Home Blog SCCs vs BCRs: Which Transfer Tool Do You Need?

GDPR

SCCs vs BCRs: Which Transfer Tool Do You Need?

Posted by Kevin Yun|September 2, 2026

Standard contractual clauses are a pre-approved contract you execute between an exporter and an importer, usable the day you adopt them. Binding corporate rules are an internal data protection code that a supervisory authority must formally approve, and they only cover transfers inside your own corporate group. For essentially every SaaS company below enterprise scale, the answer is SCCs, and it is not close.

This article covers what each instrument is, the modular structure that trips people up, why BCRs are rare, how the Data Privacy Framework changes the picture, and which one your vendors are actually using.

Two Instruments, Two Very Different Costs

Both sit in Chapter V of the GDPR, which governs transfers of personal data outside the EEA, and both are what the regulation calls appropriate safeguards.

Standard contractual clauses are adopted by the European Commission under Article 46(2)(c). The current set comes from Commission Implementing Decision (EU) 2021/914 of 4 June 2021, published in the Official Journal on 7 June 2021, replacing clauses that dated from 2001, 2004 and 2010. You adopt them by signing them. No regulator approves your particular use, and no one grants you permission.

Binding corporate rules sit in Article 47. They are a set of internal policies binding on every entity in a corporate group, and they must be approved by a lead supervisory authority through the consistency mechanism, with the European Data Protection Board issuing an opinion. Approval is a formal regulatory process that typically runs to a year or more.

The practical difference follows from that. SCCs are available to anyone. BCRs are available to organisations willing to fund a long regulatory approval process, and they only help with intra-group transfers. A BCR does nothing for the transfer to your payment processor.

The Modular Structure Is Where People Go Wrong

The 2021 clauses are not a single document. They contain four modules and you use the one matching the relationship:

Module One — controller to controller. Module Two — controller to processor. Module Three — processor to processor, which is what applies when you are a processor for your customer and you engage a sub-processor outside the EEA. Module Four — processor to controller.

Picking the wrong module is a real and common error, and it is not cosmetic: the obligations differ meaningfully between them. A SaaS company is usually the importer under Module Two when contracting with EU customers, and the exporter under Module Three when it passes data to its own vendors. Both can be true simultaneously, in the same data flow.

There is also a separate instrument that shares the date and confuses almost everyone. Commission Implementing Decision (EU) 2021/915, also of 4 June 2021, sets out standard contractual clauses between controllers and processors under Article 28(7). Those are model DPA terms for use inside the EEA. They are not a transfer mechanism, they do not appear in Chapter V, and adopting them does nothing to legitimise a transfer to a third country.

Why Almost No One Has BCRs

The approval burden explains the scarcity. Article 47(2) sets out what BCRs must contain, including the structure of the group, the transfers covered, the binding nature internally and externally, the application of the general data protection principles, the rights of data subjects, and acceptance of liability by an EU-established member of the group for breaches by members outside it.

That last element is the one that stops most projects. An EU entity must accept liability for what its non-EU affiliates do with personal data. That is a commercial decision as much as a legal one.

The result is that BCRs are held by large multinationals and almost nobody else. They are also more common on the controller side than the processor side. Among the twelve vendors examined for this blog on 7 August 2026, exactly one had approved BCRs: Twilio, which publishes a Processor Policy covering Segment. Very few processors hold them, which is why our look at whether Segment is GDPR compliant treats it as the unusual case that it is.

Where The Data Privacy Framework Fits

Neither instrument is needed where an adequacy decision covers the transfer, because under Article 45 the transfer requires no additional safeguard at all.

This matters enormously for US transfers. The EU-US Data Privacy Framework was adopted in July 2023, and where a US recipient is certified under it, transfers to that recipient are covered by adequacy. That is why the dominant pattern in vendor contracts is now DPF first, with SCCs sitting behind as a fallback if certification lapses or does not cover the transfer.

Any resource still describing the position as "Privacy Shield was invalidated, so use SCCs" is describing 2020 rather than today. Cloudflare's addendum states that a transfer to the US under the DPF is not a restricted transfer at all, and provides that Cloudflare will notify customers if its certification lapses, at which point the SCC provisions engage. That is the structure to expect.

Our guide to international transfers covers the broader transfer landscape and the mechanisms available. Note that the DPF postdates parts of it, so check the date on anything describing the post-Schrems II position.

Which One Your Vendors Are Actually Using

You will rarely choose between these instruments in the abstract. You will encounter them in a vendor's paperwork and need to work out what you have got.

The patterns from the vendor DPAs verified on 7 August 2026 are consistent. Zapier incorporates the SCCs automatically if the DPF is invalidated or does not cover, including the C2P and P2P modules, the Swiss amendments, the UK Addendum and Brazilian clauses. Sentry puts the DPF first with SCCs behind it, applying Modules Two and Three. Vercel is the outlier, relying on the SCCs and a UK transfer instrument rather than the DPF.

Two things to record every time: which mechanism applies, and which module. A DPA that says "the SCCs apply" without specifying the module has left the most consequential question open.

Note also that transfers and storage location are separate questions. A vendor can rely on the DPF and still store your data in Frankfurt, or rely on SCCs and store it in Virginia. The question of whether the law requires EU storage at all is a different one entirely.

Common Mistakes With Transfer Mechanisms

Signing SCCs without selecting a module. The 2021 clauses only work once you specify which of the four applies and complete the annexes. An unmodularised set of clauses is an incomplete contract.

Confusing Decision 2021/915 with Decision 2021/914. The first provides model Article 28 terms; the second provides transfer clauses. Same date, entirely different function, and the numbers differ by one digit.

Treating BCRs as an aspiration for a small company. Approval requires a lead supervisory authority, an EDPB opinion and an EU entity accepting liability for its affiliates. For most companies that effort is better spent elsewhere.

Assuming BCRs cover external vendors. They bind members of your corporate group. Every transfer to a third party still needs its own mechanism.

Repeating the post-Schrems II position without checking the date. The Data Privacy Framework was adopted in July 2023 and changed the default for US transfers. Guidance written before then, including some still ranking well, describes a landscape that has moved.

FAQ

Do I need SCCs if my vendor is certified under the Data Privacy Framework?

Not for that transfer while the certification holds, because adequacy under Article 45 removes the need for an additional safeguard. Most vendor DPAs still incorporate SCCs as a fallback, which is sensible given the litigation history of adequacy decisions covering the United States.

Can a small company get binding corporate rules approved?

In principle yes, in practice almost never. Approval runs through a lead supervisory authority and an EDPB opinion, typically takes a year or more, and requires an EU group entity to accept liability for non-EU affiliates. BCRs also only cover intra-group transfers, so a small group gains little.

Which SCC module applies to my SaaS?

Usually Module Two when an EU customer sends you personal data as their processor, and Module Three when you pass that data to your own sub-processors outside the EEA. Both commonly apply to the same data at different stages of its journey.

Do the SCCs cover UK transfers?

Not by themselves. The UK operates its own regime, using either the International Data Transfer Agreement or the UK Addendum bolted onto the EU clauses. Vendors serving both markets typically incorporate the Addendum, but check rather than assume.

Closing Thought

The choice framed in the title is not really a choice for most readers, and presenting it as one obscures what actually matters. Nobody weighs SCCs against BCRs the way they might weigh two vendors. One is available to you and the other realistically is not.

The useful work is knowing which mechanism each of your vendors relies on, which module they selected, and what happens if the underlying adequacy decision falls over again, because it has twice. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which keeps that record in one place rather than scattered across signed PDFs. It does not negotiate transfer terms with your vendors, which remains a job for someone reading the actual clauses.