Transfer clauses are long because they combine legal mechanism, data-processing terms, destination risk and operational promises. Reading from page one often hides the central question: does this document describe the transfer that actually occurs?
Write the data flow in one sentence before reviewing the clause. If the contract describes a different flow, that is the first finding.
Start with the transfer map
Record who exports and imports the data, their roles, the people and data involved, purpose, originating and destination countries, storage locations, remote-access locations, sub-processors, frequency, retention and return or deletion. Include support access and onward transfers, not only the primary hosting region.
| Field | Question | Evidence |
|---|---|---|
| Parties and roles | Who exports, imports and determines purposes? | Contract, RoPA and processing instructions |
| People and data | Whose data and which categories move? | Data inventory and annex |
| Purpose and frequency | Why, how often and through which interfaces? | Architecture and service description |
| Locations and access | Where is data stored and from where can it be accessed? | Hosting, support and sub-processor records |
| Onward transfers | Which parties and countries receive data next? | Sub-processor list and transfer chain |
| Lifecycle | How long is data retained, returned or deleted? | Retention rule and exit plan |
Identify the legal route
| Regime | Possible route | Review point |
|---|---|---|
| EU GDPR | Adequacy decision, Article 46 safeguard such as 2021 SCCs, BCRs, or a limited Article 49 derogation. | Confirm the destination, scope, roles, correct route and whether destination-law assessment is required. |
| UK GDPR | Adequacy regulation, UK IDTA, UK Addendum to EU SCCs, BCRs, or a limited exception. | Use the UK instrument and complete the required transfer risk assessment or data protection test. |
| India DPDP Act | Transfers permitted subject to countries or territories restricted by Central Government notification. | Check current restrictions, sectoral localisation rules, contracts and any applicable directions or higher protections. |
| Other jurisdictions | Local adequacy, contracts, certification, consent or regulator approval depending on law. | Do not assume EU SCCs automatically satisfy another country’s transfer rules. |
EU and UK exceptions for specific situations should not be treated as a convenient substitute for an appropriate recurring transfer mechanism. Confirm the conditions and document why the route fits the actual transfer.
Select the correct EU SCC module
| Module | Exporter | Importer | Typical check |
|---|---|---|---|
| 1 | Controller | Controller | Each party has independent purposes and transparency duties. |
| 2 | Controller | Processor | Processing instructions and Article 28 obligations align. |
| 3 | Processor | Processor | The upstream controller and processing chain are correctly identified. |
| 4 | Processor | Controller | The importer’s controller role and applicable GDPR scope are understood. |
Complete the annexes. Describe data, people, purposes, frequency, retention, competent authority, technical and organisational measures and sub-processors precisely. Blank or generic annexes can make a formally signed instrument operationally unreliable.
Assess destination law and practice
Where the chosen safeguard requires it, assess whether laws and practices in the destination could prevent the importer from complying with the instrument. Document the importer’s experience where relevant, the type of data and access, likely government-access scenarios, applicable safeguards and objective information used.
| Question | Evidence | Possible response |
|---|---|---|
| Could public authorities lawfully seek the data? | Applicable laws, importer input and authoritative material | Limit data, change architecture or add safeguards |
| Can the importer notify and challenge requests? | Policy, legal constraints and historical transparency | Contract commitments and escalation procedure |
| Is data intelligible to the importer or authorities? | Encryption design, key control and access model | Strong encryption or pseudonymisation with keys retained separately |
| Is access necessary for the service? | Support model, privilege and workflow | Remove standing access; use approved, logged sessions |
| Do residual risks remain? | Assessment of effectiveness and limitations | Approve, redesign, suspend or select another provider |
Read the operational clauses
| Clause area | What to confirm |
|---|---|
| Instructions and purpose | Processing is limited to documented instructions and the service purpose. |
| Security | Measures match the actual data and risk; changes cannot silently reduce protection. |
| Sub-processors | Current list, countries, advance notice, objection process and equivalent obligations. |
| Government requests | Notification where lawful, review, challenge where appropriate, minimum disclosure and records. |
| Incident response | Notification timing and content allow the exporter to meet its own deadlines. |
| Rights and cooperation | Importer supports rights, complaints, audits and regulator enquiries. |
| Audit and evidence | Relevant reports, remediation, access to information and escalation are available. |
| Return and deletion | Timeline, format, copies, backups, sub-processors and deletion confirmation. |
| Suspension and termination | Exporter can suspend transfers when safeguards cannot be met. |
| Liability and precedence | Commercial terms do not undermine mandatory clauses or practical remedies. |
Follow onward transfers
The primary hosting country is only the start. Support centres, group companies, telemetry providers, content delivery, security services and sub-processors may create additional transfers. Require the chain to use an appropriate route and equivalent protection, and maintain a current record of countries and parties.
- Receive advance notice of new sub-processors and countries.
- Assess material changes before the transfer begins.
- Record objections, remediation and decisions.
- Update the RoPA, transfer inventory, privacy notice and risk assessment.
- Verify deletion by departing sub-processors.
Apply India’s model carefully
Section 16 of India’s DPDP Act allows the Central Government to restrict transfers to notified countries or territories. The Act also preserves laws that provide a higher degree of protection or restriction, so sectoral localisation or storage duties may continue to apply.
Do not read the absence of an SCC-style mechanism as absence of diligence. Confirm current government notifications and commencement, map destination and onward access, protect the data contractually, assess security and sectoral rules, and retain evidence of the decision.
Red flags
- The contract references obsolete EU clauses or leaves the SCC module blank.
- Annexes use generic descriptions that do not match the service or data flow.
- The UK transfer uses EU SCCs without the required UK instrument.
- No transfer assessment exists where the route requires one.
- The importer will not identify sub-processors, countries or remote support locations.
- Government-access promises are absolute despite legal restrictions, or absent entirely.
- Security measures can be reduced unilaterally.
- Return and deletion omit backups, logs and sub-processors.
- Liability, governing-law or precedence wording conflicts with mandatory safeguards.
Keep a transfer evidence pack
- The approved transfer map and data-flow description.
- The mechanism decision and applicability analysis.
- Signed clauses with correct modules and completed annexes.
- The transfer risk assessment and supplementary measures.
- Current sub-processor, country and remote-access records.
- Security evidence, government-request policy and transparency information.
- Change notices, objections and approvals.
- Exit, return and deletion evidence.
References and scope
- Regulation (EU) 2016/679 (GDPR), Chapter V, Articles 44–49.
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses.
- European Data Protection Board recommendations on measures supplementing transfer tools.
- UK Information Commissioner guidance on the IDTA, UK Addendum and transfer risk assessment.
- Digital Personal Data Protection Act, 2023 (India), section 16, together with current notifications, commencement and applicable sectoral rules.
General information for practitioners, not legal advice. Transfer requirements depend on roles, destinations, scope, mechanism, sector and current government or regulator decisions. Verify official texts and obtain qualified advice for the transfer concerned.