Glossary
Standard contractual clauses (SCCs)
Contract terms adopted by the European Commission, signed by both sides to give a transfer out of Europe a lawful footing.
In plain terms
A contract somebody else has already written and approved, which you and your supplier both sign so that data can lawfully leave Europe. The appeal is that the protective terms are settled, so neither side spends time negotiating what protection ought to mean.
Why it matters
Because this is the mechanism most buyers actually meet, usually as an appendix arriving with a vendor agreement and getting signed unread. It commits both sides to things, the people whose data it covers can enforce it against either of them, and the party least likely to have read it is frequently the one signing.
How it works
The terms are adopted centrally, which is the entire point. The European Commission has approved the text in advance, so the parties adopt it rather than arguing over what adequate protection means, and that is what makes the mechanism workable at the scale software procurement happens at.
Filling in is expected and changing is different. Choosing the parts that apply to your arrangement, completing the annexes, filling the bracketed details and adding safeguards that increase protection are all anticipated and do not alter the core text, so a vendor doing those things is using the instrument correctly.
Editing the text itself is the line. Where the parties change the clauses beyond those adaptations, the modified version may no longer serve as the basis for the transfer unless a national data protection authority approves it separately, which turns a settled arrangement into an application.
Sitting inside a wider contract is fine and contradicting it is not. The clauses can be supplemented and folded into a commercial agreement, provided nothing elsewhere in that agreement cuts across them, directly or indirectly, or reduces what the people whose data it is would otherwise get.
Signing is not the whole of the exercise, because the parties are expected to have assessed beforehand whether the laws and practices where the data is going would prevent the receiving side from keeping to the clauses. An organisation that signed and stopped has done one part of a two-part obligation.
The people whose data it covers can enforce it. Redress runs against the sending organisation as well as the receiving one, which is the detail that turns an unread appendix into something with teeth, and it is the reason reading your own side of it is worth the few minutes it takes.
Filling in, or changing the instrument
Common misconceptions
People assume
Signing them completes the exercise.
In fact
The parties are also expected to have assessed beforehand whether conditions where the data is going would stop the receiving side keeping to the clauses. Signing is one part of a two-part obligation, and the second part is the one that gets skipped.
People assume
They only impose obligations on the vendor.
In fact
They bind everybody who signs, and the people whose data it is have redress against the sending organisation as well as the receiving one. The buyer's own commitments are the half that goes unread, and they are enforceable.
Questions
- A vendor wants to change some of the wording. Is that a problem?
- It depends which wording. Completing the annexes, filling in bracketed details, selecting the parts that apply and adding protections are all expected. Editing the clause text itself is different, and a modified version generally cannot be relied on unless a data protection authority approves it separately.
- Can they be part of a normal commercial contract?
- Yes, and that is the usual arrangement. They can be supplemented and incorporated into a wider agreement, so long as nothing else in that agreement contradicts them or weakens what individuals get. A blanket limitation of liability elsewhere in the contract is the classic thing that does.
- What should a buyer actually read?
- Your own obligations rather than the protective terms, which are fixed and identical in every copy anybody is ever sent. The buyer-side commitments are the part that varies in how much work it implies, and the people whose data it is can enforce them against you.
Key takeaways
- Adopted centrally: the protective text is settled, not negotiated.
- Filling in and adding protection are expected; editing the text is not.
- A wider contract may supplement them but must not cut across them.
- They bind the buyer too, and individuals can enforce against both sides.
Last checked August 2026