Insights: AlertBetter Than Santa Clauses? New and Improved Standard Contractual Clauses (SCCs)! And a form DPA!June 9, 2021 Long-awaited SCCs for EU Data Transfers Adopted by European Commission with 18-month Transition Period The EU has a cross-border data transfer framework gift for you! On June 4, 2021, the European Commission (“EC”) adopted two sets of standard contractual clauses (“SCCs”) that businesses may use as a tool to comply with European cross-border data transfer requirements for transferring data outside of the European Economic Area (“EEA”), and as a controller-processor data processing agreement (“DPA”). The EC's decision implementing the new SCCs will enter into force twenty days after publication in the Official Journal of the European Union. Parties currently using the prior version of the SCCs will have until September 27, 2021, to start using the new SCCs for all new data transfers and will have until December 27, 2022, to replace the prior SCCs currently in effect. It is important to note that if the underlying agreement between the parties is re-negotiated or the scope of the data being processed is changed during the transition period, then the new SCCs must be utilized. Practical Steps 1. For Cross-Border Data Transfers: Steps to take now (a) Identify all in-force contracts that rely on – or should rely on! – SCCs as a cross-border data transfer mechanism. (b) Determine which new SCCs / modules are most appropriate for each in-force contract. (c) Develop a plan for amending those contracts to replace old SCCs with new SCCs with appropriate modules over the course of the next 18 months. (d) Verify insurance coverage to ensure that any new potential liability relating to claims between controllers and processors is adequately covered. Steps to take in late summer 2021 and beyond (e) Once the European Data Protection Board (“EDPB”) finalizes its guidance on data protection safeguards, which is expected this summer, implement internal data protection safeguards to align with SCC requirements (see Enhanced Data Protection Safeguards and Enhanced Sub-Processor Requirements summaries below). (f) Amend standard contracting practices to ensure that all new contracts that require SCCs are entered into with new SCCs with appropriate modules. 2. For Controller-Processor DPAs: Steps to take now (a) Determine whether the form DPA meets your organization's business requirements, given other business operational needs beyond GDPR requirements; if possible, transition to the new SCC form DPA. (b) Develop a plan to amend currently in-force DPAs with the new SCC form DPA. (c) Amend standard contracting practices to ensure that all new contracts that require DPAs are entered into with the new DPA, if applicable. Summary of new SCCs 1. SCCs for Cross-Border Data Transfers The new model clauses apply to data transfers to third countries outside of the EEA. Under Article 46(1) of European Union's General Data Protection Regulation (“GDPR”), in the absence of an adequacy decision, a controller or processor acting as the data exporter may transfer personal data to a third country only if the data exporter has ensured appropriate safeguards. Under Article 46(2)(c) of the GDPR, appropriate safeguards include model clauses. However, on July 16, 2020, in the Schrems II decision, the Court of Justice of the European Union cast substantial doubt about whether the prior model clauses remain effective, especially regarding transfers to the United States. Schrems II requires parties relying on the model clauses to implement additional appropriate safeguards ensuring that transferred personal data is adequately protected when personal data is transferred to countries outside of the EEA. The new SCCs address issues raised by Schrems II and have been deemed by the EC to provide appropriate safeguards, subject to the parties' identification of sufficient technical and organizational measures for protecting personal data. The following are a few significant changes from the previous version of the SCCs:
The EC's implementing decision clarifies that data exporters and data importers may continue to execute the prior model clauses until September 27, 2021, and all previously concluded model clauses will remain valid until December 27, 2022 (Article 4). The EC's implementing decision also states that these model clauses should fulfill requirements for controller-processor DPAs. Parties must take account of the specific circumstances of the transfer, such as applicable laws permitting governmental access to the transferred personal data, when considering what safeguards to put in place under the new SCCs. The EC, in contrast with draft guidance from the EDPB, encourages parties to consider the practical application of such laws (including the history of government requests for access to personal data in the applicable industry and with respect to the specific data importer and exporter). Finalized EDPB guidance is expected later this summer, and parties should wait to finalize safeguards identified in the model clauses, as practical, to ensure that such safeguards meet the EDPB's expectations. 2. SCCs for Data Controllers and Processors The second set of SCCs are a standard-form DPA. The EC's implementing decision on these SCCs makes clear that they fulfill the requirements for DPAs under Articles 28(3) and 28(4) of GDPR. As background, Article 28(3) of the GDPR requires the processor to enter into a contract that governs the subject matter and duration of the processing, the nature and purpose of the processing, the types of personal data being processed, the categories of data subjects, and the obligations and rights of the controller. In practice, this set of SCCs provides businesses with guidance on what to include in DPAs and, if properly implemented, a compliance safe harbor. The rate of adoption for this standard-form DPA may remain low, however, as many companies have crafted DPAs tailored to the company's operations and with a global scope. Generally, the new SCCs offer a welcome update to the prior clauses, which were often ill-suited to business realities and modern data transfers. For now, the privacy community will anxiously await the finalized EDPB guidance to see if they follow the EC's risk-based approach to governmental access to personal data.
Related People![]() John M. Brigagliano
jbrigagliano@ktslaw.com ![]() Vita E. Zeltser
vzeltser@ktslaw.com |


