Using Standard Contractual Clauses (SCCs) Correctly
Introduction
The European Commission's Standard Contractual Clauses (SCCs) of 4 June 2021 (Implementing Decision 2021/914) are the dominant instrument for third-country transfers under Art. 46(2)(c) GDPR. For Swiss data exports to third countries without adequate protection, the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) recognised these SCCs together with the Swiss Addendum of 27 August 2021, Art. 16(2)(d) DSG in conjunction with Art. 9 DSV. Signing SCCs without tailoring them to the actual processing flow defeats both their function as a safeguard and the requirements set by Schrems II (CJEU, C-311/18, 16 July 2020).
- EU legal basis: Art. 46(2)(c) GDPR, Implementing Decision 2021/914, EDPB Recommendations 01/2020.
- Swiss legal basis: Art. 16–17 DSG, Art. 9–10 DSV, FDPIC Addendum of 27 August 2021.
- Modules: four constellations (controller-to-controller, controller-to-processor, processor-to-processor, processor-to-controller).
- Companion documents: Transfer Impact Assessment (TIA), sub-processor flow-down, docking clause.
- Risk: a breach can attract a fine of up to EUR 20 million (Art. 83(5) GDPR); in Switzerland Art. 60 ff. DSG apply.
- Deadline: legacy contracts on the 2010/2001 SCCs lost effect on 27 December 2022.
This article walks through module choice, annex completion, the Swiss Addendum and the interplay with the TIA, and lists the most frequent defects we see in advisory practice.
Module choice 1 to 4
The 2021 SCCs consist of a common body plus four modules to be chosen depending on the parties' roles. A wrong choice means the clause does not legally take effect, the transfer then occurs without a valid safeguard.
- Module 1, Controller to Controller: an EEA controller transfers to a third-country controller, e.g. intra-group between two legal entities with their own purposes.
- Module 2, Controller to Processor: the classical processing scenario, e.g. a Swiss controller and a US SaaS provider. The SCC simultaneously replaces the data-processing agreement (DPA) under Art. 28 GDPR or Art. 9 DSG, provided Annexes I.B, II and III are completed in full.
- Module 3, Processor to Processor: an EEA processor transfers to a sub-processor in a third country. Often forgotten, although the standard case in cloud setups.
- Module 4, Processor to Controller: a third-country processor returns data to an EEA controller, e.g. when a Swiss collection partner exploits a US recovery system.
Parties typically choose modules cumulatively, not alternatively. A typical contract with a global SaaS provider activates Module 2 (for the main relationship) and Module 3 (for the sub-processor chain) at the same time. In the SCC header, unused modules are struck through, and module-specific options are ticked in the clauses. Leaving all four modules to run "pro forma" creates interpretation risk in disputes.
Integrating the Swiss Addendum correctly
By communication of 27 August 2021, the FDPIC recognised the 2021 SCCs subject to specific adjustments, because the SCCs themselves only refer to the GDPR and EEA supervisory authorities. These adjustments are captured either in a separate Swiss Addendum or directly inside the annexes.
Mandatory adjustments:
- Supervisory authority: the FDPIC sits alongside or replaces the named EU supervisory authority, depending on the Swiss nexus of the processing.
- Governing law: Swiss law (in particular DSG) for purely Swiss matters; in mixed cases Swiss law is added to Annex I.C.
- Jurisdiction: Swiss court (typically the seat of the data exporter or the residence of the data subject).
- Terminology alignment: depending on the data category, "GDPR" is supplemented with "DSG"; "personal data" may include data of legal persons where DSG still protects them, relevant only in narrow exceptions since the revision.
Carrying over EU group contracts unchanged and adding only a Swiss subsidiary's signature risks losing Swiss protection altogether and creating jurisdictional disputes with the FDPIC. The FDPIC communication is published on the authority's website, following it is not optional but a precondition for the SCC qualifying as a safeguard under Art. 16 DSG.
Transfer Impact Assessment as mandatory companion
Schrems II made it clear that SCCs are not enough on their own: the data exporter must verify whether the law and practice in the destination country undermine the guarantees promised in the SCCs. EDPB Recommendations 01/2020 structure this exercise as a six-step Transfer Impact Assessment (TIA).
Six TIA steps:
- Mapping the transfer: who transfers what to whom, to which country, for what duration?
- Identifying the transfer tool: which SCC module, which additional safeguards?
- Assessing the third-country law: are there governmental access powers (in particular FISA 702, Cloud Act in the US, comparable powers in CN, IN, SA)?
- Supplementary measures: encryption with key sovereignty at the exporter, pseudonymisation, contractual transparency and notification duties, technical splitting.
- Procedural steps: where required, consultation of the FDPIC under Art. 23 DSG.
- Re-evaluation at intervals: at least annually or on legal change.
