To undertake

Drafting a model contract for personal data outside the EU: this should be included

Drafting a model contract for personal data outside the EU? Read which components should be included, common mistakes, and when to consult a lawyer.

Published on August 23, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

In practice, drafting a model contract for personal data outside the EU involves selecting the appropriate Standard Contractual Clauses, carefully completing the appendices, and substantiating the transfer with a transfer impact assessment. The Standard Contractual Clauses are the model provisions established by the European Commission that serve as an appropriate safeguard under Article 46 of the GDPR. You adopt these provisions unchanged and supplement them with the details of your transfer. This ensures that the protection of personal data remains at the GDPR level, even outside the EEA.

Drafting a model contract for personal data outside the EU with the key components

The short answer

  • First check whether an adequacy decision applies (Art. 45 GDPR); if so, a model contract is not necessary.
  • Otherwise, select the appropriate module of the Standard Contractual Clauses (Art. 46 GDPR).
  • Complete the attachments with the details, purposes, recipients, and security measures.
  • Conduct a transfer impact assessment and record additional measures.
  • Adopt the model provisions unchanged; modifying passages compromises the guarantee.

Drafting a model contract for personal data outside the EU: the first step

The first step is not the contract, but the question of whether you actually need the contract. Determine to which country you are transferring data and whether an adequacy decision exists for this under Article 45 of the GDPR. If so, you may transfer without additional safeguards. If such a decision is lacking, you need appropriate safeguards, and Standard Contractual Clauses are the usual route for this.

Next, map out the transfer. Which personal data goes to which party, for what purpose, and with what frequency? Who is the exporter and who is the importer, and in what roles do they act? This determines which module of the Standard Contractual Clauses you need. Without this overview, you cannot complete the contract correctly, as it is precisely the appendices that require this information.

The correct module and the attachments

Selecting the correct module and attachments for drafting a model contract for personal data outside the EU

The Standard Contractual Clauses are modular. There are modules for the different relationships between parties, for example from controller to controller or from controller to processor. Choose the module that suits your situation. An incorrect module renders the contract legally unfit, even if the wording is otherwise correct. This is one of the areas where things go wrong in practice.

The appendices are at least as important as the main text. In them, you describe the categories of personal data, the categories of data subjects, the purposes of the transfer, the retention periods, and the technical and organizational security measures. Fill these in completely and concretely. Empty or general appendices undermine the safeguard, as it is then impossible to determine exactly what is being transferred and how it is secured.

Conduct the transfer impact assessment

Following the Schrems II ruling of 2020, signing Standard Contractual Clauses is no longer sufficient on its own. For each transfer, you must assess whether the third country offers adequate protection in practice, particularly against access by government authorities and intelligence services. This assessment, the transfer impact assessment, must be documented in writing. You consider the legislation in the third country, the nature of the data, and whether the importer can comply with the clauses in practice.

If you conclude that the level of protection is insufficient, take additional measures. Consider strong encryption where the key remains within the EEA, pseudonymisation, or contractual and organisational safeguards. Document which measures you have taken and why they are sufficient. This documentation is your accountability to the Dutch Data Protection Authority and the data subjects.

Alignment with the processor agreement

Alignment of the model contract with the data processing agreement when transferring outside the EEA

A model contract for data transfer rarely stands alone. Often, the importer is also a processor, in which case you additionally need a data processing agreement pursuant to Article 28 of the GDPR. The Standard Contractual Clauses in some modules already contain processor agreements, but check whether all required topics are covered. Ensure that the data transfer contract and the data processing agreement align and do not contradict each other.

A software company uses a hosting provider in a country without an adequacy decision. The company enters the Standard Contractual Clauses in the controller to processor module, completes the appendices with the data and security measures, and conducts a transfer impact assessment. Because the hosting provider is also a processor, it is verified whether the processor agreements are complete. In this way, the documents together form a cohesive whole rather than being separate pieces.

Honest recommendation

Legal expert discusses drafting a model contract for personal data outside the EU

You don't always have to build it from scratch yourself. If you transfer to a country with an adequacy decision, or if your supplier provides completed Standard Contractual Clauses and a Data Processing Agreement as standard, you can manage perfectly well with ready-made model clauses and a careful review of the appendices. It becomes a custom job as soon as you transfer sensitive data or large volumes to a country without an adequacy decision. In such cases, selecting the right module and conducting a sound transfer impact assessment can be difficult to ensure conclusively on your own. In those instances, have it drafted or reviewed, as a deficient transfer can lead to enforcement action.

Want to read more? View the model contract for personal data outside the EU on our contracts page, first read what a model contract for personal data outside the EU is , and see what it costs to have a model contract for personal data outside the EU drawn up .

Frequently Asked Questions

What is the first step in drafting?

Check whether an adequacy decision applies to the destination country (Art. 45 GDPR). If so, you may transmit without additional safeguards and a standard contract is not necessary. If such a decision is missing, you need appropriate safeguards, usually via Standard Contractual Clauses.

Which module of the Standard Contractual Clauses do I choose?

The module that fits the relationship between the parties, for example from controller to controller or from controller to processor. An incorrect module renders the contract legally unfit, even if the text is otherwise correct.

May I amend the model provisions?

You adopt the core provisions of the Standard Contractual Clauses unchanged; modifying them affects the guarantee. You do, however, complete the appendices and may add supplementary, non-conflicting agreements. The approval by the European Commission applies specifically to the unchanged model text.

What do I put in the attachments?

The categories of personal data and data subjects, the purposes of the transfer, the retention periods, and the technical and organizational security measures. Fill these in fully and specifically; empty or general attachments undermine the safeguard because it is not established what is being transferred.

Do I need to conduct a transfer impact assessment?

Often, yes. Since the Schrems II ruling in 2020, you must assess for each transfer whether the third country offers sufficient protection in practice. You record this assessment in writing and, if the level of protection falls short, you take additional measures such as encryption or pseudonymization.

Do I need a data processing agreement in addition to the model contract?

If the importer is also a processor, you need a data processing agreement pursuant to Article 28 of the GDPR. Some modules of the Standard Contractual Clauses already contain processor agreements; check whether all required topics are covered and whether the documents align with each other.

How do I substantiate that the transmission is correct?

By selecting the correct legal basis, completing the appendices in full, and documenting the transfer impact assessment with any additional measures. This documentation constitutes your accountability to the Dutch Data Protection Authority and parties involved in an audit.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

August 23, 2026

Drafting a disclaimer of liability: this is what belongs in it

Drafting a disclaimer of liability? Read which components should be included, common mistakes, and when to hire a lawyer.

August 23, 2026

Drafting a model contract for personal data outside the EU: this should be included

Drafting a model contract for personal data outside the EU? Read which components should be included, common mistakes, and when to consult a lawyer.

August 23, 2026

Drafting an internal employee privacy statement: what belongs in it

Drafting an internal employee privacy statement? Read about the components that should be included, common mistakes, and when to hire a lawyer.

August 22, 2026

Having employer's confirmation of employee termination of employment contract drafted: costs and process

Having a lawyer draft a confirmation from the employer regarding the termination of the employment contract by the employee: what does it cost, how does the process work, and when?

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation