Standard Contractual Clauses for US SaaS Companies: What You Need When Transferring Data to EU Customers

Home  /  Data Privacy  /  Standard Contractual Clauses for US SaaS Companies: What You Need When Transferring Data to EU Customers

If your SaaS company has customers in the European Union or the European Economic Area, you are almost certainly transferring personal data from Europe to the United States. Under the General Data Protection Regulation (GDPR), that transfer is not automatically lawful. You need a legal mechanism to authorize it, and for most US SaaS companies, that mechanism is Standard Contractual Clauses.

Many US technology companies discover this requirement only when a European customer’s legal team flags it during contract review. At that point, the deal is delayed, and the legal team on the other side controls the timeline. Understanding SCCs before you need them is not just a compliance detail. It is a commercial advantage.

This guide explains what Standard Contractual Clauses are, when your SaaS company needs them, what they require, and where mistakes most often occur.

1. What Standard Contractual Clauses Are

Standard Contractual Clauses are contractual templates approved by the European Commission that provide a lawful basis for transferring personal data from the EU or EEA to countries that the Commission has not recognized as providing an adequate level of data protection. The United States does not currently hold a blanket adequacy decision for all data transfers, which means US companies generally need an approved mechanism like SCCs to receive personal data from European controllers or processors.

The current SCCs were adopted by the European Commission in June 2021 through Implementing Decision 2021/914/EU. They replaced the older model clauses that were invalidated in part by the Court of Justice of the European Union’s Schrems II ruling in July 2020. The 2021 SCCs apply in a modular format, meaning different versions apply depending on whether data is moving from a controller to a controller, a controller to a processor, a processor to a processor, or a processor to a controller.

SCCs must be incorporated into a binding agreement between the parties, and the parties cannot modify the standard clauses themselves. Supplementary provisions are permitted, but only if they do not contradict the SCCs.

2. Who Needs SCCs

A US SaaS company needs SCCs when it receives personal data from an EU or EEA entity as part of delivering its service. This applies in two common scenarios.

The first is when your European customer is a data controller under the GDPR, and they are transferring their customers’ or employees’ personal data to your SaaS platform for processing. In this case, your company acts as a data processor, and the transfer requires a Data Processing Agreement with embedded SCCs covering the controller-to-processor transfer.

The second scenario is when your company operates its own platform where European users create accounts and upload personal data, making your company the controller. If you then transfer that data to US-based servers or share it with US subprocessors, you are initiating a cross-border transfer that requires a lawful mechanism. For data flows that involve only your own platforms and infrastructure, the EU-US Data Privacy Framework may apply if your company has self-certified under it, but that framework’s ongoing legal stability is a separate consideration your counsel should assess.

Many SaaS companies do not realize they need SCCs because their customer-facing SaaS agreement does not address GDPR data transfer mechanisms at all. A SaaS agreement that is silent on SCCs does not protect you from GDPR enforcement when your European customers’ data crosses into US systems.

3. The Four SCC Transfer Modules and Which One Your SaaS Company Needs

The 2021 European Commission SCCs come in four modules based on the relationship between the parties involved in the transfer.

Module 1 applies to controller-to-controller transfers, where both the EU entity and the US entity independently determine the purpose and means of processing personal data. This applies to some B2B data sharing arrangements but is less common in pure SaaS relationships.

Module 2 applies to controller-to-processor transfers and is the most common module for SaaS companies. When a European business (the controller) sends its customer or employee data to your SaaS platform for processing (making you the processor), Module 2 governs the transfer.

Module 3 applies to processor-to-processor transfers, relevant when a European processor engages your SaaS platform as a subprocessor. If you provide infrastructure, analytics, or back-end processing to another processor serving EU controllers, Module 3 applies.

Module 4 covers processor-to-controller transfers, which are less common in standard SaaS arrangements but arise when a processor sends data back to a controller located outside the EU.

Identifying the correct module before you draft your Data Processing Agreement is essential. Using the wrong module or attempting to combine modules incorrectly undermines the legal validity of your transfer mechanism.

4. What SCCs Require You to Include in Your Agreement

Standard Contractual Clauses impose specific obligations on both the data exporter (the EU entity) and the data importer (your US SaaS company). These obligations become part of your customer contract once the SCCs are incorporated.

As the data importer, you must process the transferred data only for the specific purposes defined in the agreement, maintain appropriate technical and organizational security measures, cooperate with data subject requests including access, deletion, and correction requests, notify the data exporter promptly if you receive a binding legal request from a US government authority to access the personal data, and refrain from using the data in ways that would conflict with the data exporter’s instructions.

You are also required to conduct a Transfer Impact Assessment (TIA) before finalizing SCCs. A TIA evaluates the legal framework of the country where the data importer is located, specifically whether that country’s laws allow government authorities to access the transferred data in ways that would undermine the protections the SCCs provide. For transfers to the US, the TIA must assess US surveillance laws including FISA Section 702 and Executive Order 12333 and document what supplementary measures you have implemented to address identified risks.

