Four days ago, quietly and without much coverage outside privacy circles, the transition period ended. Any new contract signed from 27 September that involves personal data leaving the European Economic Area must now use the standard contractual clauses adopted in June, not the versions that have been pasted into supplier agreements since 2001 and 2010. The second deadline is the one that should be in your planning calendar: existing contracts relying on the old clauses remain valid only until 27 December 2022, and only if the processing operations they describe have not changed. That gives fifteen months to find, assess and repaper every agreement in the estate that moves data out of Europe. Almost nobody has resourced that work, largely because the new clauses are still being discussed as a legal development. They are not. They are a contract operations problem with a hard stop.
Each event links to its supporting source. This is a selective chronology, not a performance comparison.
What actually changed
Five things matter, and only the first is widely known. The clauses are modular. There are now four modules covering controller to controller, controller to processor, processor to processor, and processor to controller. You have to select the right one and delete the rest, which sounds administrative until you notice how many real arrangements are processor to processor. If your European client's global outsourcer sends data to your operation, that is the module you need, and it is the one most often filled in wrongly. Multiple parties can join one instrument. A docking clause allows additional entities to accede to an existing set of clauses without renegotiating from scratch. For groups with a dozen legal entities across several jurisdictions, this is the most practically useful change in the entire document. The transfer assessment is now a contract term. The parties warrant that they have assessed whether the law of the destination country prevents the importer from meeting its obligations, taking account of the specific circumstances of the transfer, and they must document that assessment and make it available to the supervisory authority on request. The exercise that regulators recommended after the 2020 judgment, and that the European board finalised in June, has become something you have promised in writing to have done. Government access has its own clauses. The importer must notify the exporter if it receives a request from a public authority, challenge requests it considers unlawful, disclose the minimum permissible, keep records of what it received and what it provided, and confirm that it has no reason to believe local law prevents it from complying with these duties. Read that list slowly while thinking about a supplier in a jurisdiction with broad state access powers and statutory secrecy obligations, and you will understand why some vendors have taken months to sign. The annexes carry the weight. The clauses require a specific description of the transfer, the categories of data subjects and data, any sensitive data, the frequency, the retention period, the sub-processors and their purposes, and a genuine list of technical and organisational measures. Not a paragraph asserting industry-standard security. Actual measures. There is also a companion set, adopted the same day, for controller to processor contracts inside the Union. Many organisations need both and are conflating them, which produces a document that updates the transfer basis and leaves the processing terms stale.
Why this is an operations problem
The legal analysis for a single contract takes an hour. The estate is the difficulty. A mid-sized organisation with European exposure has somewhere between fifty and several hundred agreements that touch personal data crossing a border, and the clauses are usually incorporated by reference to a decision number in a schedule nobody has read since signature. The work is therefore inventory, triage and sequencing rather than drafting. The triage that works in practice has three buckets. Large software and cloud vendors will publish updated data processing agreements incorporating the new clauses unilaterally; accept those, record the version, and move on, because negotiating with a hyperscaler's standard terms is not where your fifteen months should go. Mid-market suppliers will need to be asked, and many will be grateful for a template. The remaining fifth of the estate is where the real effort belongs: integrators, outsourcing providers, staffing firms, marketing and analytics agencies, translation and transcription vendors, debt collection, benefits administrators and anybody handling employee data. Those are bespoke contracts, they involve onward transfers to countries you have not assessed, and they are the ones a regulator or an enterprise customer will ask about.
The annexes are the honest test
Here is the part that catches organisations out. Annex I requires an accurate description of what is transferred, to whom, how often, for how long and for what purpose. That is an extract from a record of processing activities. If your record is a spreadsheet last updated for the 2018 deadline, the annex cannot be completed truthfully, and the gap becomes visible in a document you have signed. Annex II requires the security measures actually applied to this transfer. Vendors will attempt to attach a product security page. Push back and ask for specifics: encryption in transit and at rest, where keys are held and by whom, pseudonymisation where applicable, access control and privileged access management, logging and retention of logs, deletion and return at the end of the contract, and the arrangements for sub-processors. A supplier who cannot describe those in a page is telling you something useful.
Practical Guidance for SCC Compliance Review
- Build the inventory first — every agreement involving a transfer out of the Union, with counterparty, module, destination countries and onward transfers.
- Triage into vendor-led updates, template-led updates and bespoke negotiation, and spend your effort on the third group.
- Select modules deliberately, paying particular attention to processor-to-processor arrangements in outsourcing chains.
- Use the docking clause for intra-group flows instead of papering every entity pair separately.
- Treat the annexes as the deliverable, and refuse marketing pages in place of technical measures.
- Document the transfer assessment and keep it, because you have now promised in writing that it exists.
- Ask importers directly how they would handle a government access request, and record the answer rather than relying on the signature.
- Put the December 2022 deadline in the contract renewal calendar, and refresh the clauses at renewal rather than in a single panic next autumn.
