Skip to content

Glossary

Standard contractual clauses (SCCs)

Contract terms adopted by the European Commission, signed by both sides to give a transfer out of Europe a lawful footing.

In plain terms

A contract somebody else has already written and approved, which you and your supplier both sign so that data can lawfully leave Europe. The appeal is that the protective terms are settled, so neither side spends time negotiating what protection ought to mean.

01

Why it matters

Because this is the mechanism most buyers actually meet, usually as an appendix arriving with a vendor agreement and getting signed unread. It commits both sides to things, the people whose data it covers can enforce it against either of them, and the party least likely to have read it is frequently the one signing.

02

How it works

The terms are adopted centrally, which is the entire point. The European Commission has approved the text in advance, so the parties adopt it rather than arguing over what adequate protection means, and that is what makes the mechanism workable at the scale software procurement happens at.

Filling in is expected and changing is different. Choosing the parts that apply to your arrangement, completing the annexes, filling the bracketed details and adding safeguards that increase protection are all anticipated and do not alter the core text, so a vendor doing those things is using the instrument correctly.

Editing the text itself is the line. Where the parties change the clauses beyond those adaptations, the modified version may no longer serve as the basis for the transfer unless a national data protection authority approves it separately, which turns a settled arrangement into an application.

Sitting inside a wider contract is fine and contradicting it is not. The clauses can be supplemented and folded into a commercial agreement, provided nothing elsewhere in that agreement cuts across them, directly or indirectly, or reduces what the people whose data it is would otherwise get.

Signing is not the whole of the exercise, because the parties are expected to have assessed beforehand whether the laws and practices where the data is going would prevent the receiving side from keeping to the clauses. An organisation that signed and stopped has done one part of a two-part obligation.

The people whose data it covers can enforce it. Redress runs against the sending organisation as well as the receiving one, which is the detail that turns an unread appendix into something with teeth, and it is the reason reading your own side of it is worth the few minutes it takes.

Filling in, or changing the instrument

Filling in, or changing the instrumentThe reason this matters commercially is that the two columns arrive in the same email and look alike. A vendor sending back an appendix with the annexes completed, the options narrowed to the arrangement in hand and a couple of extra protections written in has used the instrument exactly as intended, and refusing that is refusing normal practice. A vendor sending back the same appendix with the clause text softened has produced a document that may not do the job, and the remedy is not a negotiation but a separate approval nobody wants to go and get. The wider contract is where this most often goes wrong quietly, because the appendix can be untouched while a general limitation of liability elsewhere in the agreement pulls against it, and the two documents are usually reviewed by different people who never read them side by side. The practical check is to compare, once, before signing: read your own obligations in the appendix, then read the parts of the main agreement that would apply to them.Expected, not an alterationChoosing the parts that apply.Completing annexes andbracketed details.Adding safeguards that raiseprotection.Changes what you are relying onEditing the clause text itself.A wider contract term that cutsacross it.Anything reducing whatindividuals get.Both columns look like redlininga contract, which is why thedistinction gets lost. Theleft-hand column is theinstrument working as designed.The right-hand column means whatyou have is no longer the thingthe approval attaches to.
The reason this matters commercially is that the two columns arrive in the same email and look alike. A vendor sending back an appendix with the annexes completed, the options narrowed to the arrangement in hand and a couple of extra protections written in has used the instrument exactly as intended, and refusing that is refusing normal practice. A vendor sending back the same appendix with the clause text softened has produced a document that may not do the job, and the remedy is not a negotiation but a separate approval nobody wants to go and get. The wider contract is where this most often goes wrong quietly, because the appendix can be untouched while a general limitation of liability elsewhere in the agreement pulls against it, and the two documents are usually reviewed by different people who never read them side by side. The practical check is to compare, once, before signing: read your own obligations in the appendix, then read the parts of the main agreement that would apply to them.
03

Seen in the wild

  • An appendix arriving with an assistant vendor's agreement and being signed unread.

    ChatGPT
  • Checking which parts a search vendor has filled in, and what their annexes actually list.

    Glean
  • An automation vendor's terms where the transfer appendix is the substantive part.

    Make
04

Common misconceptions

People assume

Signing them completes the exercise.

In fact

The parties are also expected to have assessed beforehand whether conditions where the data is going would stop the receiving side keeping to the clauses. Signing is one part of a two-part obligation, and the second part is the one that gets skipped.

People assume

They only impose obligations on the vendor.

In fact

They bind everybody who signs, and the people whose data it is have redress against the sending organisation as well as the receiving one. The buyer's own commitments are the half that goes unread, and they are enforceable.

05

Questions

A vendor wants to change some of the wording. Is that a problem?
It depends which wording. Completing the annexes, filling in bracketed details, selecting the parts that apply and adding protections are all expected. Editing the clause text itself is different, and a modified version generally cannot be relied on unless a data protection authority approves it separately.
Can they be part of a normal commercial contract?
Yes, and that is the usual arrangement. They can be supplemented and incorporated into a wider agreement, so long as nothing else in that agreement contradicts them or weakens what individuals get. A blanket limitation of liability elsewhere in the contract is the classic thing that does.
What should a buyer actually read?
Your own obligations rather than the protective terms, which are fixed and identical in every copy anybody is ever sent. The buyer-side commitments are the part that varies in how much work it implies, and the people whose data it is can enforce them against you.
06

Key takeaways

  • Adopted centrally: the protective text is settled, not negotiated.
  • Filling in and adding protection are expected; editing the text is not.
  • A wider contract may supplement them but must not cut across them.
  • They bind the buyer too, and individuals can enforce against both sides.
08

Tools that use this

  • ChatGPT

    A transfer appendix arriving with the agreement and signed unread.

  • Glean

    Which parts have been filled in, and what the annexes list.

  • Make

    Terms where the transfer appendix is the substantive part.

Last checked August 2026

All glossary terms