02/10/2024 – The recent fine imposed by the Dutch Data Protection Authority on Uber is still fresh in the memory, while the European Commission announced shortly afterwards that it will launch a public consultation for new standard contractual clauses (SCCs) in the fourth quarter of 2024. These SCCs are aimed at international transfers to controllers and processors in third countries that are directly subjected to the General Data Protection Regulation (GDPR). A situation not yet covered under current SSCs. In this blog, I explain why the new SCCs can be of great significance for your organisation.  

A quick recap, what are SCCs?  

Personal data transfers to organisations in countries outside the EEA is not simply allowed, as these countries do not have a level of protection equal or comparable to the level of protection provided by the GDRP. Therefore, appropriate safeguards must be put in place. One of these safeguards involves the conclusion of SSCs. Other transfer mechanisms include transfers based on an adequacy decision, binding corporate rules (BCRs) or specific exceptions from articles 48-49 GDPR. The SCCs, drafted by the European Commission, are publicly available model clauses that can be used by organisations to protect their transfers between EEA countries and countries outside the EEA, also known as transfers between a data exporter (based in the EEA) and data importer (based outside the EEA). 
 
The current SCCs have been in place since June 2021. Since then, there has also been a discussion about the scope of these SCCs. For instance, the SCCs were drafted for situations where the data exporter is based in the EEA or otherwise falls within the scope of the GDPR and the data importer is based outside the EEA and does not fall within this scope. SSCs thus do not seem to be appropriate for situations where the data importer falls directly under the territorial scope of the GDPR. The territorial scope means that not only data controllers based in the Union are bound by the GDPR. Indeed, article 3 GDPR states that the GDPR also applies to data controllers based outside the Union who offer goods or services to persons in the Union or monitor behaviour of persons in the Union.  
 
This has raised an important question: can the current SCCs be used as a valid transfer mechanism for situations where a data importer is itself directly subject to the GDPR? If the answer is no, can organisations not legally transfer personal data to third countries if that country does not have an adequacy decision, the organisation does not have BCRs and there is no incidental transfer?  
 
The US is subject to a special adequacy decision: the Data Privacy Framework. If you want to read more about data transfers to the US? Then click here.  

Why is this important

This question is at the heart of the highest fine ever imposed by the Dutch Data Protection Authority (‘AP’). In August 2024, the AP published the fine decision, in which it fined Uber 290 million euros for transferring personal data to its US establishment without a legally valid transfer mechanism in the period between August 2021 and November 2023. Before August 2021, Uber used SCCs for the transfer and in November 2023, Uber was certified for the Data Privacy Framework (EU-US adequacy decision). In the meantime, Uber had removed the SCCs from its intra-group data processing agreement. Should Uber have acted differently here?  
 
Uber argued that it operates a centralised IT infrastructure through which personal data is stored directly in the US. In addition, Uber B.V. and the US-based UTI are joint data controllers which would not have resulted in a data exporter transfer as described in the GDPR. What also weighed in for Uber was a Q&A from the European Commission (EC) in 2021 in which the EC had indicated that the new SCCs could not be used when the data importer is based outside the EEA and directly subject to the GDPR. Moreover, the EC had announced the development of additional SCCs for this specific scenario in 2021 and they have not been published to date.  
 
The AP rejected these arguments. It stated that joint controllers are not excluded from the transfer provisions of the GDPR. International data transfers also occur when personal data is stored directly in an IT infrastructure outside the EEA. In addition, according to the AP, Uber could not infer from a Q&A by the EC that SCCs or other transfer mechanisms would not be necessary in this case.  

Why new SCCs?

As just described, legal ambiguity has arisen that could lead to major consequences for your organisation. With these long-awaited new SCCs, the European Commission wants to set clear obligations for data importers based outside the EEA to fall under the territorial scope of the GDPR. The public consultation will start in Q4 and the draft SCCs are expected to be approved in Q2 of 2025. 

What next? 

International transfers remain a tricky issue for many organisations. However, the AP's recent fine on Uber shows the importance of putting this issue on top of the agenda. But where to start? In any case, start by answering the following questions:  

  • Which organisations or branches does your organisation transfer personal data to?
  • In which countries are these organisations or branches located?
  • Can you base these transfers on an adequacy decision?
  • If not, does your organisation have BCRs in place?
  • If not, have SSCs been concluded with these parties?
  • If so, what version of SSCs and do your contracts need to be updated now - or in the future?  
Joost van Kleef Legal Consultant

Do you want to know more?

Do you need help answering one or more of the previous questions on international data transfers? Or in drafting or updating your intra-group agreement or contracts with suppliers? Would you like to know more about recent developments in the light of the new SCCs? We would be happy to help, contact us for more information. 

Our services orContact