International Processor Agreements

We analyse and negotiate international processor agreements and SCC documentation

International Suppliers and Processor Agreements – What Needs to Be Adapted?

View as Markdown
3 mins read • Legal Writer • GDPR • 4 May 2026

When personal data is processed by suppliers outside the EU/EEA, specific safeguards are required under the GDPR. For many organisations operating across Europe, this means reviewing, updating and sometimes renegotiating their data processing agreements, particularly where processing takes place in so-called third countries.

Data Transfer Risk Assessment and SCC GDPR Requirements

One legal basis for transfers to a third country may be Standard Contractual Clauses, often referred to in an SCC GDPR context. These clauses must normally be supplemented by an assessment of the level of protection in the recipient country. This data transfer risk assessment, also known as a Transfer Impact Assessment, must be documented and kept up to date.

However, SCC GDPR documentation is only one of several possible legal mechanisms under Chapter V of the GDPR. Other legal bases for transfers to third countries may include adequacy decisions, Binding Corporate Rules, approved contractual clauses, legally binding instruments between public authorities and limited derogations for specific situations.

When a Data Transfer Risk Assessment Is Required

An adequacy decision from the European Commission means that the recipient country is considered to provide a level of protection equivalent to the GDPR. In such cases, transfers may take place without additional safeguards. For other mechanisms, the controller must carefully assess whether the level of protection in the recipient country is sufficient and whether supplementary safeguards are needed.

Binding Corporate Rules may be used within corporate groups, but they require approval from supervisory authorities. Contractual clauses approved by a supervisory authority and the European Commission may also be used in addition to SCC. In specific public-sector contexts, legally binding and enforceable instruments between public authorities may also provide a legal basis.

Derogations may apply in special situations, for example where the data subject has explicitly consented to the transfer, or where the transfer is necessary to perform a contract, comply with a legal obligation or protect important public interests. These derogations are restrictive and should not be used for routine transfers.

Keeping Control Across Borders

International data processing also makes monitoring and follow-up more complex. Controllers need procedures for continuously reviewing suppliers when they act as processors, including where those processors are based in jurisdictions outside the EU/EEA.

When using international processors, organisations should ensure that SCC are used where appropriate and that the data transfer risk assessment has been completed and documented. They should also impose clear requirements on sub-processors and transparency throughout the supplier chain.

It is also important to assess whether technical measures, such as encryption, can reduce transfer-related risks. The controller should further monitor how the processor assists with data subject rights, particularly in relation to access requests, erasure requests and other GDPR rights.

Legal Support for International Processor Agreements

At Morling Consulting, our data protection lawyers help companies across Europe analyse, negotiate and follow up on processor agreements, both within and outside the EU. We assist with SCC GDPR documentation, data transfer risk assessment work and practical supplier follow-up so that international processing arrangements remain controlled, documented and legally robust.

Speak to a data protection lawyer

Do you need help with international processor agreements? Contact us and we will assess your SCC safeguards

"*" indicates required fields