6.2 SCCs and the EU-U.S. Data Privacy Framework
Key Takeaways
- The 4 June 2021 EU SCCs (Implementing Decision (EU) 2021/914) use four modules: controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller
- UK restricted transfers use the ICO's International Data Transfer Agreement or the UK Addendum to the 2021 EU SCCs; Switzerland recognizes the EU SCCs with Swiss adaptations
- The EU-U.S. DPF is a Commerce self-certification program; the public commitment is enforceable under FTC Act Section 5, and participating organizations appear at dataprivacyframework.gov
- The Commission's DPF adequacy decision took effect 10 July 2023; the UK Extension took effect 12 October 2023; Swiss-U.S. DPF transfers became available 15 September 2024
- As of August 2026 the DPF is still an available mechanism; Trump v. Slaughter (29 June 2026) and the EDPB's 31 July 2026 letter put it under review — they did not annul it — so keep SCCs as a fallback
SCCs and the EU-U.S. Data Privacy Framework
Once Chapter V tells you that you need a tool, the CIPP/US exam expects you to name the right tool. Two instruments dominate U.S. practice: the Commission's 2021 Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. They are not substitutes for each other in every fact pattern, and in 2026 a careful program keeps both.
The 2021 EU SCC modules
On 4 June 2021 the Commission adopted modernised transfer SCCs in Implementing Decision (EU) 2021/914. They replace the three Directive-era sets and apply to transfers by a controller or processor in the EU/EEA (or otherwise subject to the GDPR) to a controller or processor outside the EU/EEA that is not itself subject to the GDPR. Parties pick the module that matches the roles on that flow — they do not staple all four modules into every contract as decoration.
| Module | Exporter → importer | Typical U.S. fact pattern |
|---|---|---|
| Module 1 | Controller → controller | An EU retailer shares customer data with a U.S. affiliate that decides its own marketing purposes |
| Module 2 | Controller → processor | An EU controller uses a U.S. cloud or payroll processor |
| Module 3 | Processor → processor | An EU processor sub-processes to a U.S. sub-processor |
| Module 4 | Processor → controller | An EU processor returns or collects data for a non-EEA controller |
Module 2 is the everyday U.S. vendor clause. Module 3 is the sub-processor clause that must line up with the Article 28 chain. Module 1 is for independent controllers, not for a vendor you still treat as a processor. Module 4 is the least intuitive: the Commission has said it covers an EEA processor hired by a non-EEA controller, including collection in the EEA on that controller's behalf.
The 2021 clauses bake in Schrems II mechanics: the importer must notify the exporter of an inability to comply, including government-access problems; the parties must assess the destination country; and Annex II is where technical and organizational measures — the supplementary-measures layer — are scheduled. Signing the modules without completing those annexes and the TIA is not compliance.
UK IDTA / addendum and Swiss adaptations
United Kingdom transfers are not automatically covered by the EU SCC decision. After Brexit, a restricted transfer under the UK GDPR needs a UK-recognized safeguard. The Information Commissioner's Office (ICO) issued two primary tools: the standalone International Data Transfer Agreement (IDTA) and the UK Addendum to the 2021 EU SCCs. The Addendum is the practical choice when the same contract already uses the EU modules: complete the EU SCCs, then complete the Addendum tables so the clauses work as a UK safeguard. The IDTA is a free-standing UK contract (tables, optional extra-protection and commercial clauses, and mandatory clauses). Do not tell an examiner that "we signed the EU SCCs, so the UK flow is done."
Switzerland is not an EU Member State. The Federal Data Protection and Information Commissioner (FDPIC) has recognized the 2021 EU SCCs as a transfer safeguard under Swiss law if the parties adapt them (governing law, Swiss data subjects, FDPIC in place of an EU authority). A Swiss-to-U.S. flow therefore uses Swiss-adapted SCCs or, if the U.S. organization is certified, the Swiss-U.S. DPF discussed below — not a silent assumption that Decision 2021/914 applies of its own force.
How the EU-U.S. DPF works
The Data Privacy Framework program is administered by the International Trade Administration (ITA) in the U.S. Department of Commerce. Eligible U.S. organizations self-certify at https://www.dataprivacyframework.gov/ and publicly commit to the DPF Principles (Notice; Choice; Accountability for Onward Transfer; Security; Data Integrity and Purpose Limitation; Access; Recourse, Enforcement and Liability, plus supplemental principles). Participation is voluntary. Once the organization certifies, effective compliance is compulsory.
