SCCs vs BCRs
Last reviewed: · By Victor Humenhuk (CIPP/E certified)
Both are Article 46 'appropriate safeguards' for transferring personal data outside the EEA where no adequacy decision covers the destination. Standard contractual clauses are pre-approved Commission text - Decision (EU) 2021/914, structured in four modules - that any two parties can sign without a separate authorisation from a supervisory authority. Binding corporate rules are a bespoke internal code for a corporate group or a group of enterprises engaged in a joint economic activity, approved by the competent supervisory authority through the consistency mechanism, and they only cover transfers inside that group. Since Schrems II, both require a transfer impact assessment and, where the destination country's law undermines the safeguard, supplementary measures or suspension.
SCCs vs BCRs compared
| Feature | Standard contractual clauses | Binding corporate rules |
|---|---|---|
| Legal basis | Art 46(2)(c) - Commission Decision (EU) 2021/914 | Art 46(2)(b) and Art 47 |
| Who can use them | Any exporter and importer, including unrelated parties | Members of one corporate group or joint economic activity only |
| Regulatory approval | None required before signing | Approval by the competent supervisory authority via the consistency mechanism, with an EDPB opinion |
| Typical lead time | Short - a contracting exercise | Long - a drafting and regulatory approval process |
| Flexibility | The clauses cannot be amended; only the modules, optional clauses and annexes are configured | Drafted to the group's own structure within the Art 47(2) minimum content |
| Transfers to third parties | Covered, party by party, or through the docking clause | Not covered - a separate tool is needed for external recipients |
| Enforceable by data subjects | Yes - third-party beneficiary rights in the clauses | Yes - Art 47(1)(b) requires expressly conferred enforceable rights |
| Article 28 contract terms | Modules two and three also satisfy Art 28(3) | Handled separately in intra-group agreements |
| Transfer impact assessment | Required | Required |
How do the 2021 standard contractual clauses work?
The 2021 clauses replaced the earlier 2001, 2004 and 2010 sets. Contracts concluded before 27 September 2021 on the old clauses had until 27 December 2022 to be repapered, so the old clauses no longer provide a valid safeguard.
- Four modules - controller to controller, controller to processor, processor to processor, and processor to controller. You select the module that matches the actual roles.
- Docking clause - allows new parties to join an existing set, which is what makes them workable across a supply chain.
- Clause 14 - obliges the parties to warrant that they have no reason to believe the importer's local laws prevent compliance, which is the contractual hook for the transfer impact assessment.
- Annexes - the parties, the description of the transfer, and the technical and organisational measures. The clauses themselves must be reproduced unchanged, though they can sit inside a broader commercial contract.
- Scope limit - the 2021 clauses are designed for importers whose processing is not itself already subject to the GDPR under Article 3.
How do binding corporate rules get approved?
Article 47(1) sets three gateway conditions: the rules must be legally binding on and enforced by every member of the group, including employees; they must expressly confer enforceable rights on data subjects; and they must contain the minimum content listed in Article 47(2), points (a) to (n).
That minimum content includes the group structure and members, the transfers covered, the binding nature internally and externally, application of the general data protection principles, data subject rights and the complaint mechanism, acceptance of liability by an EEA-established member for breaches by members outside the EEA, transparency obligations, the role of the data protection officer, the audit and compliance programme, cooperation with supervisory authorities, and staff training.
Approval runs through the competent supervisory authority and the consistency mechanism in Article 63, with an EDPB opinion under Article 64(1)(f). Once approved, no separate transfer authorisation is needed for transfers within the scope of the rules. There are two flavours: controller BCRs for a group's own data, and processor BCRs for service providers handling client data across their global entities.
What does Schrems II require on top of either tool?
In Schrems II (C-311/18) the CJEU invalidated the Privacy Shield adequacy decision but upheld the SCC decision, on the condition that the exporter verifies, case by case, whether the law and practice of the destination country prevent the importer from honouring the clauses. The same logic applies to BCRs: a contract or an internal code cannot bind a foreign public authority.
The EDPB set out the method in Recommendations 01/2020: know your transfer, identify the transfer tool, assess the law and practice of the third country, adopt supplementary measures where needed, take any formal procedural steps, and re-evaluate at appropriate intervals. Supplementary measures may be technical, such as strong encryption with keys held in the EEA, contractual or organisational. If no measure brings the protection up to a standard essentially equivalent to that guaranteed in the EEA, the transfer must not proceed or must be suspended.
Where the destination is covered by an adequacy decision - including the EU-US Data Privacy Framework adopted on 10 July 2023, for importers that are certified and for the data categories their certification covers - no Article 46 tool and no transfer impact assessment is needed for that transfer.
Related study notes
- Providing adequate safeguards - SCCs and the transfer impact assessment
- Binding corporate rules (BCRs) for intra-group transfers
- Comparing the transfer mechanisms & the future of restrictions
- Module 7 · Appropriate safeguards: SCCs, BCRs & codes
- Binding corporate rules for processors
Frequently asked questions
Do standard contractual clauses need approval from a supervisory authority?
No. Article 46(2)(c) safeguards apply without requiring any specific authorisation because the Commission has already approved the text. That is their main practical advantage over BCRs. You do, however, have to document the transfer impact assessment and be able to produce it on request.
Can binding corporate rules cover transfers to customers or suppliers?
No. BCRs only cover transfers within the group of undertakings or the group of enterprises engaged in a joint economic activity that adopted them. Transfers to external parties need a separate mechanism, most often the SCCs.
Are the old 2010 standard contractual clauses still valid?
No. Commission Decision (EU) 2021/914 repealed the earlier decisions, and contracts still relying on the old sets had to be repapered by 27 December 2022. Note also that the UK operates its own International Data Transfer Agreement and Addendum for transfers out of the UK.
Which should a company choose?
SCCs for speed, for external vendors and for anything transactional; BCRs where a large group moves data internally at scale and wants one governance framework instead of hundreds of contracts. Many groups run both: BCRs internally and SCCs at the external boundary.
Test yourself
Try the free CIPP/E practice questions, or read the full CIPP/E study guide - free.