Standard Contractual Clauses, or SCCs, are contract templates approved by the European Commission. When a European company sends data to a country without an An adequacy decision is an EU ruling that a non-EU country protects data well enough to allow data transfers there without extra safeguards. Learn more → , like the US, it can use SCCs to commit both sides to GDPR is the EU's main data protection law. It gives Europeans rights over their personal data and sets strict rules for companies that handle it. Learn more → -level protections. SCCs became far more common after the Schrems II is a 2020 EU court ruling. It found that standard tools for sending data to the US did not protect Europeans enough from US surveillance laws. Learn more → ruling, which struck down the easier Privacy Shield agreement. Critics point out that a contract cannot override a government’s surveillance laws. SCCs help with compliance, but they do not remove the underlying legal risk.
Frequently asked questions
What are Standard Contractual Clauses (SCCs)?
Standard Contractual Clauses are contract templates. The European Commission approves them. Companies use them when sending personal data to a country without an adequacy decision.
By signing an SCC, both companies agree to follow GDPR-level rules. This applies even though the data is now outside the EU. SCCs are the most common tool for sending data to the US today.
Are SCCs legally binding on their own?
Yes, as a contract. Both companies that sign an SCC are legally bound by its terms. If one side breaks the agreement, the other side can take legal action.
But a contract only binds the companies that sign it. It cannot bind a government. If a government's law forces a company to hand over data anyway, the SCC alone cannot stop that from happening.
Do SCCs fully solve the problem raised by Schrems II?
Not on their own. The Schrems II ruling said companies must do more than just sign an SCC. They must also check if the destination country's laws actually let the SCC work as intended.
This check is sometimes called a transfer impact assessment. If a country's surveillance laws are too broad, like in the US, the company may need extra technical safeguards. In some cases, no safeguard is considered enough, and the transfer stays risky.
When do companies need to use SCCs?
Companies need SCCs when they send personal data from the EU to a country without an adequacy decision. The US is the most common example, since it has no general adequacy decision.
A company doesn't need SCCs if it has another valid legal basis instead. For US transfers specifically, a company can rely on the EU-US Data Privacy Framework instead, if it has joined that program.