SCC data transfers: how coaches arrange this in the Netherlands
SCC data transfers: how coaches arrange this in the Netherlands

Yes, SCCs are an instrument recognised by the European Commission for transferring personal data outside the EEA. For your coaching practice, this means you may use standard contractual clauses whenever there is no adequacy decision for the destination country. The obligation does not stop at signing the contract: you must assess for each transfer whether that country's legislation undermines the protection of SCCs, and take additional measures where necessary. So start with a transfer impact assessment and document it, before you let data flow to a tool or party outside Europe.
In short:
- Using SCCs alone is not enough; a transfer impact assessment and additional security measures remain necessary for data transfers outside the EEA.
- When using SCCs, you must choose the right module, complete the annexes correctly, and properly document why you do or do not take additional measures.
- An adequacy decision does not make standard contractual clauses unnecessary; automatic approval for countries on that list only applies without additional risks.
- Common mistakes include failing to review SCCs, skipping the transfer impact assessment, and modifying contract text beyond the permitted range of choices.
- For small practices, it is often practical and feasible to take technical security measures when using tools and software outside the EEA and to document this.
Table of contents
- What exactly are SCCs in data transfers?
- SCCs or an adequacy decision: when do you use which?
- How to apply SCCs in practice
- Completing the annexes: which choices do you make yourself?
- The most common mistakes with SCCs
- Practical checklist for coaches and small practices
- Is this achievable without a legal background?
- How Exantur helps with the organisational side
- Sources
- Frequently asked questions
What exactly are SCCs in data transfers?
SCCs, called standard contractual clauses (modelcontracten in Dutch), are standard texts drawn up by the European Commission on the basis of Article 46 of the GDPR. They form a legal safety net: if there is no adequacy decision for the country the data is going to, these contracts still provide an appropriate safeguard for the rights of data subjects.