5. Supplementary Measures After Schrems II

The CJEU’s July 2020 Schrems II ruling invalidated the EU-US Privacy Shield and established that SCCs alone are not sufficient if the legal framework of the destination country undermines their protections. The European Data Protection Board issued its Recommendations 01/2020 on supplementary measures in November 2020 (updated in June 2021), identifying technical, contractual, and organizational steps data importers must implement alongside SCCs.

Technical supplementary measures include end-to-end encryption where your company holds the decryption keys rather than a third party, pseudonymization of data before transfer, and access controls that prevent unauthorized access to plaintext personal data. Contractual supplementary measures include provisions requiring you to notify the European customer immediately if you receive a US government data request, a commitment to challenge overbroad government requests through all available legal remedies, and transparency reporting.

Not every technical measure is feasible for every SaaS architecture. The TIA process requires you to document which measures you can implement and why any that you cannot implement do not create unacceptable risk given the specific data categories transferred and the nature of the processing.

6. Common Mistakes US SaaS Companies Make With SCCs

The most common mistake is treating SCCs as a boilerplate addendum that can be pasted into a contract without review. SCCs require completion of specific annexes that identify the parties, describe the data processing activities, list data categories transferred, identify the technical and organizational measures in place, and specify subprocessors. Leaving these annexes blank or vague renders the SCCs legally inadequate.

The second common mistake is failing to update SCCs when the service or processing activities change. If your SaaS platform adds new features that involve new categories of data or new subprocessors, the SCCs attached to your customer agreements may no longer accurately reflect the actual transfer. GDPR enforcement actions have flagged this discrepancy specifically.

The third mistake is not including a subprocessor management process in the SCCs. Under the 2021 module structure, you must either list all subprocessors in the annex or provide a mechanism for notifying the controller of subprocessor changes. Enterprise EU customers will require the ability to object to new subprocessors before they are added.

7. How a Technology Lawyer Helps You Implement SCCs Correctly

SCCs require legal analysis, not just document assembly. A technology attorney who understands cross-border data transfers can identify which module applies to your specific business model, draft the annexes with sufficient specificity to satisfy GDPR supervisory authority expectations, structure your subprocessor notification process, review your TIA and help you document it in a defensible way, and integrate the SCCs into your customer-facing SaaS agreement in a way that does not conflict with your other contractual protections.

Getting SCCs wrong creates enforcement risk under the GDPR, which authorizes fines of up to 4% of global annual turnover or EUR 20 million for violations of its data transfer requirements, whichever is higher. It also creates deal friction, because sophisticated EU customers will spot inadequate SCCs during contract review and require renegotiation before signing.


Frequently Asked Questions

Do I need SCCs if my SaaS company uses the EU-US Data Privacy Framework?
If your company has self-certified under the EU-US Data Privacy Framework and your data transfers fall within its scope, you may be able to rely on the Framework instead of SCCs for those transfers. However, the Framework does not cover all data transfers, and its legal status remains subject to legal challenge in European courts. Many practitioners recommend implementing SCCs as a backup mechanism even where the Framework applies.

Can I use the old 2010 model clauses instead of the 2021 SCCs?
No. The transition period for using the old model clauses ended on December 27, 2022. Any contracts still relying on the 2010 SCCs for cross-border data transfers are no longer compliant with GDPR, and those transfers lack a valid lawful mechanism. You should replace them with the 2021 SCCs.

What is a Transfer Impact Assessment and do I really need one?
A TIA is a documented analysis of whether the legal framework of the destination country (in this case, the US) allows government access to transferred data in ways that undermine the SCC protections. European Data Protection Authorities expect organizations transferring data to conduct and document TIAs. Skipping a TIA is a compliance gap that enforcement authorities have specifically flagged in enforcement actions against US companies.

Do SCCs replace my Data Processing Agreement?
No. SCCs address the cross-border transfer mechanism. A Data Processing Agreement addresses the processor obligations required under GDPR Article 28 when a controller engages a processor. In most SaaS relationships, you need both: a DPA with embedded SCCs, where the SCCs form an annex or schedule to the DPA.

What happens if a European customer demands SCCs and I do not have them?
Without SCCs or another valid transfer mechanism, you cannot lawfully receive personal data from EU or EEA entities under GDPR. European customers’ legal teams will refuse to finalize contracts that lack a compliant transfer mechanism, or they may require you to process data on EU-based servers. The commercial risk of not having SCCs ready is lost European deals and delayed contract timelines.

Conclusion

Standard Contractual Clauses are not optional compliance paperwork for US SaaS companies with European customers. They are the contractual mechanism that makes your service lawfully accessible to the EU market. Getting them right requires more than inserting a template, and getting them wrong risks both regulatory enforcement and lost enterprise deals.

If you need your SaaS agreements and data transfer mechanisms reviewed by a technology lawyer who understands GDPR’s cross-border requirements, contact Hansen Tong at TOSLawyer.com. The goal is documentation that satisfies European customers and holds up when enforcement authorities take a closer look.


Comments are closed.