MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
In practice, drafting a model contract for personal data outside the EU involves selecting the appropriate Standard Contractual Clauses, carefully completing the appendices, and substantiating the transfer with a transfer impact assessment. The Standard Contractual Clauses are the model provisions established by the European Commission that serve as an appropriate safeguard under Article 46 of the GDPR. You adopt these provisions unchanged and supplement them with the details of your transfer. This ensures that the protection of personal data remains at the GDPR level, even outside the EEA.
The short answer
- First check whether an adequacy decision applies (Art. 45 GDPR); if so, a model contract is not necessary.
- Otherwise, select the appropriate module of the Standard Contractual Clauses (Art. 46 GDPR).
- Complete the attachments with the details, purposes, recipients, and security measures.
- Conduct a transfer impact assessment and record additional measures.
- Adopt the model provisions unchanged; modifying passages compromises the guarantee.
Drafting a model contract for personal data outside the EU: the first step
The first step is not the contract, but the question of whether you actually need the contract. Determine to which country you are transferring data and whether an adequacy decision exists for this under Article 45 of the GDPR. If so, you may transfer without additional safeguards. If such a decision is lacking, you need appropriate safeguards, and Standard Contractual Clauses are the usual route for this.
Next, map out the transfer. Which personal data goes to which party, for what purpose, and with what frequency? Who is the exporter and who is the importer, and in what roles do they act? This determines which module of the Standard Contractual Clauses you need. Without this overview, you cannot complete the contract correctly, as it is precisely the appendices that require this information.
The correct module and the attachments
The Standard Contractual Clauses are modular. There are modules for the different relationships between parties, for example from controller to controller or from controller to processor. Choose the module that suits your situation. An incorrect module renders the contract legally unfit, even if the wording is otherwise correct. This is one of the areas where things go wrong in practice.
The appendices are at least as important as the main text. In them, you describe the categories of personal data, the categories of data subjects, the purposes of the transfer, the retention periods, and the technical and organizational security measures. Fill these in completely and concretely. Empty or general appendices undermine the safeguard, as it is then impossible to determine exactly what is being transferred and how it is secured.
Conduct the transfer impact assessment
Following the Schrems II ruling of 2020, signing Standard Contractual Clauses is no longer sufficient on its own. For each transfer, you must assess whether the third country offers adequate protection in practice, particularly against access by government authorities and intelligence services. This assessment, the transfer impact assessment, must be documented in writing. You consider the legislation in the third country, the nature of the data, and whether the importer can comply with the clauses in practice.
If you conclude that the level of protection is insufficient, take additional measures. Consider strong encryption where the key remains within the EEA, pseudonymisation, or contractual and organisational safeguards. Document which measures you have taken and why they are sufficient. This documentation is your accountability to the Dutch Data Protection Authority and the data subjects.
Alignment with the processor agreement
A model contract for data transfer rarely stands alone. Often, the importer is also a processor, in which case you additionally need a data processing agreement pursuant to Article 28 of the GDPR. The Standard Contractual Clauses in some modules already contain processor agreements, but check whether all required topics are covered. Ensure that the data transfer contract and the data processing agreement align and do not contradict each other.
A software company uses a hosting provider in a country without an adequacy decision. The company enters the Standard Contractual Clauses in the controller to processor module, completes the appendices with the data and security measures, and conducts a transfer impact assessment. Because the hosting provider is also a processor, it is verified whether the processor agreements are complete. In this way, the documents together form a cohesive whole rather than being separate pieces.
Honest recommendation
You don't always have to build it from scratch yourself. If you transfer to a country with an adequacy decision, or if your supplier provides completed Standard Contractual Clauses and a Data Processing Agreement as standard, you can manage perfectly well with ready-made model clauses and a careful review of the appendices. It becomes a custom job as soon as you transfer sensitive data or large volumes to a country without an adequacy decision. In such cases, selecting the right module and conducting a sound transfer impact assessment can be difficult to ensure conclusively on your own. In those instances, have it drafted or reviewed, as a deficient transfer can lead to enforcement action.
Want to read more? View the model contract for personal data outside the EU on our contracts page, first read what a model contract for personal data outside the EU is , and see what it costs to have a model contract for personal data outside the EU drawn up .
Frequently Asked Questions
Check whether an adequacy decision applies to the destination country (Art. 45 GDPR). If so, you may transmit without additional safeguards and a standard contract is not necessary. If such a decision is missing, you need appropriate safeguards, usually via Standard Contractual Clauses.
The module that fits the relationship between the parties, for example from controller to controller or from controller to processor. An incorrect module renders the contract legally unfit, even if the text is otherwise correct.
You adopt the core provisions of the Standard Contractual Clauses unchanged; modifying them affects the guarantee. You do, however, complete the appendices and may add supplementary, non-conflicting agreements. The approval by the European Commission applies specifically to the unchanged model text.
The categories of personal data and data subjects, the purposes of the transfer, the retention periods, and the technical and organizational security measures. Fill these in fully and specifically; empty or general attachments undermine the safeguard because it is not established what is being transferred.
Often, yes. Since the Schrems II ruling in 2020, you must assess for each transfer whether the third country offers sufficient protection in practice. You record this assessment in writing and, if the level of protection falls short, you take additional measures such as encryption or pseudonymization.
If the importer is also a processor, you need a data processing agreement pursuant to Article 28 of the GDPR. Some modules of the Standard Contractual Clauses already contain processor agreements; check whether all required topics are covered and whether the documents align with each other.
By selecting the correct legal basis, completing the appendices in full, and documenting the transfer impact assessment with any additional measures. This documentation constitutes your accountability to the Dutch Data Protection Authority and parties involved in an audit.