That public commitment is enforceable under U.S. law. For most commercial organizations the hook is section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) — unfair or deceptive acts or practices. Saying "we adhere to the DPF Principles" and then ignoring Choice or Onward Transfer is a Section 5 representation case, the same theory the Commission used against Safe Harbor and Privacy Shield participants. Certain air carriers and ticket agents fall to the Department of Transportation rather than the FTC. Commerce maintains the public list of active (and inactive) participants on the DPF site; an EU exporter relying on Article 45 must confirm the importer is currently certified for the EU-U.S. DPF, not merely that it once held a Privacy Shield mark.
The Commission's adequacy decision for the EU-U.S. DPF took effect 10 July 2023 (Implementing Decision (EU) 2023/1795). From that date, EEA exporters may transfer personal data to a participating U.S. organization without a separate SCC package for that certified importer. The decision does not adequacy-wash unaffiliated U.S. vendors, onward transferees that are not certified, or processing outside the self-certified scope.
Two sibling mechanisms exist. Organizations that also self-certify to the UK Extension to the EU-U.S. DPF may receive United Kingdom and Gibraltar personal data in reliance on that extension from 12 October 2023 (the UK "data bridge"). Organizations that self-certify to the Swiss-U.S. DPF may receive Swiss personal data in reliance on that framework from 15 September 2024, the date Switzerland's adequacy recognition entered into force. EU, UK, and Swiss certifications are separate boxes on the Commerce form.
The U.S. side of the adequacy file also includes Executive Order 14086 (7 October 2022) and the Data Protection Review Court, which were designed to answer Schrems II on intelligence access and redress. Those instruments matter to why the Commission granted adequacy; they do not replace self-certification or Section 5 enforceability for a commercial importer.
Current 2026 status: available, under review, not annulled
As of August 2026, the DPF remains an available Chapter V mechanism. The Commerce site is live, organizations continue to appear on the list, and neither the Commission nor the CJEU has withdrawn or invalidated the 10 July 2023 adequacy decision.
On 29 June 2026 the U.S. Supreme Court decided Trump v. Slaughter. The Court held that statutory for-cause removal protections for Federal Trade Commission commissioners are unconstitutional and that commissioners are removable at will by the President. The DPF adequacy narrative had treated FTC independence — historically, removal only for inefficiency, neglect of duty, or malfeasance — as part of the U.S. enforcement story. On 31 July 2026 the EDPB wrote to Commissioner Michael McGrath asking the Commission to closely assess the judgment's impact on the DPF. The IAPP reported that letter on 3 August 2026. NOYB has said it is preparing a CJEU challenge. None of those events is an annulment.
Teach the operational rule, not a rumor. The DPF is not invalidated. It is under review. A U.S. multinational that relies on DPF certification should keep 2021 SCCs (and a TIA) as a fallback for the same flows, because Article 46 tools remain available if the Commission amends or withdraws adequacy or a later court strikes the decision. Do not invent a 2026 CJEU judgment that does not exist.
Scenario. A Delaware SaaS company is on the DPF list for EU-U.S. and the UK Extension but never ticked Swiss-U.S. An EEA customer can use Article 45. A UK customer can use the Extension. A Swiss customer cannot use DPF adequacy until the company certifies to the Swiss-U.S. DPF; that flow needs Swiss-adapted SCCs (and a Swiss transfer assessment) in the meantime. If Slaughter later produces a Commission review, the same company should already have Module 2 papered as the fallback — not a plan to "wait and see" with no Article 46 instrument.
Exam traps
- Do not say the 2021 SCCs have only two modules, or that Module 4 "does not exist."
- Do not treat the EU SCC decision as automatically completing a UK or Swiss transfer.
- Do not say every U.S. company is on the DPF, or that a Privacy Shield legacy mark is enough in 2026.
- Do not teach that Trump v. Slaughter or the EDPB's 31 July 2026 letter annulled the DPF.
Which set is the four modules of the 4 June 2021 EU Standard Contractual Clauses?
As of August 2026, what is the accurate CIPP/US statement about the EU-U.S. Data Privacy Framework after Trump v. Slaughter?
How does a U.S. organization's public commitment to the Data Privacy Framework Principles become enforceable in the United States?