Standard Contractual Clauses 2021 Example

The updated CLAs allow more than two parties to comply with the terms of the contract with the CLCs and allow other controllers and subcontractors to “join the standard contractual clauses as exporters or importers of data throughout the life cycle of the contract to which they belong”. This more complex contractual “ecosystem” was not taken into account by the former CCTs. The GDPR contains specific and mandatory clauses that must be included in contracts between data controllers and subcontractors when these subcontractors process EU personal data on behalf of these data controllers. These mandatory clauses, as well as other recommended clauses, have been compiled by the European Commission to facilitate the parties in a single document: this SET One SCCs. These Set-One CCTs are primarily designed to be used for intra-EU transfers or other transfers to data processors where Set Two SCCs are not required. The above recommendations are aimed at organizations that wish to comply with the new CCAs under the GDPR. For organisations wishing to transfer data under the Data Protection Act 2018 and the UK GDPR, they must continue to rely on previous CTAs. The ICO said it will publish its own CTCs and guidelines for data transfers later in 2021. The new CTCs better reflect the requirements of the GDPR, which was adopted in May 2018, as well as the July 2020 ruling of the Court of Justice of the European Union (CJEU) in Schrems II, which invalidated the EU-US Privacy Shield with a legal opinion that also affected transfers relying on THE SCCs.

In general, the new CCTs are an improvement over previous standards, as they offer greater flexibility for long and complex processing chains and a “single point of entry that covers a wide range of transfer scenarios”. (See press release “European Commission adopts new tools for secure exchange of personal data”, 4 June 2021.) For data importers who are subcontractors, as modules two and three also include the mandatory clauses of the GDPR, they are likely to be used only for transfers outside the EU to data processors (whereas the former CTCs were previously generally attached to a separate data processing agreement (“DPA”) that included the mandatory clauses of the GDPR). Modules two and three can reduce or even eliminate the need for a separate DPA, but it is important to note that since the SCC Set One remain valid, the SCC Set Two cannot be modified and all the conditions of a current DPA you have will be replaced by the SCC in case of conflict. If your company is a data processor outside the EU, we recommend that you review and compare the DPAs you currently have with applicable third parties to understand your future obligations – especially as these new CTCs may become the new market standard. You can also extend new CTCs to meet the specific needs of your business, which is possible as long as these additions don`t contradict or distract from written CTCs. The new CBAs provide a much-needed update of the CCS and include new clauses for additional security measures and assessments for cross-border data transfers required by the Schrems II Decision. In particular, THE SCCs now require organisations to carry out a Transfer Impact Assessment (TIA) to assess the protection of personal data in importing countries. The TIA is consistent (and effectively codified) with the guidelines presented by the European Data Protection Board in December 2020 and recently updated on 21 June 2021: as expected, the updated CBAs also include strong protection of data subjects. The general responsibilities of the data exporter under the GDPR include providing information about the intention of data subjects to transfer their personal data, including the categories of personal data processed, the right to obtain a copy of the standard contractual clauses and any disclosure. In addition, with a few exceptions, data subjects are able to enforce the CCTs as third-party beneficiaries with regard to the obligations of the data exporter and the data importer. Therefore, THE SCCs should oblige the data importer to inform data subjects via a contact point and to deal promptly with complaints or enquiries.

In the event of a dispute between the data importer and a data subject exercising his or her rights as a third party beneficiary, the data subject may lodge a complaint with the competent supervisory authority or bring the dispute before the competent courts of the EU. The new CTCs entered into force on 27 June 2021, i.e. 20 days after their publication in the Official Journal of the European Union (OJ) on 7 June 2021. L 199/31). As of September 27, 2021, three months after the entry into force of the new CLAs (the “Repeal Date”), the old CLAs will be officially considered suspended and invalid for use in new agreements. After this date, all new agreements are required to use the new CCTs. All existing agreements using the current CBAs are valid until 27 December 2022, i.e. 18 months after the publication of the CLCs in the Official Journal. These will replace the old 2010 Standard Contractual Clauses.

The new clauses reflect changes implemented with the eu`s new data protection law, the General Data Protection Regulation (GDPR) of 2018. The GDPR restricts the types of personal data that can be legally transferred. The new standard contractual clauses require companies to provide their employees with more information about data transfers than before under the GDPR. “Multinational employers with employees in the EU may need to review and redistribute the data processing notices they have previously provided to employees,” Gordon confirmed. You can make changes to these EU CLAs so that they make sense in the UK context, as long as you don`t change the legal meaning of the CBAs. For example, changing the references of the old EU data protection to the GDPR of the United Kingdom, changing the references to the EU or the Member States, the United Kingdom and changing the references to a supervisory authority at the ICO. All new contracts must use the new standard contractual clauses after September 21, 2021. If, after this period, employers with employees in the EU provide data without adequate legal protection, they could face fines or legal proceedings. Otherwise, you may not make any changes to the CTCs unless they are adding additional warranties or clauses to business-related matters. You can add parties (i.e. importers or exporters of additional data) as long as they are also related to the CLCs. .

. .