Commission Implementing Decision (EU) 2021/914 on standard contractual clauses
- Document
- 4 June 2021
- Event
- 4 June 2021
- Retrieved
- 16 September 2026
The workload
A solo founder sending EU or UK personal data to a US-based vendor — a support desk, an email platform, an analytics service — needs a legal basis for that transfer under GDPR, and the practical option for most small operators is signing a standard set of contractual clauses with the vendor rather than negotiating a bespoke agreement. Verified: the European Commission's own Implementing Decision (EU) 2021/914, adopted 4 June 2021, replaced the clauses in place since 2001 and 2010 with a new modular template covering controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers in one document. The workload the update created was re-papering: finding every data-processing contract that relied on the old clauses and replacing them before the deadline.
What the documents show
Verified: the decision's own text repeals the two earlier Commission decisions with effect from 27 September 2021, and states that contracts already concluded under the old clauses shall be deemed to provide appropriate safeguards only until 27 December 2022, after which relying on them no longer counts as a safeguard at all. Verified: the Commission's own SCC page, retrieved 16 September 2026, still describes these as the current standard contractual clauses for data transfers between EU and non-EU countries. Signing the new clauses is necessary but the decision's own recitals say it is not automatically sufficient: the exporter must still assess whether the destination country's laws would stop the importer complying.
The operating cost
Neither document names a filing fee — the clauses are a free template, not a paid registration. Verified: the decision requires the exporter to document an assessment of the destination country's laws and practices and any supplementary safeguards, considering the specific circumstances of the transfer; for a solo founder the real cost is the time spent reviewing each vendor's location and any government-access laws reaching it, not a flat charge.
The stop condition
The decision states its own stop date for the old clauses — 27 December 2022, after which reliance on them no longer satisfies Article 46 — but sets no expiry for the 2021 clauses themselves; they remain the operative template until the Commission adopts a further replacement or a court invalidates the transfer mechanism they partly stand in for.
- Does any vendor contract moving EU or UK personal data out of the EEA still cite pre-2021 clauses that stopped counting as a safeguard after 27 December 2022?
- Has the destination country's laws been assessed and documented, not just the clauses signed?
- Does the module chosen — controller-to-processor is the common case for a SaaS vendor — actually match the relationship with each vendor?
The 2021 clauses are the template regulators currently recognize, but the decision that created them is explicit that signing paper is only part of what the safeguard requires.
Sources & reading trail
States the adoption date, the repeal of the 2001 and 2010 decisions from 27 September 2021, and the 27 December 2022 deadline for replacing old-clause contracts.
Source published: 4 June 2021 · Retrieved: 16 September 2026
Confirms the 2021 clauses remain the Commission's current standard mechanism for EU-to-third-country data transfers.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.