Under the GDPR after Schrems II (case C-311/18), why may signing the 2021 standard contractual clauses not be enough to make a transfer lawful?
answer
- a contract binds only its parties
- essentially equivalent protection
- Clause 14 warranty and assessment
- supplementary measures or stop
- documented, shown on request
basics
~20 sUnder the GDPR, SCCs bind only exporter and importer, not the destination's authorities. After Schrems II, Clause 14 of the 2021 SCCs requires assessing local law, adding supplementary measures where needed, and suspending the transfer if protection cannot be ensured.
solid answer
~40 sStandard contractual clauses are a **contract**, so they cannot bind the public authorities of the destination country. In **Schrems II** (case C-311/18) the CJEU held that data transferred under Chapter V must keep a level of protection **essentially equivalent** to the EU's. It kept SCCs as a tool, but put the burden on the parties to check that the destination's law lets the importer comply. The 2021 SCCs (Decision (EU) 2021/914) write this into **Clause 14**. The parties warrant they have **no reason to believe** local laws and practices prevent compliance, after assessing the transfer's circumstances, those laws, and any **supplementary measures**. The assessment is **documented and available to the supervisory authority on request**. If appropriate safeguards cannot be ensured, the exporter must **suspend** the transfer and may terminate.
go deeper
Recall that SCCs are contracts between exporter and importer, and that after Schrems II they come with an assessment of the destination's laws.
Walk through Clause 14: the warranty, the three elements weighed, documentation for the authority, and the importer's duty to notify changes.
Judge which supplementary measures actually defeat the access risk for a given flow, and when the honest outcome is suspension or not transferring at all.
Set policy for which data categories may reach which destinations in the clear, given that contractual measures cannot override foreign law.
## The gap a contract cannot close An SCC is an agreement between a **data exporter** (a controller or processor subject to the GDPR) and a **data importer** in a third country. It can oblige the importer to do many things. It cannot oblige the importer's **government**. If a destination's law lets public authorities demand or reach transferred data beyond what is necessary and proportionate, the importer may be legally unable to keep its promises. **Schrems II** (CJEU, case C-311/18, 16 July 2020) is where this became law. The Court: - required that data transferred from the EU keep a level of protection **essentially equivalent** to that guaranteed in the EU; - **invalidated** the EU-US Privacy Shield adequacy decision; - left SCCs available, but made clear that the parties must verify, case by case, whether the destination's law allows that protection. Where it does not, they must add measures or stop. ## How the 2021 SCCs build this in Implementing Decision (EU) 2021/914 replaced the old clauses. It **repealed** the earlier SCC decisions with effect from **27 September 2021**. Contracts signed on the old clauses before that date were deemed adequate only until **27 December 2022**, and only if the processing stayed unchanged. The modules are One (controller to controller), Two (controller to processor), Three (processor to processor) and Four (processor to controller). **Clause 14** ("Local laws and practices affecting compliance with the Clauses") is the Schrems II clause: 1. **Warranty, 14(a).** The parties warrant they have *no reason to believe* the destination's laws and practices, including disclosure requirements and public-authority access, prevent the importer from fulfilling the clauses. Laws that respect the essence of fundamental rights and do not exceed what is necessary and proportionate for an Art. 23(1) objective are not in conflict. 2. **What they must weigh, 14(b):** - the **specific circumstances**: length of the processing chain, number of actors, transmission channels, onward transfers, type of recipient, purpose, categories and format of data, sector, storage location; - the destination's **laws and practices** relevant to those circumstances; - any **contractual, technical or organisational safeguards** supplementing the clauses. 3. **Documentation, 14(d).** The assessment is documented and made available to the competent supervisory authority on request. Practitioners call this a **transfer impact assessment (TIA)**. 4. **Change, 14(e)-(f).** The importer notifies the exporter promptly if it becomes subject to non-conforming laws or practices. The exporter then identifies measures, and **suspends** the transfer if no appropriate safeguards can be ensured or if the supervisory authority instructs it. It may terminate the contract for that processing. **Clause 15** adds duties on government access requests: notify the exporter (and, where possible, the data subject), review legality, challenge unlawful requests, and keep records. ## What "supplementary measures" means in practice The recitals of Decision 2021/914 describe them as contractual, technical or organisational measures that ensure security and confidentiality. What counts depends on what the destination's law would allow authorities to reach: | Kind | Example | What it changes | |---|---|---| | Technical | encryption where the importer never holds the keys | data reachable abroad is unintelligible | | Technical | pseudonymisation with the re-identification table kept in the EU | an access demand yields no identified individuals | | Contractual | stronger commitments on transparency and on challenging requests | better information, but it cannot override the law | | Organisational | strict need-to-know access and logging | narrows what is exposed | The limit is the point of Schrems II. Contractual and organisational measures cannot stop lawful public-authority access in the destination. If the importer must see the data in the clear and the local law's access goes beyond what is necessary and proportionate, no measure may be enough. The answer is then to **not transfer**, or to suspend. ## Two scope points often missed - **Who the clauses are for.** Under **Art. 1(1)** of Decision 2021/914, the SCCs cover transfers to an importer *whose processing of the data is not subject to* the GDPR. - **No rewriting.** Parties may put SCCs inside a wider contract and add safeguards, but nothing may contradict the clauses (recital 3). ## Why an interviewer asks this The weak answer treats SCCs as a signature-only formality. The strong answer knows that the signature starts a **continuing, documented assessment**, and that the exporter owns the decision to suspend.
- Under the 2021 SCCs, what must an importer do when it receives a binding disclosure request from a public authority?Clause 15 requires it, where possible, to notify the exporter and the data subject, review the request's legality and challenge it if there are reasonable grounds to think it unlawful, disclose only the minimum permissible, and document requests and responses for the exporter or supervisory authority. If it can no longer comply with the clauses, it must inform the exporter.
- Under the GDPR, can a supervisory authority stop a transfer that runs on valid SCCs?Yes. Art. 58(2)(j) empowers an authority to order the suspension of data flows to a recipient in a third country, and Clause 14(f) obliges the exporter to suspend when instructed. Under Art. 2 of Decision 2021/914, the Member State then informs the Commission.
saying these in an interview costs you the question
- Once the SCCs are signed, the transfer is compliant with nothing further to do.
- SCCs bind the destination country's government as well as the importer.
- The Clause 14 assessment is optional good practice, not part of the clauses.
- Contractual promises alone can always fix a conflicting third-country law.
- Pre-2021 SCC contracts remain valid indefinitely if left unchanged.