Waselius & Wist Navigation
  • Our team
  • In Focus
    • Recent Work
    • News
    • Legal Updates
    • Publications
    • Rankings
    • Blog
    • Pykälät töissä podcast
    • Newsletter
  • About Us
    • Corporate Social Responsibility
    • ESG Initiatives
  • Expertise
    • Banking and Finance
    • Capital Markets
    • Corporate and Commercial
    • Corporate governance and Investigations
    • Data Protection
    • Dispute Resolution
    • Employment and Incentives
    • Energy and Natural Resources
    • EU and Competition
    • Financial Regulatory and Compliance
    • Insurance
    • Intellectual Property and Technology
    • Marketing
    • Mergers and Acquisitions
    • Private Equity
    • Real Estate
    • Restructuring and Insolvency
    • Tax and Structuring
  • Careers
    • Lawyers
    • Law students
    • Support staff
    • Open Positions
    • Contact
  • Contact
  • Our team
  • In Focus
    • Recent Work
    • News
    • Legal Updates
    • Publications
    • Rankings
    • Blog
    • Pykälät töissä podcast
    • Newsletter
  • About Us
    • Corporate Social Responsibility
    • ESG Initiatives
  • Expertise
    • Banking and Finance
    • Capital Markets
    • Corporate and Commercial
    • Corporate governance and Investigations
    • Data Protection
    • Dispute Resolution
    • Employment and Incentives
    • Energy and Natural Resources
    • EU and Competition
    • Financial Regulatory and Compliance
    • Insurance
    • Intellectual Property and Technology
    • Marketing
    • Mergers and Acquisitions
    • Private Equity
    • Real Estate
    • Restructuring and Insolvency
    • Tax and Structuring
  • Careers
    • Lawyers
    • Law students
    • Support staff
    • Open Positions
    • Contact
  • Contact
In Focus
Home In Focus New GDPR standard contractual clauses available for use as of 27 June 2021

Legal Updates28.06.2021

New GDPR standard contractual clauses available for use as of 27 June 2021

On 4 June 2021, the European Commission published the final version of the implementing decision on the below two sets of standard contractual clauses that may both be used by businesses as of 27 June 2021:

  • Standard contractual clauses covering international (EEA cross-border) transfers of personal data (Transfer SCCs). Under the GDPR, transfers of personal data from the EEA to other countries is prohibited unless appropriate safeguards are put in place. The Transfer SCCs are one of the transfers tools provided by the GDPR and commonly used by businesses when involved in international data transfers.
  • Standard contractual clauses that may be used between controllers and processors when the processor is carrying out processing activities on behalf of the controller and a data processing agreement under Art 28 GDPR must be put in place (Art 28 SCCs).

Transfer SCCs

The new Transfer SCCs are better suited for complex international processing scenarios than the existing ones, which are based on the data protection directive 95/46/EC. Contrary to the existing SCCs the new Transfer SCCs also apply to different processing scenarios often involving multiple data importers and exporters.

The Transfer SCCs also take into account the Schrems II ruling by the Court of Justice of the European Union and provides both data exporters and importers with certain tools to comply with the said ruling requirements (for more details on the Schrems II ruling please see our legal update on recent developments post CJEU Schrems II judgement). However, when preparing for international data transfers the relevant transfer parties should review the Transfer SCCs together with the European Data Protection Board’s very recently adopted (18 June 2021) recommendations on supplementary measures for data transfers. These recommendations derive from the Schrems II judgment and includes a six step plan helping businesses to assess the risks with EEA cross-border data transfers and to identify if supplementary measures must be put in place to protect the data to be transferred.

What is new under the Transfer SCCs?

  • Transfer SCCs cover additional data transfer scenarios: While the existing SCCs cover data transfers (1) controller-controller and (2) controller-processor the new Transfer SCCs also cover transfers (3) processor – processor and (4) processor – controller. Also, the clauses can be used even if the data exporter is not established within the EEA but is nevertheless caught by the GDPR when, for example, offering goods or services to individuals within the EEA.
  • Modular approach: The Transfer SCCs contain general provisions that apply to all kind of transfers taking place under the Transfer SCCs as well as modular provisions that must separately be chosen by the relevant parties for each specific transfer situation. Therefore, the taking into use of the new Transfer SCCs requires that businesses understand their role and select the right module for the transfer situation at hand. The Transfer SCCs may also be joined by several parties by the so called “docking clause”.
  • Schrems II elements: The Transfer SCCs reflect the Schrems II ruling by requiring both the data exporter and importer to warrant that they have carried out an assessment based on which they have no reason to believe that the laws in the destination country would prevent the data importer from fulfilling its obligations under the Transfer SCCs (Data Transfer Risk Assessment). The Transfer SCCs include an example list of elements that may be taken into account when conducting the above assessment (such as the length of the processing chain, the number of actors involved and the transmission channels used, intended onward transfers, the type of recipients, the purpose of processing, the categories and format of the transferred personal data, the economic sector in which the transfer occurs, to name a few).  The assessment must be documented and provided to the competent supervisory authority upon request.A further Schrems II element is the obligation of the data importer to notify the data exporter and the data subject if it receives a request from a public authority for disclosure of transferred personal data or if it becomes aware of any direct access by public authorities to transferred personal data. In these cases the data importer must also challenge the legality of the request and consider whether it has grounds to challenge such an order and if possible, challenge the request.
  • Data processing agreement elements included: Where the Transfer SCCs are used in a controller-processor or processor-sub processor relation, the relevant parties do not need to draw up a separate data processing agreement. The Transfer SCCs already include the necessary stipulations of a data processing agreement as set forth under GDPR Art 28.
  • 18-month transition period: While the new Transfer SCCs are available for use as of 27 June 2021, exporters and importers can continue to sign the existing SCCs until 27 September 2021. After this date no new contracts can be signed using the existing standard contractual clauses.

Businesses relying on the existing Transfer SCCs will have 18 months to replace them with the new ones. This means that by 27 December 2022 agreements with customers, suppliers and other parties with whom personal data is shared must have been updated and re-negotiated to include the new Transfer SCCs.

While the new Transfer SCCs certainly better reflect the increased complexity of businesses’ data processing activities, their use and application will also require more work from both data importers and exporters. Below are some recommended action items to be considered by businesses:

  • Since data exporters and controllers cannot after 27 September 2021 sign new contracts using the existing SCCs, businesses will already now start to make themselves acquainted with the new Transfer SCCs and assess which data transfer scenarios and related modular provisions apply to their data transfers. Businesses must be ready to take the new Transfer SCCS in as an element in discussions and negotiations with their customers, suppliers and other business related parties end September 2021.
  • Businesses should also map and review their current data transfers and especially identify such transfers that are made using the existing SCCs and the role it has in such a transfer. Contracts under which data transfers are made relying on the existing SCCs must be amended to include the new Transfer SCCs no later than 27 December 2022.
  • Businesses should consider preparing a Data Transfer Risk Assessment template together with a plan on how to in practice carry out the assessment for each non -EEA country to which personal data is or may be transferred.
  • Business may also consider implementing a process by which adoption of relevant data protection laws in third countries relevant for the business in question is followed-up.

Art 28 SCCs

The Art 28 SCCs serve as a model data processing agreement between controllers and processors where a processor carries out processing activities on behalf of a controller and a data processing agreement under GDPR art 28 must be put in place. Additionally, also a number of supervisory authorities across the EU have published their own model data processing agreements that also, naturally, may be used by controllers and (sub) processors.

The Art 28 SCCs are optional meaning that there is no obligation for a data controller or processor to use them. Hence, the Art 28 SCCs will not require additional work for businesses already having their own standard GDPR Art 28 compliant data processing agreements in place but businesses may continue to use their existing data processing agreements.

Parties wishing to use the Art 28 SCCs may attach them as an annex to their principal agreement. The clauses further come with four annexes to be filled in by the parties: (i) list of the parties, (ii) description of the processing, (iii) technical ad organizational measures and (iv) list of sub-processors.

The Art 28 SCCs do not cover international data transfers requirements. If personal data is transferred outside of the EEA in a controller-processor or processor-sub processor scenario, the Transfer SCCs (discussed above) include the necessary elements of a GDPR Art 28 processing agreement and, therefore, no additional data processing agreement must in these cases be put in place.

For more information please contact:

Charlotta Sittnikow

Counsel

Share:
Image

Contact info

Eteläesplanadi 24 A
00130 Helsinki, Finland

+358 9 668 9520
+358 9 668 95 222
info@waselius.fi

Quick links

  • Our Team
  • In Focus
  • About Us
  • Expertise
  • Careers

E-invoicing

E-address: 003710525214
Operator: Apix Messaging Oy
Service ID: 003723327487


BUSINESS ID 1052521-4
VAT ID FI10525214

Legal notice
Privacy notice
General Terms and Conditions

© 2025 Waselius Attorneys Ltd

This website uses cookies to compile statistical data on the use of our website in order to enable us to evaluate and improve our site. OK Decline Cookie Policy
Manage Cookies

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
CookieDurationDescription
_lfa2 yearsMarketing & analytics (website visitor tracking) using Leadfeeder
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT