The Standard Contractual Clauses adopted in Implementing Decision (EU) 2021/914 are the most widely used safeguard for transfers out of the European Economic Area. They are modular, and the module chosen determines what the parties owe each other. When sub-processors are involved, two provisions do most of the work: the onward transfer rules and the clauses governing how a processor may engage another processor.
This article covers what to check when your vendor relies on the clauses and its chain extends beyond it. The wider transfer sequence is in our international data transfer checklist.
Get the module right
The clauses come in four modules, and using the wrong one is a common and consequential drafting error:
- Module One: controller to controller.
- Module Two: controller to processor.
- Module Three: processor to processor.
- Module Four: processor to controller.
For a typical software purchase, where you are the controller and the vendor processes on your instructions, Module Two applies. Where you are yourself a processor for your own customers and you engage a vendor in a third country, Module Three applies, and the obligations run differently because your instructions themselves derive from your customer.
Organizations that act as both controller and processor, which is common for software companies, will need different modules for different relationships. Check which one the vendor's paperwork actually uses rather than assuming.
The annexes are the substance
The clauses are boilerplate; the annexes carry the content. Three are mandatory and all three are frequently defective:
- Annex I identifies the parties, describes the transfer, and names the competent supervisory authority.
- Annex II sets out the technical and organizational measures.
- Annex III lists the sub-processors where Module Two or Three applies with specific authorization.
Blank, template, or generic annexes are the most common defect in vendor paperwork. An Annex II that says "industry standard measures" describes nothing and cannot support the assessment the clauses require. An Annex I that does not describe the actual data categories leaves the transfer undefined.
Read the annexes first. If they are empty, nothing else in the document matters much.
Onward transfers
Clause 8.8 restricts onward transfers by the data importer to a third party outside the European Economic Area. In practice the importer may make an onward transfer only where the third party is bound by the clauses under the appropriate module, or where another Chapter V route applies, and in each case only if the processing is covered by the original instructions.
For a buyer, three checks follow:
- Does the vendor's sub-processor chain extend to entities outside the European Economic Area?
- For each, what is the onward transfer route: the clauses via docking, a separate arrangement, or an adequacy decision?
- Does the vendor commit to imposing the same data protection obligations on those entities, as Article 28(4) of the General Data Protection Regulation (GDPR) requires?
The answers are rarely in the clauses themselves. They live in the sub-processor list and the Data Processing Agreement, which is why reading those documents together matters. Our article on evaluating a sub-processor list covers what a usable list contains.
The docking clause
Clause 7 allows an entity that is not originally a party to accede to the clauses. It is optional, and vendors sometimes leave it out.
Its presence is useful where a chain grows over time, because it lets a new sub-processor join the existing arrangement without renegotiating everything. Its absence is not fatal, but it means each new entity needs its own route, and you should ask what that route is rather than assuming continuity.
Clause 14 and the chain
Clause 14 requires the parties to warrant that they have no reason to believe the laws and practices of the destination prevent the importer from fulfilling its obligations. That assessment is not limited to the importer you contract with. Where the chain extends onward, the destinations of onward transfers form part of the picture, because they are where the data actually ends up.
The European Data Protection Board's Recommendations 01/2020 set out how to approach the analysis, and our transfer impact assessment guide covers the practical method.
What changes when the chain changes
A new sub-processor in a new country can alter the onward transfer position and the Clause 14 analysis at the same time, without any change to the signed clauses. The paperwork stays valid while the facts underneath it move.
That is why the sub-processor notification mechanism matters as much as the clauses themselves. Our articles on general and specific authorization and handling an objection cover the mechanics of responding.
A checklist for review
- The correct module for the relationship, and consistent use across the documents.
- Annex I completed with real parties, real data categories, and the competent supervisory authority.
- Annex II describing measures specifically enough to test.
- Annex III present and current where specific authorization applies.
- The onward transfer position stated for each third-country sub-processor.
- The docking clause included, or an alternative route explained.
- A Clause 14 assessment that covers onward destinations, not only the direct importer.
- A commitment that sub-processors are bound by materially the same obligations.
Frequently asked questions
Do the clauses cover our vendor's sub-processors automatically?
No. The clauses bind the parties to them. Sub-processors are covered through the onward transfer provisions and the vendor's own contracts with them, which is why Article 28(4) flow-down matters.
Does an adequacy decision remove the need for the clauses?
For transfers genuinely covered by an adequacy decision, yes, and the Clause 14 assessment is not triggered. Confirm that the decision covers the specific entity and data, and track whether it remains in force.
Do we need to re-sign when a sub-processor changes?
Usually not. Well-constructed arrangements handle new sub-processors through the authorization and onward transfer provisions. What does need revisiting is your assessment, if the destination is new.
Are older clauses still usable?
The 2021 clauses replaced the earlier sets, and arrangements resting on superseded clauses should be reviewed. Treat any contract citing pre-2021 decisions as a finding.
Where DPAFlow fits in
Clause paperwork is stable; the chain it governs is not. DPAFlow checks vendor sub-processor lists, Data Processing Agreement pages, and trust-center pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts. Detected changes enter a review workflow where your team decides whether the onward transfer position or the assessment needs revisiting.
DPAFlow does not review clause drafting and does not provide legal advice. The transfer assessment module is described on the transfer impact assessment page.
This article explains a contractual instrument in general terms. It is not legal advice, and the drafting and assessment calls belong to your counsel.