Reading a DPA
What are standard contractual clauses (SCCs)?
Standard contractual clauses (SCCs) are contract terms written by the European Commission. When a company sends personal data from the EU to a recipient outside the GDPR’s reach, the parties can sign these terms to meet the GDPR’s transfer rules. Everything below is quoted from the official text on the date shown.
What the decision says they do
The standard contractual clauses set out in the Annex are considered to provide appropriate safeguards within the meaning of Article 46(1) and (2)(c) of Regulation (EU) 2016/679 for the transfer by a controller or processor of personal data processed subject to that Regulation (data exporter) to a controller or (sub-)processor whose processing of the data is not subject to that Regulation (data importer).
Commission Implementing Decision (EU) 2021/914, Article 1(1) — official text · read September 30, 2026
The GDPR names them as one of the ways to make a transfer lawful:
The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by: … (c) standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2);
GDPR Article 46(2)(c) — official text · read September 30, 2026
Four modules, one for each pair of roles
The clauses come in modules. The parties pick the one that matches who is the controller and who is the processor. A company using an AI vendor to process its customers’ data is usually in Module Two.
- MODULE ONE: Transfer controller to controller
- MODULE TWO: Transfer controller to processor
- MODULE THREE: Transfer processor to processor
- MODULE FOUR: Transfer processor to controller
Module titles as the Annex to Decision (EU) 2021/914 gives them, read September 30, 2026.
Clause 9, and the blank that vendors fill in
Clause 9 governs sub-processors. The parties choose one of two options, and both leave the period blank:
OPTION 1: SPECIFIC PRIOR AUTHORISATION The data importer shall not sub-contract any of its processing activities performed on behalf of the data exporter under these Clauses to a sub-processor without the data exporter’s prior specific written authorisation. The data importer shall submit the request for specific authorisation at least [Specify time period] prior to the engagement of the sub-processor, together with the information necessary to enable the data exporter to decide on the authorisation.
Standard contractual clauses, Clause 9(a), Module Two, Option 1 — official text · read September 30, 2026
OPTION 2: GENERAL WRITTEN AUTHORISATION The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least [Specify time period] in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s).
Standard contractual clauses, Clause 9(a), Module Two, Option 2 — official text · read September 30, 2026
“[Specify time period]” is where a vendor’s notice window comes from. Vendors write their own number into their DPAs:
Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting privacy@openai.com.
OpenAI — https://openai.com/policies/data-processing-addendum/ · read September 30, 2026 · snapshot 16626fe4e570
Customer may object to the Processing of Customer’s Personal Data by the New Sub-Processor, for reasonable and explained grounds, by providing a written objection to [email protected] within 5 business days following Gong’s written notice to Customer of the intended engagement with the New Sub-Processor.
Gong — https://gong.io/legal/data-processing-addendum · read August 31, 2026 · snapshot cab59af09f81
We quote the period from 70 AI vendors’ agreements on notice windows. What a sub-processor is and what a DPA is have their own pages.
Common questions
- What are standard contractual clauses?
- Contract terms adopted by the European Commission that, when used, provide appropriate safeguards for transferring personal data to a recipient whose processing is not subject to the GDPR. The current set is in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- What are the four SCC modules?
- Module One: controller to controller. Module Two: controller to processor. Module Three: processor to processor. Module Four: processor to controller. The parties use the module that matches their roles.
- What do SCCs say about sub-processors?
- Clause 9 gives two options: specific prior authorization, where the importer asks before each sub-processor, and general written authorization, where it works from an agreed list and must inform the exporter of changes "at least [Specify time period] in advance".
- Who fills in the time period in Clause 9?
- The parties do. The template leaves it blank. In practice the period appears in the vendor's DPA, and Xither quotes it for each AI vendor agreement it holds on its notice windows page.
- Where does the GDPR allow standard contractual clauses?
- Article 46(2)(c) lists standard data protection clauses adopted by the Commission as one of the appropriate safeguards for transfers, available without specific authorization from a supervisory authority.
What this page is not
It is not legal advice. It quotes the clauses and published agreements on the dates shown; the version your contract incorporates, and how it was completed, governs.
Xither Staff Writer · reviewed September 30, 2026. Vendor clauses and counts are generated from the record when the page is served.