For transfers to the US, the EU-US Data Privacy Framework (Adequacy Decision of 10 July 2023) has reduced the TIA burden for certified recipients. Swiss exporters cannot directly rely on it; the Federal Council brought a Swiss-US equivalent into force by ordinance of 14 August 2024, effective 15 September 2024. For non-certified US recipients and all other third countries, the TIA remains mandatory. An undocumented TIA is a standard finding in FDPIC inquiries and triggers corrective action.
Filling the annexes properly
The SCCs only deliver their protective effect if the annexes are completed with care. Boilerplate such as "all customer data" or "all sub-processors per list" is not enough. The EDPB and FDPIC read the annexes as an operational specification, not a marketing document.
Annex I.A, Parties: full company names, addresses, contact points, role (exporter / importer), date.
Annex I.B, Description of the transfer: data categories (e.g. identification, contact, authentication, content, location data), categories of data subjects (employees, customers, suppliers), purposes, retention period, transfer frequency, nature of the processing (hosting, analytics, support, etc.).
Annex I.C, Competent supervisory authority: FDPIC for pure Swiss scenarios; EEA supervisory authority for GDPR scenarios; combined entries for mixed cases.
Annex II, Technical and organisational measures: encryption, access control, logging, backup, pseudonymisation, physical security, sub-processor management, staff training, incident response. Generic references to SOC 2 reports are insufficient, the TOMs must be readable and verifiable inside the contract.
Annex III, Sub-processors: named list with location, activity and data categories. With general authorisation: process for updates and the right to object.
An incomplete Annex II is the most frequent audit finding: key management, retention periods or precise sub-processor regions are often missing. The SCCs do not formally lose validity in this case, but their suitability as an "appropriate safeguard" is open to challenge in disputes.
Docking clause and sub-processor flow-down
The docking clause (clause 7 of the 2021 SCCs) lets additional parties join the contract at a later date without a full renegotiation. This is particularly valuable in group setups and in evolving sub-processor chains.
Operational setup:
- Accession statement: a standard form in the annex that new parties sign and that automatically becomes part of the contract.
- Consent rights: existing parties can refuse accessions that would lower the protection standard, a contractual 30-day window prevents open-ended negotiations.
- Updating the annexes: new parties are added to Annex I.A and, where relevant, Annex III.
Sub-processor flow-down (clause 9 in Modules 2 and 3): processors may engage sub-processors only with general or specific authorisation from the controller and must contractually impose the same data-protection duties on them. The most frequent trap: Swiss controllers sign a master agreement in which the processor maintains a 200-line sub-processor list, and never review it. Recommendation: a quarterly sub-processor review as a mandatory item in the privacy calendar, with sampling of the relevant third-country safeguards. Anyone who grants blanket consent and never looks again cannot rely on "good faith" in dispute, the accountability duty in Art. 7(4) DSG requires active follow-up.
Common defects in practice
In our mandates the following patterns recur, each constituting a formal or substantive SCC defect.
- Wrong module choice: Module 2 ticked even though the recipient pursues its own purposes (correct: Module 1). Consequence: instruction-binding obligations do not match the actual role.
- Outdated 2010 SCCs: contracts with US providers signed before 2021 and never refreshed. They have not been a valid safeguard since 27 December 2022.
- Missing Swiss Addendum: SCCs adopted 1:1 from EU templates; FDPIC and Swiss law absent from Annex I.C.
- Generic TIA: a single template across all third countries, with no country- or recipient-specific analysis of government access powers.
- Annex II as TOM pamphlet: a vendor marketing brochure instead of a verifiable technical specification.
- No sub-processor governance: general authorisation without an update process, list of approved sub-processors or objection rights.
- Schrems II gap: the TIA acknowledges the risk (e.g. FISA 702) but lists no concrete supplementary measures, the SCC does not "cure" the risk on its own.
Each defect is fixable in isolation; in combination they prove that the third-country transfer is unprotected, the prime attack point in FDPIC and EU supervisory enforcement.
How SIDD supports you
SIDD delivers turnkey SCC implementations for Swiss companies, from mapping the third-country transfers through the correct module choice to a complete annex set including the Swiss Addendum. Our Swiss data-protection advisory ensures that your SCCs are not just signed but operationally effective, and that the accompanying TIA matches the current EDPB Recommendations.
If you are a Swiss controller without an EU establishment but operate within the Union, we also act as your EU representative under Art. 27 GDPR and coordinate access requests and complaint handling with EU supervisory authorities. For the ongoing administration of SCCs, sub-processor lists and TIA updates, the Priverion platform offers a dedicated module for third-country transfers.
A first assessment of your current SCC landscape starts with an initial no-obligation conversation. To move straight to template or negotiation support, request a quote, we respond within one business day.
