Free tool

Which transfer mechanism? SCC module picker and adequacy checker

Answer five questions about a data flow and get the GDPR route for it: no transfer at all, an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses with the right module. The tool also tells you when a transfer impact assessment is expected and where Article 49 fits in.

Published 7 October 2026 · Sources checked 7 October 2026

A university that picks a tool for its own teaching, research or administration is normally the controller.

A software vendor that only processes data on your instructions is a processor. A partner that uses the data for its own purposes is a controller.

Remote access from another country (for example vendor support staff) counts too. Pick the country of each recipient and run the tool once per flow.

For example sub-processors, hosting providers, support teams or affiliates in other countries.

Runs entirely in your browser. Nothing you select is stored or sent anywhere.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

How the tool decides

Chapter V of the GDPR works as a sequence. The tool follows the same order a DPO would:

  1. Is there a transfer at all? If the recipient is in the EU or the wider EEA (Iceland, Liechtenstein and Norway), Chapter V does not apply. You still need a data processing agreement under Article 28 if the recipient is your processor.
  2. Is there an adequacy decision? Under Article 45, data can flow to a country, territory or international organisation that the Commission has found adequate, without any further transfer tool. The EDPB confirms that no further steps from its transfer recommendations are needed in that case, although you must keep track of whether the decision is revoked or invalidated.
  3. For the United States: is the organisation on the Data Privacy Framework List? The US adequacy decision only covers organisations included in that list.
  4. Otherwise, which Article 46 tool? For most university vendor contracts that means the 2021 standard contractual clauses, with the module chosen by the roles of the two parties.
  5. Transfer impact assessment. When you rely on SCCs, Clause 14 and the EDPB's six-step roadmap apply.
  6. Article 49 derogations only for occasional, specific situations, never as the default route for a vendor contract.

Adequacy decision countries list (checked 7 October 2026)

The European Commission's adequacy page lists the following on 7 October 2026. Recent changes are a decision for the European Patent Organisation (15 July 2025), renewed decisions for the United Kingdom (December 2025), a decision for Brazil (26 January 2026) and the conclusion of the first review of the Republic of Korea decision (23 July 2026).

Country, territory or organisationScope noted by the Commission
Andorra, Argentina, Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, UruguayNo limitation shown on the overview page; check the individual decision
BrazilDecision of 26 January 2026, adopted alongside Brazil's own adequacy decision for the EU
CanadaCommercial organisations only
JapanFirst periodic review report published 4 April 2023
Republic of KoreaFirst review concluded 23 July 2026; the decision continues
United KingdomUnder the GDPR and the Law Enforcement Directive, renewed in December 2025
United StatesCommercial organisations participating in the EU-US Data Privacy Framework
European Patent OrganisationInternational organisation, decision of 15 July 2025

Every country not on this list (for example India, China, Australia or Singapore) is a third country without adequacy, so a transfer there needs an Article 46 tool such as SCCs.

SCC modules explained

Commission Implementing Decision (EU) 2021/914 contains one set of clauses with four modules. You pick the module from the roles of the exporter and the importer, and you can combine modules in one contract when a vendor plays different roles for different data.

ModuleExporter to importerTypical university example
Module 1Controller to controllerSharing student data with a partner university outside the EEA that uses it for its own exchange programme
Module 2Controller to processorA survey, transcription or learning platform hosted or supported from outside the EEA
Module 3Processor to processorYour EU vendor passing data to its own sub-processor outside the EEA
Module 4Processor to controllerYour institution acts as processor for a non-EEA controller and returns the data to it

Two details matter in practice. Onward transfers are governed by Clause 8.7 in Module 1 and Clause 8.8 in Modules 2 and 3, and Clause 9 sets the rules on using sub-processors in Modules 2 and 3. And the decision itself says the clauses are meant for importers whose processing is not already subject to the GDPR: Article 1 refers to importers "whose processing of the data is not subject to that Regulation". The Commission's SCC page says separate clauses for importers directly subject to the GDPR are still being developed.

When you need a transfer impact assessment

A transfer impact assessment (TIA) is the documented check that the law and practice of the destination country do not stop the importer from honouring the clauses. Clause 14 of the SCCs requires both parties to warrant that they have no reason to believe local laws prevent compliance, taking into account the specific circumstances of the transfer, the laws and practices of the destination and any additional safeguards. Clause 14 applies to Modules 1, 2 and 3, and to Module 4 only where the EU processor combines the data it received with personal data it collected in the EU.

