access and which information enters tickets? The facts need to match the contract and configured permissions. Ownership of the hosting account does not answer those questions.
First check whether an applicable adequacy decision covers the transfer or another suitable instrument is used. For SCC Modules 2 and 3, particularly relevant here, Clause 14 requires assessment of law and practice in the third country and the actual safeguards. This is commonly called a Transfer Impact Assessment. Clause 14 has a separate application condition for Module 4; the modules should not be treated as identical.
Contractual promises cannot remove foreign authorities' statutory access powers. Where problematic access rules apply to the particular transfer and the importer needs plaintext data, transport or disk encryption must not automatically be treated as an effective supplementary measure. The actual access, control of keys and demonstrated protection matter.
A new sub-processor, another access location or a different support provider may alter the processing described. The business needs a reliable route from a technical change to an appropriate review. A signed annex does not maintain itself.
The SCCs contain notification and action duties concerning public-authority access and inability to comply with the clauses. Where compliance cannot be ensured, the transfer must be suspended or the relevant contractual relationship terminated under the specified conditions. A planned measure must not appear in the project record as protection already in operation.
No. These modules incorporate Article 28(3) and (4). The appropriate module must be validly agreed with the necessary details and annexes.
Storage location alone is insufficient. Access by separate suppliers, further recipients and actual data flows also need assessment.
The specified choices of modules and options and completion of annexes are allowed. Other modifications must not change the clauses so that they lose their effect as an approved transfer instrument; additional provisions must not contradict them.
No. Actual processing, its legal basis, roles, security measures, annexes and transfer assessment must fit together. A signature alone does not establish those conditions.
No. They address processing on a controller’s behalf and do not by themselves safeguard a third-country transfer. Assess the appropriate basis under Chapter V GDPR. The 2021/914 SCCs can be one such instrument where their scope conditions are met and their safeguards work.
Assess development and support transfers: data flows, SCCs, third-country law and safeguards. Includes editable TIA working templates in German and English.
Distributed software development with T-NEX: agree scope, collaboration and handover in advance, with costs considered across the full engagement.
Explore serviceCommission external software development with clear goals, data responsibilities, roles, acceptance criteria, handover and ongoing operational support.
Bring a concrete task. Together, we will define what the application needs to do.
Discuss data access in a development project