Glossary

Standard Contractual Clauses (SCCs)

Standard Contractual Clauses are pre-approved contract terms, published by the European Commission, that make transferring personal data outside the EU lawful under GDPR. When an EU customer’s data flows to your US infrastructure, something legal has to carry it — SCCs are the workhorse mechanism, embedded as an annex to your DPA.

How they work in practice

The Commission publishes modules for each relationship shape (controller-to-processor being the SaaS staple). You select the right module, complete the annexes — what data, what purposes, what security measures — and both parties sign. The 2021 clauses also require a transfer impact assessment (TIA): a documented evaluation of whether the destination country’s laws undermine the protections, plus supplementary measures (encryption, access controls) where needed.

SCCs vs adequacy decisions

If the destination country holds an EU adequacy decision, you don’t need SCCs at all. For the US, the Data Privacy Framework provides adequacy for certified companies — but certification is per-company, coverage has survived legal challenges nervously, and many EU customers ask for SCCs regardless as belt-and-braces. Practical SaaS posture: certify if eligible, keep SCCs in the DPA anyway.

What reviewers check

That the SCCs match your actual data flows (module and annexes, not just a signature), that sub-processor transfers are covered down the chain, and that a TIA exists. An SCC package contradicted by your architecture diagram is the finding that costs procurement weeks.

Related Terms

DPO (Data Protection Officer) — A DPO is GDPR's mandated privacy overseer — required for large-scale monitoring or sensitive-data processing. Most B2B SaaS startups don't need one yet.

Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.

Sub-processor — A sub-processor is any third party your company uses to process customer personal data — your cloud host, email provider, analytics. You must disclose them.