Standard Contractual Clauses for Transfers to Third Countries, Commission Implementing Decision (EU) 2021/914
Commission Implementing Decision (EU) 2021/914
In force since .
A cross border transfer rule binding public and private bodies.
- Criminal exposure
- No
- Private right of action
- Yes
- Obligation class
- Transfer
- Audit expectation
- on_request
- Who audits it
- Self, Independent third party
- Where the report goes
- Produced on request
As of .
What it requires
- A transfer by a controller or processor to a controller or (sub-)processor whose processing of the data is not subject to Regulation (EU) 2016/679 is treated as having appropriate safeguards under Article 46(1) and (2)(c) where the Clauses in the Annex are used (Article 1(1)); the Clauses may not be modified, except to select the appropriate Module or to add or update information in the Appendix (Clause 2(a)).
- The data exporter and the data importer warrant that they have no reason to believe that the laws and practices of the third country of destination prevent the importer from fulfilling its obligations under the Clauses, having taken due account of the circumstances of the transfer, the laws and practices of the destination and any supplementary safeguards (Clause 14(a) and (b)).
- The Parties document the assessment under Clause 14(b) and make it available to the competent supervisory authority on request (Clause 14(d)).
- The data importer notifies the data exporter promptly if it has reason to believe that it is or has become subject to laws or practices not in line with Clause 14(a); the data exporter then promptly identifies appropriate measures and suspends the transfer if it considers that no appropriate safeguards can be ensured, or if instructed to do so by the competent supervisory authority (Clause 14(e) and (f)).
- The data importer notifies the data exporter and, where possible, the data subject promptly of a legally binding request from a public authority for disclosure of the transferred data or of any direct access by public authorities, and reviews the legality of the request and challenges it where there are reasonable grounds to consider it unlawful (Clauses 15.1(a) and 15.2(a)).
- Each Party is able to demonstrate compliance with the Clauses, and the data importer keeps appropriate documentation of its processing and makes it available to the competent supervisory authority on request (Clause 8.9 in Modules One to Three).
- For Modules One to Three, the Clauses are governed by the law of an EU Member State that allows third-party beneficiary rights and disputes are resolved by the courts of an EU Member State, and a data subject may also bring proceedings in the courts of the Member State of habitual residence (Clauses 17 and 18).
Who enforces it
Enforcement body
The competent supervisory authority of each Member State, which may exercise its corrective powers under Article 58 of Regulation (EU) 2016/679 over transfers on the Clauses and informs the Commission of any resulting suspension or ban (Article 2 of the Decision).
What this law does
Article 1(1) provides that the standard contractual clauses set out in the Annex are considered to provide appropriate safeguards within the meaning of Article 46(1) and (2)(c) of Regulation (EU) 2016/679 for a transfer by a controller or processor to a controller or (sub-)processor whose processing of the data is not subject to that Regulation.
The Annex sets out the Clauses in four Modules: transfer controller to controller, controller to processor, processor to processor and processor to controller. Clause 2(a) treats the Clauses as appropriate safeguards provided they are not modified, except to select the appropriate Module or Modules or to add or update information in the Appendix.
Recital 7 states that the Clauses may be used for such transfers only to the extent that the processing by the importer does not fall within the scope of Regulation (EU) 2016/679. Under Clause 14(a) the Parties warrant that they have no reason to believe that the laws and practices of the third country of destination applicable to the processing of the personal data by the data importer prevent the data importer from fulfilling its obligations under the Clauses.
Clause 14(d) requires the Parties to document the assessment of those laws and practices and to make it available to the competent supervisory authority on request. Clause 14(f) requires the data exporter to suspend the data transfer if it considers that no appropriate safeguards can be ensured, or if instructed to do so by the competent supervisory authority or, in Module Three, by the controller.
Under Clause 15.1(a) the data importer notifies the data exporter and, where possible, the data subject promptly if it receives a legally binding request from a public authority for disclosure of the transferred personal data. Under Clause 15.2(a) the data importer reviews the legality of a request for disclosure and challenges it if, after careful assessment, it concludes that there are reasonable grounds to consider the request unlawful under the laws of the country of destination.
Article 2 requires a Member State whose competent authorities exercise corrective powers under Article 58 of Regulation (EU) 2016/679 in response to the data importer being or becoming subject to laws or practices that prevent compliance with the Clauses, leading to the suspension or ban of data transfers, to inform the Commission without delay.
Article 4(1) provides that the Decision enters into force on the twentieth day following that of its publication in the Official Journal of the European Union. Article 4(2) and (3) repeal Decision 2001/497/EC and Decision 2010/87/EU with effect from .
Article 4(4) deems contracts concluded before on the basis of Decision 2001/497/EC or Decision 2010/87/EU to provide appropriate safeguards until , provided the processing operations that are the subject matter of the contract remain unchanged and that reliance on those clauses ensures that the transfer is subject to appropriate safeguards.
When LexLint raises it
When your app profile says your app crawls the web, trains models, deploys a chatbot, sends automated outreach, processes voice recordings or processes biometric data.