EDPB Recommendations 01/2020 (version 2.0, adopted 18 June 2021) describe six steps:

  1. Know your transfers, including onward transfers and remote access.
  2. Identify the transfer tool you rely on.
  3. Assess whether the tool is effective in light of the destination's law and practice.
  4. Adopt supplementary measures where needed (technical, contractual or organisational).
  5. Take any formal procedural steps the measures require.
  6. Re-evaluate at appropriate intervals.

If no supplementary measure can bring the protection up to the EU standard, the EDPB says the transfer must be avoided, suspended or ended.

The EU-US Data Privacy Framework

Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 finds that the United States ensures an adequate level of protection for data transferred to organisations included in the Data Privacy Framework List maintained by the US Department of Commerce. Three practical points follow:

Article 49 derogations: the exception, not the rule

Article 49 allows a transfer without adequacy or appropriate safeguards only on narrow grounds, such as explicit informed consent, necessity for a contract with the data subject, important reasons of public interest or legal claims. The EDPB stresses that derogations are exceptional and must not become the rule. For public universities there is an extra limit: Article 49(3) says explicit consent, the two contract grounds and the compelling legitimate interests ground do not apply to activities carried out by public authorities in the exercise of their public powers.

Validemic's analysis
For a recurring vendor contract, a derogation is almost never the right answer. If adequacy and SCCs both look unworkable, the usual options are a different vendor, EU-only hosting and support, or strong technical measures such as encryption with keys held by the university.

Common mistakes we see in vendor reviews

Sources

All sources retrieved 7 October 2026.

  1. Regulation (EU) 2016/679 (GDPR), Articles 28, 44 to 49, EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  2. European Commission, Adequacy decisions: commission.europa.eu, adequacy decisions
  3. Commission Implementing Decision (EU) 2021/914 on standard contractual clauses, EUR-Lex: eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng
  4. European Commission, Standard contractual clauses (SCC): commission.europa.eu, SCC page
  5. Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework, EUR-Lex: eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng
  6. US Department of Commerce, Data Privacy Framework List: dataprivacyframework.gov/list
  7. EDPB, Recommendations 01/2020 on measures that supplement transfer tools, version 2.0: edpb.europa.eu, Recommendations 01/2020
  8. EDPB, Guidelines 2/2018 on derogations of Article 49: edpb.europa.eu, Guidelines 2/2018

About this tool

We built this tool from the legal texts and guidance listed above, read on 7 October 2026. The adequacy list is fixed in the page and was taken from the Commission's adequacy page that day; adequacy decisions are adopted, renewed and reviewed over time, so check the Commission page for anything newer. The tool gives a starting point for your own assessment and is not legal advice. Your contract, the vendor's sub-processors and the data involved can change the answer. If you spot an error or a change, please contact us and we will correct it.

Frequently asked questions

Which SCC module should a university use with a cloud vendor?

In most vendor contracts the university decides why and how the data is processed (controller) and the vendor processes it on the university's behalf (processor), so Module 2, controller to processor, is the usual choice. If the vendor uses the data for its own purposes as an independent controller, Module 1 applies to that flow.

Do I need SCCs if the country has an adequacy decision?

No. Article 45 GDPR allows transfers to a country with an adequacy decision without any specific authorisation, and the EDPB says no further transfer steps are needed in that case. You still need a data processing agreement under Article 28 if the recipient is your processor, and you should watch for changes to the decision.

Is a transfer impact assessment always required?

It is expected whenever you rely on an Article 46 tool such as SCCs. Clause 14 of the 2021 SCCs requires the parties to warrant that local laws do not prevent compliance and to document that assessment, and EDPB Recommendations 01/2020 set out the six steps. It is not needed for transfers covered by an adequacy decision.

Which countries have an EU adequacy decision in 2026?

On 7 October 2026 the European Commission lists Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (commercial organisations participating in the EU-US Data Privacy Framework), Uruguay and the European Patent Organisation.

Can a public university rely on consent to transfer data?

Article 49(3) GDPR says explicit consent, the two contract derogations and the compelling legitimate interests derogation do not apply to activities carried out by public authorities in the exercise of their public powers. Derogations are exceptions in any case, so a planned, repeated vendor transfer should rest on adequacy or SCCs.

Are all US vendors covered by the Data Privacy Framework?

No. The adequacy decision covers transfers to organisations that are on the Data Privacy Framework List kept by the US Department of Commerce. Check the vendor's own entry on dataprivacyframework.gov before relying on it; otherwise use SCCs.