[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-standard-contractual-clauses::en":3,"gloss-cluster-standard-contractual-clauses::en":20,"gloss-next-standard-contractual-clauses::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"standard-contractual-clauses","security","Standard Contractual Clauses (SCCs)","Standard contractual clauses are template contract terms, adopted by the European Commission, that provide a legal basis for transferring personal data out of the European Economic Area to a country that has not received an adequacy decision. They are the mechanism most SaaS vendors rely on when EU customer data is processed by infrastructure or staff outside the EEA, and they appear as an annex or incorporated module inside the data processing agreement rather than as a separate contract. The clauses are pre-approved and cannot be modified in substance — a vendor may complete the annexes describing the transfer, the parties and the safeguards, but altering the operative terms invalidates them. For a buyer, three things follow. First, the presence of SCCs is a yes-or-no compliance checkbox but not the whole answer: the current framework also expects a transfer impact assessment, a documented view of whether the destination country's laws would undermine the protections the clauses promise, and supplementary measures such as encryption where they would. Second, the annexes are the part worth reading, because that is where the vendor lists what data is transferred, to whom, where it goes and which subprocessors are involved — the detail your own privacy filing depends on. Third, SCCs are not the only route. Where a vendor is certified under an active adequacy framework for a given country, transfers to that country may rely on it instead; those frameworks have been struck down before, which is why vendors typically keep SCCs in place as a fallback. If you process EU personal data, ask for the DPA with the SCC annexes completed, not a statement that the vendor is \"GDPR compliant\" — the second sentence is marketing and the first is a document.","SCCs are the pre-approved contract wording that makes it lawful to send EU personal data to a country without an adequacy decision.",null,[11,14,17],{"slug":12,"name":13},"data-processing-agreement","Data Processing Agreement (DPA)",{"slug":15,"name":16},"data-residency","Data Residency",{"slug":18,"name":19},"gdpr","GDPR (General Data Protection Regulation)",[21,25,29,33,36,39,42,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"bridge-letter","Bridge Letter",{"slug":37,"category":5,"name":38,"updated_at":32},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":40,"category":5,"name":41,"updated_at":24},"byok","Bring Your Own Key (BYOK)",{"slug":43,"category":5,"name":44,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":46,"category":5,"name":47,"updated_at":28},"data-classification","Data Classification",{"slug":49,"category":5,"name":50,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":52,"category":5,"name":53,"updated_at":32},"data-minimization","Data Minimization",{"slug":55,"category":5,"name":56,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":12,"category":5,"name":13,"updated_at":32}]