When Safe Harbor was struck down, standard contractual clauses became the mechanism everyone reached for. They were already in the toolkit, they had been approved by the Commission in earlier decisions, and — unlike an adequacy framework — they did not depend on a political arrangement between governments that a court could invalidate in a single judgment. That last assumption turned out to be only partly true, and the years since have turned model clauses from a piece of standard paperwork into the most operationally demanding transfer mechanism in use. Understanding why is the difference between a transfer programme that survives scrutiny and one that consists of signed documents nobody has read.
What the clauses actually do
Standard contractual clauses are a contract between the data exporter and the data importer, in a form pre-approved by the European Commission, in which the importer accepts obligations equivalent to those the exporter is under: purpose limitation, security measures, onward transfer restrictions, cooperation with supervisory authorities, and — importantly — third-party beneficiary rights allowing the individuals whose data is transferred to enforce the clauses directly. The mechanism works by importing European standards into a jurisdiction that does not otherwise apply them, through private contract. It was available before Safe Harbor fell and it remains the most widely used route today. The modern sets are modular, covering controller to processor, controller to controller, processor to processor and processor to controller. Choosing the right module is not a formality: the obligations differ, and clauses executed under the wrong module are a defect that a regulator will notice before you do. Organisations that repapered in a hurry frequently signed the controller-to-processor module for relationships that were in fact controller to controller, or vice versa, and the error is common enough to be worth auditing. A practical note that catches people out: the older sets were repealed and replaced, with a transition period for existing contracts. Any transfer still running on legacy clauses is running on an instrument that no longer provides a valid basis.
The part that makes them hard
The clauses do not bind the government of the importing country. That was always true and was treated as a technicality until the court said otherwise. The reasoning is unavoidable once stated. If the concern about a destination jurisdiction is that public authorities have disproportionate access powers and individuals have no effective remedy, a private contract between two companies cannot fix it. The importer can promise to resist unlawful requests; it cannot promise to prevail. Clauses transfer obligations between commercial parties and stop at the edge of sovereign power. What followed was the requirement that made this mechanism operationally heavy: before relying on the clauses, the exporter must assess whether the law and practice of the destination country undermine the protection they promise, and — where it does — apply supplementary measures sufficient to close the gap, or stop the transfer. That assessment is the transfer impact assessment, and it is a genuine piece of analysis: which laws apply to the importer, what access powers exist, what redress is available, what the importer has actually experienced in terms of requests, and what technical and organisational measures are in place. Supplementary measures that regulators have treated as meaningful are mostly technical — strong encryption with keys held by the exporter, pseudonymisation that the importer cannot reverse, split processing — rather than contractual. Extra promises in a contract do not add protection against a legal compulsion. The honest consequence: for some transfers, no supplementary measure works. Where the importer must access data in the clear to provide the service, encryption held by the exporter is not available, and the assessment concludes what it concludes.
Choosing between the available mechanisms
Model clauses are the default, not the only option, and the alternatives suit different situations. Binding corporate rules are internal group-wide rules approved by a lead supervisory authority, suitable for intragroup transfers in large multinationals. They are expensive and slow to obtain — typically a multi-year approval process — and durable once in place. For a group moving employee and customer data between many entities, they remove the need to paper each pair. Adequacy decisions and framework certifications are the lightest option where they apply, and they carry the political fragility discussed above. Using one does not preclude having clauses in place as a fallback, and prudent organisations do both. Derogations — explicit consent, contractual necessity, legal claims, vital interests — are narrow, intended for occasional rather than systematic transfers, and routinely misapplied. Consent as a basis for routine employee data transfer is particularly weak given the imbalance in the employment relationship. Not transferring is the underused answer. Regional processing, local storage of identifiers with only aggregated data crossing borders, or pseudonymisation before transfer each remove the question rather than documenting it. These are more expensive to engineer and cheaper to live with.
Practical Guidance for Transfer Mechanism Review
- Confirm every transfer is on a current instrument. Legacy clauses that have been repealed are not a valid basis, and stale agreements are the most common finding in a first review.
- Check the module matches the actual relationship. Controller-to-processor clauses signed for a controller-to-controller arrangement are a defect, and both parties usually got it wrong together.
- Write a transfer impact assessment for each significant destination, not one generic document. The analysis is jurisdiction-specific and importer-specific; a template applied to everything demonstrates that no assessment occurred.
- Prefer technical supplementary measures over contractual ones. Exporter-held encryption keys and irreversible pseudonymisation change the risk; additional warranties do not.
- Map onward transfers and subprocessors, and require flow-down clauses. Your exposure sits in the layer your direct contract does not describe.
- Keep clauses in place alongside any framework certification. This converts a future invalidation from an emergency into a change of reference in your records.
