Global Workforce, EOR & Cross-Border OperationsPlaybook3 min readUpdated September 2026

Using Standard Contractual Clauses to Move EU Data to the US

Moving personal data from the EU to the US, employee records, customer data, anything that includes identifiable information, needs a legal transfer mechanism, and for most companies without a specific adequacy decision to rely on, that mechanism is Standard Contractual Clauses. SCCs aren't a formality you attach to a contract and forget; a real assessment of whether they actually provide adequate protection in practice is part of using them correctly.

This matters for both customer data and employee data, and companies often handle one carefully while overlooking that the other, usually employee data moving to a US-based HR system, needs the same mechanism.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Know Which SCC Module Applies to Your Transfer

The current SCCs come in different modules depending on the relationship between the parties, controller to controller, controller to processor, processor to processor, and using the wrong module for your actual relationship undermines the whole point of having a legally valid transfer mechanism. A company sending employee data to a US-based EOR is typically in a different module relationship than a company sending customer data to a US-based analytics vendor.

Work with counsel to identify the correct module for each specific data flow, since a single company often has multiple different transfer relationships that need different modules, not one blanket agreement covering everything.

Do the Transfer Impact Assessment, Not Just the Paperwork

Using SCCs isn't sufficient on its own; you also need to assess whether the destination country's laws, US government surveillance access in particular, could undermine the protections the SCCs promise, and implement supplementary measures if they do. This assessment needs to be documented, not just asserted, since it's exactly what a regulator would ask to see.

Common supplementary measures include encryption in transit and at rest with keys held outside US government reach, and minimizing what data actually needs to transfer in the first place rather than transferring everything by default.

Minimize What Actually Needs to Cross the Border

The simplest way to reduce transfer risk is transferring less data. Before setting up a new cross-border data flow, ask whether the full dataset actually needs to move, or whether a smaller subset, or an aggregated version, would serve the actual business purpose. This isn't just a compliance nicety, it also reduces the scope of what needs to be covered by SCCs and supplementary measures in the first place.

This is particularly relevant for employee data moving into US-based HR or payroll systems, where sensitive categories like health information sometimes get transferred by default even when the US system doesn't actually need them.

Common SCC Mistakes That Undermine the Protection

A few patterns that show up repeatedly:

  • Signing SCCs once at vendor onboarding and never revisiting them as the data flow or the legal landscape changes
  • Using the wrong module for the actual relationship between the parties
  • Treating the transfer impact assessment as a checkbox rather than a documented, substantive analysis
  • Transferring more data than the receiving system actually needs, widening the risk surface unnecessarily

Each of these is a reason to review your current cross-border data flows specifically, rather than assuming an SCC signed years ago still reflects your current setup.

For example, a company that signs SCCs with its US HR platform in the first year may later add a US analytics vendor that receives customer email addresses. That second flow is a different relationship and may need a different module. A short data-flow register helps: list each vendor, the categories of data they receive, the module in use, the date the transfer assessment was done and the next review date. When a new vendor appears, adding a row prompts the module and assessment questions before any data moves.

Keep the Documentation Organized for When It's Needed

SCCs, transfer impact assessments, and any supplementary measures documentation need to be stored somewhere retrievable, since a regulator inquiry, a customer's own vendor due diligence, or an internal audit can all ask for it with limited notice. Foxit eSign is useful for executing SCCs and related agreements with multiple vendors and signatories efficiently, and Process Street can standardize the transfer impact assessment process so it's actually completed consistently rather than skipped under time pressure.

Check with EU data protection counsel on your specific transfer flows, since the right module and supplementary measures depend on the actual relationship and data involved in each case, and a generic template rarely fits every vendor relationship equally well.

Executive Capability Standard

What Good Looks Like

Good cross-border data transfer practice means every EU-to-US data flow has the correct SCC module, a documented transfer impact assessment, and supplementary measures where needed, reviewed at least annually.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Map every data flow moving personal data from the EU to the US, including employee data into HR and payroll systems.
2. Do Manually:Complete a transfer impact assessment for your highest-volume data flow by hand with counsel before building a repeatable process.
3. Delegate:Assign a data protection lead to own reviewing SCCs and transfer assessments as vendor relationships change.
4. Automate:Standardize the transfer impact assessment process with a tool like Process Street so it's completed consistently for every new vendor.
5. Buy:Engage EU data protection counsel to review your current SCCs and identify any data flows using the wrong module or missing an assessment.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Do we need SCCs for employee data, or just customer data?

Both, if either involves personal data moving from the EU to the US without another valid transfer mechanism. Companies often focus SCC compliance on customer-facing data flows and overlook employee data moving into a US-based HR or payroll system, which needs the same protection.

Is signing SCCs enough to make a data transfer legal?

Not on its own. You also need a documented transfer impact assessment evaluating whether the destination country's laws could undermine the SCC protections, and supplementary measures if they do. Signing the clauses without this assessment leaves a real gap in the protection you're relying on.

How often should we review our existing SCCs?

At least annually, and whenever a data flow or vendor relationship changes meaningfully. The legal landscape around international data transfers has shifted more than once in recent years, so an agreement signed years ago may no longer reflect current guidance or your actual data flows.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides