What is Standard Contractual Clauses (SCCs)?
Standard Contractual Clauses (SCCs) are pre-approved contractual terms that organisations use to lawfully transfer personal data from the EU/UK to countries without an EU adequacy decision. They set binding obligations on exporters and importers to protect personal data during cross-border transfers.
SCCs are model contract clauses issued by the European Commission (and mirrored by UK guidance) that parties add to their contracts when personal data is moved from the EU/UK to a third country. Under GDPR, transfers to countries without an adequacy decision require appropriate safeguards — SCCs are one of the most common, recognised legal mechanisms. The clauses specify responsibilities (for example on security, data subject rights, audits and liability) and apply to controller-to-controller, controller-to-processor and processor-to-processor situations. Since the Schrems II ruling, organisations must also assess whether the law and practices in the destination country undermine the protection SCCs promise, and add further technical or contractual measures if needed.
Usage example
A local council in France uses a cloud survey platform hosted in the United States. To comply with GDPR when storing resident survey responses on U.S. servers, the council and the platform vendor sign the EU Standard Contractual Clauses and document a transfer impact assessment identifying any additional safeguards required.
Practical application
SCCs matter because many survey platforms, cloud services and subprocessors are located outside the EU/UK. Using SCCs lets organisations legally transfer participant data while keeping contractual protections in place — reducing regulatory risk, protecting respondents' privacy and building community trust. In practice this means: including the SCCs in supplier contracts, performing a transfer impact assessment (to check for foreign access laws or other risks), and implementing supplementary measures (encryption, access restrictions, data minimisation or stored-location controls) when necessary.
FAQ
Are SCCs enough by themselves to lawfully transfer data?
Not always. SCCs provide a legal framework, but after Schrems II organisations must assess whether the recipient country's laws could allow access to the data in ways that undermine the SCCs. If risks are identified, you should add technical or organisational measures (for example strong encryption, limiting data retention or keeping data in specific regions) to bring the transfer into compliance. Consult legal counsel for high-risk situations.
When do we need SCCs?
You need SCCs when personal data is transferred from the EU/UK to a country without an EU adequacy decision (or equivalent UK position) and no other transfer mechanism applies (for example, binding corporate rules or an adequacy decision). This commonly occurs when using international cloud providers, external analytics vendors or subprocessors hosted outside the EU/UK.
Which version of SCCs should we use?
Use the latest EU Commission SCCs (adopted in 2021) for new contracts; they cover multiple transfer scenarios and include modular options depending on the roles of the parties. If you operate under UK law, check for the UK’s equivalent updated clauses. Where older clauses are in place, plan to migrate to the updated text as recommended by regulators.
Do SCCs change how we handle participant data in surveys?
SCCs don't change the survey questions you ask, but they do affect contractual, technical and operational safeguards: who is responsible for security, how long data can be retained, what access subprocessors have, and what happens if a legal request for data is made in another country. For survey administrators, this usually means ensuring the platform's contracts include SCCs and that appropriate encryption, access controls and retention policies are applied.