
The new SCCs: more questions than answers?
The new SCCs seek to address the complex requirements laid out by Schrems II, and lay to rest some of the speculation and uncertainty following the Schrems II judgment.
Key points to note
- The new SCCs have now been published in the Official Journal of the EU and will be in force with effect from 27 June 2021. From this date, organisations subject to the EU GDPR will have a period of 18 months to transition to the new SCCs.
- Unlike before, as well as covering the traditional controller-to-controller and controller-processor scenarios, the new SCCs now provide a set of processor-to-processor and processor-to-controller clauses. This resolves a key challenge previously faced by many organisations in finally plugging the obvious gaps in the coverage of the old SCCs.
- Many of the provisions in the new SCCs have been brought more in line with the EU GDPR requirements, including the obligations on processors which now include all elements required under Article 28 GDPR.
Next steps
With that said, many questions remain unanswered. For organisations carrying out data transfers subject to the UK GDPR, the ICO intends to issue draft new SCCs for consultation this summer. In the meantime, UK organisations must continue to rely on the previous EU SCCs when undertaking data transfers that are subject to the UK GDPR. However, for organisations transferring data from both the UK and the EEA to a third country, like the United States, they may well be asking: how will these two separate forms of SCCs work together?
Given that this question and so many others remain unanswered for UK-based businesses, some may well be questioning whether it is permissible to wait until the UK version is published in final form before repapering existing contracts. However, for those businesses that are subject to the EU GDPR, it is clear that the publication of the new SCCs marks the start of a lengthy project of contract repapering, international data flow mapping and contingency planning for businesses, rather than a conclusion to the uncertainty which has prevailed for the last 12 months.
Given the uncertainty around the SCCs and the now invalid EU-US Privacy Shield (and any replacement to it, whether at a UK and/or EU level), we are seeing increasing numbers of global clients look again at submitting a Binding Corporate Rules application to protect their internal transfers, in the hope and expectation that it provides greater protection against what has become a fairly volatile area of law. We do not expect to see an end to the ongoing challenges against organisations which transfer data overseas in reliance upon the SCCs, and against the regulators which are responsible for enforcing compliance with the EU GDPR.
Appreciating the major task which now faces organisations of all scales, organisations may likely turn to their AI solutions where possible to read contracts and identify those which need to be varied to introduce the new SCCs. This could save a considerable amount of time for organisations undertaking a repapering project, and should allow businesses to significantly reduce the cost of ensuring compliance now that the new SCCs have been launched.
This article was first published by pro manchester. Louisa Williams is speaking at pro manchester’s Trailblazing Tech event on Friday 2nd July. Click here for more information or to register.
Get in touch
Get in touch
Insights & events

Cyber Security and Resilience Bill Explained | TLT

AI and the future of payments: Five Big Questions with Dave Gardner

Agentic AI and Data - Five big questions with Emma Erskine-Fox

Managing the hidden cyber security risks within your supply chain

What's mine is yours: when information is held on behalf of another under FOIA

Emerging approaches to the regulation and enforcement of AI use
Fortifying defences: ICO publishes new report on common information security mistakes and pitfalls

Employee monitoring - recent developments and enforcement decisions
Auctioning of personal data for advertising purposes: CJEU confirms rules under the GDPR
Biometric data and the impact of the ICO's latest Enforcement Notice

The results are in... The European Data Protection Board's report on the role of Data Protection Officers

Retail Agility: Navigating the AI frontier in retail

Impact of flexible working on towns and cities - the market and legal considerations

Plugging into electric vehicle opportunities | Whitepaper
TLT shortlisted for two awards at the PICCASO Privacy Awards Europe 2023

TLT hires data protection and financial services specialist as partner

TLT partner nominated for top prize at the PICCASO Privacy Awards
TLT Partner Appointed Chair of North West Fraud Forum | TLT

TLT Shortlisted for Firm of the Year at Scottish Legal Awards | TLT

TLT Wins Law Firm of the Year at Manchester Legal Awards | TLT

TLT Recognised for Two Awards at The Lawyer Awards 2022 | TLT

TLT Shortlisted for Two Manchester Legal Awards 2022 | TLT

TLT enhances public sector offering with partner hire

Retail IT systems straining to keep pace with heightened demand

A quarter of retailers say data and analytics isn't important to their business

TLT appointed to sports and arts legal services panel

Claire Graham joins board of North West Fraud Forum

TLT launches Intelligent Drafting solution powered by Clarilis

TLT continues to build data team with senior hire in London











%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi13.jpg)

















