Knowledge for companies

Standard contractual clauses and data processing: which document does what?

The EU standard contractual clauses in Decision 2021/915 cover the controller–processor relationship. The SCCs in Decision 2021/914 address certain third-country transfers; Modules 2 and 3 also incorporate data-processing requirements. The appropriate instrument depends on the actual roles, access and data flows.

T-NEX GmbHFirst version: Updated: Editorial policy
In daily work

How to use the solution.

Sources checked on 10 September 2026. This guide explains the instruments for software development and support, and the facts a business needs to collect before contracting.

Overview

Distinguish the two EU sets of clauses

The Commission adopted two different sets of clauses in 2021. Implementing Decision (EU) 2021/915 concerns the contractual relationship between controllers and processors. By itself, it is not an instrument for safeguarding a third-country transfer.

Implementing Decision (EU) 2021/914 contains the standard contractual clauses for transfers to third countries. This guide concerns those SCCs. A search for a data processing agreement template and a search for transfer clauses therefore do not necessarily lead to the same document.

Contract purpose and transfer assessment
InstrumentWhat it addressesWhat else needs assessment
Article 28 GDPR DPA / EU 2021/915Processing personal data on a controller’s behalfLegal basis, actual safeguards and, where relevant, an instrument for the third-country transfer
EU 2021/914 SCCsAppropriate safeguards for transfers within their scopeModule, annexes and effectiveness for the particular transfer; Modules 2/3 include Article 28(3)/(4)
Transfer Impact AssessmentAssessment of actual protection for the transfer consideredNot a standalone substitute for the contract, legal basis or transfer instrument
Overview

When remote access is a third-country transfer

The EDPB identifies three cumulative criteria: the exporter is subject to the GDPR for the processing, it makes personal data available to another controller or processor, and that importer is outside the EEA or is an international organisation. Server location alone does not answer this question.

Where a separate supplier in a third country accesses personal data in a European system, that access may constitute a transfer. The EDPB treats an employee of the same organisation accessing its data during a business trip differently: there is no separate importer. Data protection and security duties nevertheless remain relevant. A company within the same group may itself be a separate entity.

Overview

Choose a module for each data flow

The role depends on the processing, rather than the label in a proposal. A supplier may have different roles for different data flows. Where several modules are needed, the corresponding processing activities must be distinguishable.

The 2021/914 SCCs are designed for importers whose relevant processing is not already directly subject to the GDPR. Check that scope condition before relying on them. An address outside the EEA is not sufficient to select the instrument.

2021/914 SCC modules by role in the particular data flow
Data exporterData importerModule
ControllerControllerModule 1
ControllerProcessorModule 2
ProcessorProcessor or sub-processorModule 3
ProcessorControllerModule 4
Overview

What Modules 2 and 3 cover for the DPA

Modules 2 and 3 incorporate the requirements of Article 28(3) and (4) GDPR. Where used appropriately, an additional document is therefore not required simply to repeat those requirements. That does not mean an uncompleted SCC document constitutes a complete data processing agreement.

The subject matter, purpose and duration of processing, data categories, groups of data subjects, instructions and measures must fit the actual service. Additional provisions must not contradict the SCCs or prejudice data subjects' rights. Under Clause 5, the SCCs take precedence in the event of a contradiction.

Overview

The annexes make the agreement specific

Annex I describes the parties and the transfer and identifies the competent supervisory authority. Annex II sets out technical and organisational measures. Broad terms such as access controls or encryption do not adequately describe how the relevant measures are implemented.

For sub-processing, determine the authorisation option under Clause 9. Specific prior authorisation requires completion of the list in Annex III. General written authorisation requires an agreed list, advance notice of changes and the specified opportunity to object. Responsibilities and notification routes differ between Modules 2 and 3.

For development work, the records should show whether processing includes production data, test copies, error reports or support tickets. Describe deletion, return and removal of access so that the responsible people can implement them.

  • Identify contracting entities, data-protection roles and responsible contacts.
  • Describe purpose, duration, data categories and groups of data subjects.
  • Establish storage locations and actual access countries, including support.
  • Document how safeguards operate, including roles and control of keys.
  • Record sub-processors and the chosen authorisation and change procedure.
  • Make return, deletion, end of access and evidence requirements operational.
Overview

The hosting account does not determine the data protection role

A hosting model described by T-NEX for an internal knowledge platform uses a customer-owned account and direct billing by the infrastructure provider. That assigns commercial responsibility. Data-protection roles also depend on who operates the application and which entities can access its data.

Assess the application, database, logs and support separately. Who may read content, who can grant access and which information enters tickets? The facts need to match the contract and configured permissions. Ownership of the hosting account does not answer those questions.

Overview

Assess effectiveness for the actual transfer

First check whether an applicable adequacy decision covers the transfer or another suitable instrument is used. For SCC Modules 2 and 3, particularly relevant here, Clause 14 requires assessment of law and practice in the third country and the actual safeguards. This is commonly called a Transfer Impact Assessment. Clause 14 has a separate application condition for Module 4; the modules should not be treated as identical.

Contractual promises cannot remove foreign authorities' statutory access powers. Where problematic access rules apply to the particular transfer and the importer needs plaintext data, transport or disk encryption must not automatically be treated as an effective supplementary measure. The actual access, control of keys and demonstrated protection matter.

Overview

Changes must reach the contractual records

A new sub-processor, another access location or a different support provider may alter the processing described. The business needs a reliable route from a technical change to an appropriate review. A signed annex does not maintain itself.

The SCCs contain notification and action duties concerning public-authority access and inability to comply with the clauses. Where compliance cannot be ensured, the transfer must be suspended or the relevant contractual relationship terminated under the specified conditions. A planned measure must not appear in the project record as protection already in operation.

FAQ

Frequently asked questions

Do Modules 2 and 3 always need a separate DPA alongside them?

No. These modules incorporate Article 28(3) and (4). The appropriate module must be validly agreed with the necessary details and annexes.

Is EU hosting sufficient?

Storage location alone is insufficient. Access by separate suppliers, further recipients and actual data flows also need assessment.

Can I rewrite the SCC text freely?

The specified choices of modules and options and completion of annexes are allowed. Other modifications must not change the clauses so that they lose their effect as an approved transfer instrument; additional provisions must not contradict them.

Does signing SCCs establish that a project complies with the GDPR?

No. Actual processing, its legal basis, roles, security measures, annexes and transfer assessment must fit together. A signature alone does not establish those conditions.

Are the 2021/915 SCCs a template for third-country transfers?

No. They address processing on a controller’s behalf and do not by themselves safeguard a third-country transfer. Assess the appropriate basis under Chapter V GDPR. The 2021/914 SCCs can be one such instrument where their scope conditions are met and their safeguards work.

Related options

You may also be interested in these.

Which task would you like to solve next?

Bring a concrete task. Together, we will define what the application needs to do.

Discuss data access in a development project