The Regional Angle
The new clauses have arrived in the Gulf at the precise moment when the region stopped being only a destination for other people's rules and started writing its own. Saudi Arabia's personal data protection law was published in the last week, and a federal data protection law for the Emirates is expected shortly. That changes the position of a regional entity signing as importer in a way that few legal teams have processed yet. Until now, a Gulf company receiving European data was simply agreeing to somebody else's framework. From next year it will be agreeing to somebody else's framework while simultaneously being a controller under a domestic regime with its own consent requirements, its own transfer restrictions, and in some readings its own localisation expectations for certain categories of data. The importer's warranty in the new clauses — that it has no reason to believe local law prevents it from complying — now requires a look at the new domestic law as well as at state access powers. Where a local rule restricts onward transfer or mandates disclosure, that is a conflict to be identified before signature, not a footnote. And because the regional laws carry transition periods running into next year, annexes signed this quarter may need revisiting once implementing regulations appear. The second observation is aimed at regional service providers, and it is the most commercially consequential thing in this article. A Gulf outsourcing, technology or shared-services business serving European clients is very often not receiving data from a controller at all. It receives data from the client's global provider, which makes the arrangement processor to processor — a module that did not previously exist in usable form and that brings obligations flowing in both directions, including a duty to pass equivalent terms down to your own sub-processors in India, the Philippines or Egypt. Regional providers who paper only the top of that chain will fail the next client audit. Those who paper the whole chain, list their sub-processors honestly and can produce a completed Annex II will win work from those who cannot, because European buyers are now asking for the documents rather than the assurance. The third is a structural point that saves real money. Regional groups move personal data internally with no instrument at all: a holding company in one emirate, an operating company in Saudi Arabia, a shared service centre in Egypt, a free zone entity that runs the group's email. Where any part of that structure touches European data, the docking clause turns what would have been a dozen bilateral agreements into one instrument that entities accede to as they are added or acquired. Set it up once, with the group's entity list as a maintained annex, and acquisitions stop triggering a fresh legal exercise each time.
The objection worth taking seriously
The strongest objection is that this is paperwork pretending to be protection. A contract between two companies cannot restrain a government, which was precisely the point the court made in 2020 when it struck down the previous transfer framework. Enforcement has fallen almost entirely on large platforms, not on mid-market firms with an imperfect annex. And a repapering programme consumes budget and legal attention that could have funded encryption, key management or access control that would actually reduce risk. There is real force in that, and anyone who thinks a signed annex protects data from a subpoena has misread the judgment. But it mistakes the nature of the requirement. The deadline is not a risk calculation; it is a validity condition. A contract that relies on the old clauses after 27 December 2022 has no transfer mechanism at all, which surfaces long before any regulator arrives — in customer questionnaires, in tender responses, in your own clients' audits, and in the warranties you have given to enterprise buyers who will have done this work and will ask whether you have. The practical exposure in 2022 is commercial, not punitive. And the exercise produces something genuinely valuable almost by accident. Completing Annex I forces an organisation to state, accurately, what personal data it sends where, how often, to which sub-processors and for how long. Most organisations cannot currently answer that, which is itself the finding. The inventory you build to satisfy a clause is the same inventory you need for a breach, an access request, a vendor exit or a decision about where to host. Do the paperwork badly and you have paperwork. Do it once, properly, with the annexes treated as the product, and you have a map that every subsequent data question can be answered from.
Common Questions
Do we need to repaper everything immediately?
No. New contracts from 27 September must use the new clauses. Existing ones have until 27 December 2022, provided the processing has not changed — and a material change to the processing removes that grace.
Which module applies to our outsourcing provider?
It depends on whether the provider receives data from you as controller or from another processor. Map the chain before choosing; the processor-to-processor module is common and frequently missed.
Does the United Kingdom use the same clauses?
No. Adequacy in June keeps European data flowing to Britain, but transfers out of the United Kingdom need a domestic instrument, and the regulator there consulted on its draft over the summer. Organisations with both footprints should expect two parallel sets of paper.
What should we expect over the next twelve months?
Expect a wave of unilateral vendor updates through this quarter and the next, most of which you should simply accept and record. Expect the United Kingdom's own transfer instrument to be finalised in the first half of next year, with its own transition timetable. Expect the first enforcement actions built on the June guidance about supplementary measures, aimed at transfers where no assessment was documented. Expect the new Gulf laws to publish implementing regulations during 2022 with their own transfer rules and deadlines, which will force a second look at annexes signed this year. And expect a visible rush next autumn as the December deadline approaches, at which point external legal capacity will be scarce and expensive — which is the argument for starting the inventory this month rather than next summer.
SCC Compliance Review — we inventory the agreements that move personal data out of Europe, select the right modules, complete the annexes with real measures, and sequence the repapering so the December 2022 deadline is uneventful.