- Re-run assessments when circumstances change. New destination-country legislation, a new subprocessor, a change of importer ownership, or a materially different data category all invalidate the earlier conclusion.
- Record the decision, including transfers you declined to make. Evidence of analysis is what a supervisory authority asks for, and "we assessed this and stopped" is a strong answer.
The Regional Angle
For Gulf organisations the model-clause question arises in both directions, and the inbound direction is the one that gets missed. Inbound: a European entity transferring personal data to a Gulf group — employee records to a regional shared service centre, customer data to a regional distributor, HR data to a parent company — needs a mechanism, and in most cases that mechanism is the clauses, with the Gulf entity as importer. Regional businesses on the receiving end are frequently asked to sign, sometimes without anyone internally reading the obligations they are accepting: security commitments, audit rights, subprocessor restrictions, cooperation with a foreign supervisory authority, and third-party rights for individuals. Those are real obligations, and a signature given to close a deal is enforceable afterwards. The assessment will also ask about local law: what access powers local authorities have, what redress exists, and whether the importer can lawfully resist a request. Regional entities should expect that questionnaire and be able to answer it, because an unanswered assessment stops the transfer. Outbound: local frameworks have adopted comparable structures. The UAE federal regime, Saudi Arabia's personal data protection law, and the separate DIFC and ADGM regimes each provide routes for cross-border transfer through adequacy-style determinations, contractual safeguards or specific derogations. A group transferring data from a Saudi entity to a Dubai shared service centre, or from a DIFC entity to a group platform abroad, is making a regulated transfer under local rules — not only under European ones. Practically, this means one transfer can require two mechanisms in opposite directions. Two regional specifics are worth building into any review. First, the multi-entity structure typical of Gulf groups — mainland companies, free-zone entities, a Saudi subsidiary, an offshore holding company — means intragroup flows are legally cross-border even when they feel internal, and each pair needs papering. Binding corporate rules or an intragroup agreement incorporating the clauses is usually cheaper than bilateral documents once the entity count passes a handful. Second, the categories most commonly transferred are the most sensitive ones: employee passport, visa and residency documentation, payroll data feeding wage protection submissions, and medical insurance records. Those flows run to regional service centres, PRO and government-relations providers, insurers and payroll bureaux — a chain of processors that very few organisations have mapped.
The objection worth taking seriously
The strongest criticism is that the whole apparatus produces documentation rather than protection. A transfer impact assessment written by a mid-sized company's counsel does not change what a foreign intelligence service can compel. The clauses' third-party beneficiary rights are theoretically enforceable and practically almost never exercised. Supplementary measures are frequently recorded as "encryption in transit and at rest" — which addresses interception and stolen media, not lawful compulsion of the importer. And the great majority of transfers subjected to this analysis face no realistic risk of state access at all, while the handful that genuinely do are conducted by parties with the resources to structure around it. The cost falls unevenly. Large platforms absorbed the compliance overhead and continued; smaller organisations spent disproportionate effort producing assessments for routine vendor relationships. What survives the criticism is narrower but real. The assessment obligation forced organisations to find out where their data actually goes, which is the first genuinely useful output of most privacy programmes. It made processing location an architectural decision rather than an accident. And it created commercial pressure that produced regional processing options — including the Gulf cloud regions that now let local organisations avoid the question entirely for sensitive workloads. The paperwork is the cost; the visibility and the architecture are the return. Treat the documentation as proportionate hygiene and spend the real effort on knowing your flows and reducing the ones that do not need to exist.
Common Questions
Are clauses enough on their own?
No. They are a valid mechanism only when accompanied by an assessment of the destination jurisdiction and, where required, supplementary measures. Signed clauses with no assessment behind them are the most common gap regulators find.
How detailed does a transfer impact assessment need to be?
Proportionate to the sensitivity and volume of the data and the risk profile of the destination. A short, specific, dated document naming the applicable laws, the importer's experience of requests, and the measures applied is far more defensible than a long generic template used for every vendor.
When are binding corporate rules worth the effort?
When intragroup transfers are numerous, ongoing and across many entities — which describes most multinational groups and many regional groups with several jurisdictions. The approval process is long, so the decision is really about whether the structure will still exist in three years.
How do AI vendors change this review?
They add a processor category that most transfer registers were built before. Prompts containing personal data cross borders to model providers and their subprocessors; logs, evaluation sets and fine-tuning corpora may be retained elsewhere; and embeddings derived from personal data are a transfer that no inventory records. The assessment questions to ask are specific: where inference runs, which subprocessors are involved, what is retained and for how long, whether your data trains anything, and whether deletion propagates to derived artefacts. Where the answers are unsatisfactory, the supplementary measure that actually works is not a contractual promise — it is not sending the personal data in the first place.
Transfer Mechanism Review — signed clauses without a destination assessment are paperwork, not a legal basis, and that distinction is exactly what a regulator will test.
