vaulytica

EU Standard Contractual Clauses — Module 2 (Controller to Processor) review

Verifies the official EU SCC Module 2 text (Commission Implementing Decision 2021/914) is incorporated and checks Annexes I, II, III. Also runs the GDPR Article 28 checks because SCC Module 2 must satisfy Article 28(3) by reference.

Review your document — free → See a sample report

What it checks

Subject-matter of processing identified

DPA must identify the subject-matter of the processing.

Critical · DPA-001

Duration of processing specified

DPA must specify the duration of the processing.

Critical · DPA-002

Nature and purpose of processing

DPA must describe the nature and purpose of the processing.

Critical · DPA-003

Type of personal data identified

DPA must identify the type of personal data processed.

Critical · DPA-004

Categories of data subjects identified

DPA must identify the categories of data subjects.

Critical · DPA-005

Obligations and rights of the controller stated

DPA must state the obligations and rights of the controller.

Critical · DPA-006

Processing only on documented instructions

Processor must process personal data only on documented instructions from the controller.

Critical · DPA-007

Confidentiality of authorised persons

Persons authorised to process personal data must commit themselves to confidentiality.

Critical · DPA-008

Article 32 security measures incorporated

DPA must require the processor to take all measures required pursuant to Article 32.

Critical · DPA-009

Subprocessor terms (Art. 28(2) and (4))

DPA must respect the conditions for engaging another processor.

Critical · DPA-010

Assist controller in responding to data-subject rights

Processor must assist the controller in responding to data-subject rights requests.

Critical · DPA-011

Assist controller with Articles 32–36 obligations

Processor must assist the controller with Articles 32–36 obligations (security, breach, DPIA, prior consultation).

Critical · DPA-012

Deletion or return at end of services

Processor must, at the choice of the controller, delete or return all personal data after the end of the provision of services.

Critical · DPA-013

Information available for compliance demonstration

Processor must make available all information necessary to demonstrate compliance with Article 28.

Critical · DPA-014

Subprocessor prior written authorisation (Art. 28(2))

Processor must obtain prior specific or general written authorisation before engaging a subprocessor.

Critical · DPA-015

Subprocessor change notification + objection right

Where general authorisation is used, controller must be informed of intended changes and have the opportunity to object.

Critical · DPA-016

Subprocessor flow-down of same obligations (Art. 28(4))

The DPA must require that any subprocessor the processor engages is bound by contract to the same data-protection obligations — a term Art. 28(3)(d) makes mandatory whether or not one is engaged yet.

Critical · DPA-017

DPA in writing including electronic form

DPA must be in writing, including in electronic form.

Warning · DPA-018

Pseudonymisation / encryption referenced

Art. 32(1)(a) lists pseudonymisation and encryption as appropriate measures where relevant.

Warning · DPA-019

Confidentiality / integrity / availability / resilience

Art. 32(1)(b) — ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems.

Warning · DPA-020

Restore availability after incident

Art. 32(1)(c) — ability to restore availability and access to personal data in a timely manner.

Warning · DPA-021

Regular testing of measures

Art. 32(1)(d) — process for regularly testing, assessing and evaluating effectiveness.

Warning · DPA-022

'Appropriate measures' undefined hand-waving

Flags DPAs that reference 'appropriate measures' without an Annex of technical and organisational measures.

Warning · DPA-023

Processor breach notice to controller (Art. 33(2))

Processor must notify the controller without undue delay after becoming aware of a personal data breach.

Critical · DPA-024

'Without undue delay' present

Breach-notification clause should include 'without undue delay'.

Warning · DPA-025

Breach-notice content elements (Art. 33(3))

Breach notification should include the Article 33(3) content elements (nature, categories, contact, consequences, measures).

Warning · DPA-026

Breach notice timing stricter than 'undue delay'

Flags fixed breach-notice deadlines that exceed regulator expectations (e.g., > 72 hours from controller awareness, > 5 days from processor awareness).

Warning · DPA-027

Article 30 records of processing assistance

Processor should assist controller with Art. 30 records of processing activities (RoPA).

Warning · DPA-028

DPIA assistance (Art. 35)

Processor should assist controller with Data Protection Impact Assessments under Art. 35.

Warning · DPA-029

Article 27 EU representative referenced (where applicable)

Non-EU processors should reference their EU representative under Art. 27.

Warning · DPA-030

Article 37 DPO referenced (where applicable)

Where required, the DPA should reference the Data Protection Officer under Art. 37.

Warning · DPA-031

International transfer mechanism named

Where international transfers occur, the DPA must name a Chapter V mechanism.

Critical · DPA-032

EU SCCs incorporated by reference

DPA should incorporate EU SCCs by reference where transfers require them.

Warning · DPA-033

Transfer Impact Assessment (TIA) referenced

Following Schrems II, parties should reference a TIA where Chapter V transfers occur.

Warning · DPA-034

Deletion-or-return choice belongs to processor

Flags clauses where the processor (not the controller) chooses between deletion and return.