In June 2021, the Commission replaced the old clauses with a modernised version of the SCCs, including extensive Q&As to answer practical questions. This update was needed because the old texts from 2001 and 2010 no longer aligned with the GDPR and with modern cloud services.
The new SCCs have a modular structure. This means that you do not complete one fixed contract, but choose which module fits the roles of the parties:
- Module 1: controller to controller, for example when you share data with another independent professional who decides for themselves what happens with it.
- Module 2: controller to processor, the most common situation for coaches who engage a software provider outside the EEA.
- Module 3: processor to sub-processor, relevant if your provider in turn engages another party.
- Module 4: processor to controller, a less common but nonetheless provided-for situation.
For most coaching practices, module 2 is the starting point: you are the controller, the software party is the processor.
SCCs or an adequacy decision: when do you use which?
An adequacy decision is a declaration by the European Commission that a country outside the EEA offers a level of protection equivalent to the GDPR. If the destination country is on that list, you may transfer personal data freely, without an additional contract or further assessment.
If the country is not on it, then standard contractual clauses are, according to the Dutch Data Protection Authority, one of the permitted instruments to still transfer lawfully. For most independent coaches and small practices, this is also the most practical route, because the alternatives are more demanding:
- Binding corporate rules are intended for large, international groups with multiple establishments and require an extensive approval procedure.
- Certification mechanisms exist, but in practice are still limited in availability and less suitable for sole proprietorships.
- SCCs therefore remain the standard solution as soon as you use software, storage or communication tools that process data outside the EEA.
Important: using standard contractual clauses is never a formality you tick off once. The Dutch DPA emphasises that additional safeguards and documentation often remain necessary, even after signing.
How to apply SCCs in practice
Signing standard contractual clauses is step one, not the last step. Here is how the process works from start to finish:
- Determine the correct module. Consider who is the controller and who is the processor, and choose the matching module from the Commission text.
- Complete Annex I and II correctly. Describe the parties, the categories of data and the technical measures exactly as they apply in practice, not in general terms.
- Carry out a transfer impact assessment. Answer three key questions: which law applies in the destination country, which categories of data cross the border, and can government authorities in that country demand access without judicial review?
- Determine whether additional measures are needed. The EDPB advises that you often need to supplement SCCs with technical, organisational or contractual safeguards when the destination country's legislation poses risks. Think of encryption of data during storage and transmission, pseudonymisation where names are replaced by codes, contractual guarantees about notification obligations in the event of government requests, and operational restrictions such as limiting access to essential personnel only.
- Document everything. Keep the completed annexes, the outcome of your assessment and the reason why you did or did not consider additional measures necessary.
- Inform data subjects. State in your privacy statement which transfers take place and on the basis of which instrument.
Pro tip: Keep your transfer impact assessment as a separate document alongside the standard contractual clauses themselves. During an audit, the supervisory authority often asks not only for the contract, but also for evidence that you have genuinely considered the risks.
For smaller practices, strong encryption and pseudonymisation are usually the most feasible additional measures, simply because you do not have your own legal department to negotiate more elaborate arrangements.
Completing the annexes: which choices do you make yourself?
Annex I and Annex II are not appendices to tick off quickly. They determine what has actually been agreed in the event of a dispute or audit.
- Annex I describes the parties, their roles, the categories of data subjects and data, and the purpose of the processing.
- Annex II describes the technical and organisational measures: which security, which access restrictions, which retention periods.
In its Q&A document, the Commission makes clear that you may not simply modify the core text of the clauses. Where the text leaves room, there is often a square bracket: this means that you must fill in a choice yourself, such as a country or a period. If you modify the core text yourself, beyond that permitted range of choices, you lose the protection of the standard contractual clauses and approval from the Dutch Data Protection Authority may be required.
The most common mistakes with SCCs
Most problems arise not when signing the contract, but afterwards.
- Signing SCCs and then never reviewing them again. Legislation in the destination country can change, and your transfer impact assessment can become outdated without you noticing.
- Skipping the TIA because the contract is "already signed anyway." Without this assessment, you do not know whether additional measures are needed.
- Modifying the contract text beyond the permitted range of choices, causing the legal protection to fall away.
- Relying solely on the contract without technical measures, whereas a contract cannot stop a foreign government.
- Failing to inform data subjects about which transfers take place and on what basis.
A common misconception is that SCCs are a solution you arrange once and can then forget. Supervisory authorities such as the Dutch DPA and the EDPB emphasise precisely the opposite: ongoing monitoring and reassessment are part of a responsible transfer, not just the initial assessment.
Practical checklist for coaches and small practices
As a coach, you probably transfer data more often than you think: via video calling software, email marketing, accounting packages or cloud services that host outside the EEA. Not every tool requires standard contractual clauses, but every tool outside the EEA without an adequacy decision deserves a quick check.
- Take stock of your tools. Note which software processes client data and where that data is stored.
- Ask the key questions. Is the country on the adequacy list? If not, does the provider have standard contractual clauses? Is the data encrypted?
- Document your assessment. A short document with date, tool, country and conclusion is often sufficient as a basis.
Pro tip: Ask your software provider directly about the standard contractual clauses and the location of the servers. A provider that takes the GDPR seriously can answer these questions without hesitation.
Is this achievable without a legal background?
Yes, with a step-by-step approach this is quite manageable for a small practice. Most of the time goes not into legal subtleties, but into documentation: recording which tools you use, which countries are involved, and which technical measures you already take. If you are unsure about a specific situation, contact a lawyer or consult the Dutch Data Protection Authority directly.
— Martijn
How Exantur helps with the organisational side
SCCs arrange the legal basis, but the day-to-day execution requires structure. Exantur is built for coaches who want to organise their practice in one system, with EU hosting in Frankfurt and a data processing agreement that comes as standard with your account. This means that client data, session notes and documents stay within the EU, without you having to arrange standard contractual clauses with a processor outside the EEA yourself for your most important workflow.
Exantur does not replace legal advice and does not automatically make your practice fully GDPR-compliant, but it does save you a number of transfer questions that you would otherwise have to figure out again for each tool. Want to see whether this fits your practice? Check out the plans and pricing and start a free trial period, at no cost during this period.

This article contains general information and does not replace the advice of a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.
Sources
- Transfer of personal data outside the EEA | Dutch Data Protection Authority
- Standard contractual clauses for international transfers - European Commission
- Recommendations 01/2020 on measures that supplement transfer tools (EDPB)
Frequently asked questions
What is the Dutch version of the GDPR?
The GDPR, the General Data Protection Regulation, applies directly in the Netherlands as a European regulation. There is no separate Dutch "translation" of the law needed, although the GDPR Implementation Act (Uitvoeringswet AVG) adds some national details, such as the powers of the Dutch Data Protection Authority.
Can you sue someone for a privacy breach?
Yes, data subjects can file a complaint with the Dutch Data Protection Authority or claim damages through the courts if their data has been processed or transferred unlawfully. In the case of international transfers without a valid safeguard, such as a missing standard contractual clause, this is one of the most common grounds for a complaint.
What are three key points from the GDPR for data transfers?
First, transfers outside the EEA are only permitted with a valid safeguard, such as an adequacy decision or SCCs under Article 46. Second, you must assess for each transfer whether additional measures are needed. Third, you must transparently inform data subjects about which transfers take place.
What counts as a privacy breach in the case of transfers?
A privacy breach occurs when personal data leaves the country without a valid legal basis, for example without standard contractual clauses to a country without an adequacy decision. Ignoring necessary additional measures, despite a risky transfer impact assessment, can also be regarded as a breach.
Does Exantur help with meeting GDPR requirements around transfers?
Exantur supports you with EU hosting and a data processing agreement, which reduces the number of transfer questions outside the EEA for your most important workflow. Current pricing is available on the Exantur pricing page.