Warning · DPA-035

Audit-substitution eliminates audit entirely

Flags SOC 2 / ISO substitution that eliminates the controller's audit right rather than substituting it.

Warning · DPA-036

Processor unilaterally amends instructions

Flags clauses where the processor may deviate from controller instructions unilaterally.

Warning · DPA-037

Personal data scope defined or annexed

DPA should define personal data scope in an Annex (Annex I for SCCs).

Warning · DPA-038

Technical and organisational measures annex

DPA should include an Annex describing technical and organisational measures (Annex II for SCCs).

Warning · DPA-039

Subprocessor list annex

DPA should include a list of approved subprocessors (Annex III for SCCs Modules 2 & 3).

Warning · DPA-040

GDPR-current terminology (Personal Data Breach defined)

DPA should track GDPR terminology (Personal Data Breach, Data Subject, Processor, Controller).

Warning · DPA-041

Controller / Processor roles named

DPA should clearly identify which party is the Controller and which is the Processor.

Critical · DPA-042

Signature block present

DPA should be signed by an authorised representative of each party.

Warning · DPA-043

Effective date present

DPA should state an effective date.

Warning · DPA-044

Term and termination clauses

DPA should state its term and termination conditions.

Warning · DPA-045

Governing-law clause present

DPA should specify governing law (typically EU Member State or UK).

Warning · DPA-046

Liability allocation

DPA should allocate liability between Controller and Processor.

Warning · DPA-047

Controller indemnifies Processor for GDPR fines

Flags clauses where the controller indemnifies the processor for the processor's own GDPR liability.

Warning · DPA-048

Processor caps audit cost on controller exclusively

Flags clauses where the controller must bear the entire cost of any audit, including audits triggered by processor breach.

Warning · DPA-049

Personal data referenced in document

DPA should reference 'personal data'; absence likely means the wrong template.

Critical · DPA-050

Notice clause present

DPA should specify how formal notices (including breach notices) are delivered.

Warning · DPA-051

Survival of GDPR obligations post-termination

DPA should state that obligations applicable to retained personal data survive termination.

Warning · DPA-052

Records of subprocessor changes available

Processor should keep records of subprocessor changes available on request.

Warning · DPA-053

Onward transfer obligations (SCC Clause 8.8)

Where SCCs apply, the DPA should reference onward-transfer obligations per SCC Clause 8.8.

Warning · DPA-054

Local-law disclosure obligations (Clause 14 / 15)

Where SCCs apply, processor must notify controller of legally-binding requests by public authorities.

Warning · DPA-055

SCC Clause 1 — Purpose and Scope present

EU SCC Clause 1 (Purpose and Scope) must be present.

Critical · TRANSFER-001

SCC Clause 2 — Effect and Invariability present

EU SCC Clause 2 (Effect and Invariability) must be present and unmodified.

Critical · TRANSFER-002

SCC clauses materially modified

Flags any 'as modified' / 'notwithstanding' / 'as amended' language attached to SCC clauses — forbidden by Clause 2.

Critical · TRANSFER-003

SCC Clause 8 — Data Protection Safeguards

SCC Module 2 Clause 8 (Data Protection Safeguards) must be present.

Critical · TRANSFER-004

SCC Clause 9 — Use of Sub-processors

SCC Module 2 Clause 9 (Use of Sub-processors) must be present.

Critical · TRANSFER-005

SCC Clause 11 — Redress

SCC Module 2 Clause 11 (Redress) must be present.

Warning · TRANSFER-006

SCC Clause 14 — Local Laws (TIA)

SCC Clause 14 (Local laws and practices affecting compliance) must be present, anchoring the TIA.

Critical · TRANSFER-007

SCC Clause 15 — Public Authority Access

SCC Clause 15 (Obligations of the data importer in case of public authority access) must be present.

Critical · TRANSFER-008

SCC Clause 16 — Non-Compliance with the Clauses

SCC Clause 16 (Non-Compliance with the Clauses and Termination) must be present.

Warning · TRANSFER-009

SCC Clauses 17–18 — Governing Law and Forum

SCC Clause 17 (Governing Law) and Clause 18 (Choice of Forum and Jurisdiction) must be present.

Critical · TRANSFER-010

Adequacy: reliance on the EU-US Data Privacy Framework

Flags reliance on the EU-US Data Privacy Framework (or its UK extension) so the importer's certification and a fallback transfer mechanism are confirmed.

Warning · TRANSFER-017

Adequacy decision currency clause

Where an adequacy decision is relied on, the DPA should anchor the reliance with a fallback for invalidation.

Warning · TRANSFER-018

TIA / Transfer Risk Assessment reference

Where SCCs / IDTA cover transfers to a non-adequate country, the DPA must reference a TIA / TRA.

Critical · TRANSFER-019

Every run also applies 106 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

Sources

Often reviewed with

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More privacy & data protection documents

Every document type →