Data and security
Standard Contractual Clauses and the UK Addendum for EU vendors with non-EU subcontractors
If one developer on the project sits in Ukraine, Serbia or Georgia, the enterprise client’s DPA has a transfer problem. Here is the paper that solves it.
IIIAuthorised sub-processors: see Supplier’s website1. Nordwind Dev OOO, Tbilisi, Georgia — software development, access to source repositories and staging data. 2. Kyiv Frontend LLC, Kyiv, Ukraine — UI development, no access to production data. 3. Cloud host, Frankfurt, Germany — hosting (no transfer).
- A transfer happens when data becomes accessible from outside the EEA — remote access counts, no copy required.
- As a processor engaging a non-EEA sub-processor you need Module 3 of the 2021 SCCs, plus the UK Addendum if UK data is in scope.
- Keep the transfer impact assessment proportionate. Two pages of honest analysis beats twenty of template.
When a transfer actually happens
The trigger is not a copy leaving the EEA. It is access. If a contractor in Tbilisi can log into a repository or a staging environment containing personal data, that is a transfer to Georgia, even if nothing is downloaded and the servers sit in Frankfurt. Remote access by personnel outside the EEA is the most common transfer in a software services business and the one most often missed in a DPA.
Three consequences follow. Your sub-processor list has to name the countries, not just the companies. Your contractor agreements with non-EEA individuals or entities have to carry the transfer obligations. And support access counts — a support engineer outside the EEA with a break-glass account is a transfer even if it is used twice a year.
What is not a transfer: an EEA-established sub-processor with EEA-only staff, and a non-EEA entity whose access is to fully anonymised data. Pseudonymised data is still personal data, so a repository with hashed user identifiers does not escape.
Which SCC module you need
The 2021 Standard Contractual Clauses come in four modules, and using the wrong one is the most common drafting error in this area.
- Module 2, controller to processor. Your client is the controller and you are a processor established outside the EEA. Relevant if your own company is outside the EU, not if you are an EU vendor.
- Module 3, processor to processor. You are an EU-established processor engaging a sub-processor outside the EEA. This is the module for a Polish or Estonian software house with contractors in Ukraine, Serbia, Georgia or Moldova.
- Module 1 (controller to controller) and Module 4 (processor to controller) rarely apply in this fact pattern.
Module 3 has a quirk worth knowing: it requires the data exporter to act on the controller’s instructions and to pass those instructions down, and it gives the controller third-party rights against the sub-processor directly. Your client’s privacy team will know this and will ask whether the controller is identified in the annexes. Identify them.
The clauses are incorporated by reference in the DPA and completed by annexes: Annex I for the parties, the categories of data and the purposes; Annex II for the technical and organisational measures; Annex III for the authorised sub-processors. Annex II is where vendors copy a generic list and get caught — it should match the TOMs annex in the DPA itself.
The transfer impact assessment, proportionately
Since Schrems II, signing the SCCs is not sufficient on its own: you have to assess whether the law of the destination country undermines the protection the clauses promise, and apply supplementary measures where it does. In practice this means a document, and the document has become an industry in itself.
A proportionate assessment for a software services transfer is two to three pages and answers five questions honestly. What data is transferred, and is it special-category or sensitive? Who can access it, and for what? What does the destination country’s law say about government access to data held by private companies? Is there a practical likelihood of such access for this data? And what supplementary measures apply — encryption, access controls, pseudonymisation, a policy on handling government requests, and a commitment to challenge unlawful ones?
The honest answer for most CEE software work is that the data is business contact information and application data, the access is by named developers for development purposes, and the practical risk of state access to a foreign vendor’s staging database is low. Say that, evidence the controls, and date the document. Clients accept a short assessment that engages with the facts far more readily than a long one that does not.
The UK Addendum after Brexit
If any of the data relates to UK data subjects or comes from a UK controller, the EU SCCs do not cover it. The UK has its own mechanisms: the International Data Transfer Agreement, a standalone document, or the International Data Transfer Addendum, which bolts onto the EU SCCs and adapts them to UK law.
For a vendor already using the EU SCCs, the Addendum is the pragmatic choice. It is a short form: you identify the EU SCCs it attaches to, complete a table of parties and selected clauses, and the Addendum substitutes UK law, the UK regulator and UK-appropriate wording. One set of SCCs plus one Addendum covers both flows without maintaining two parallel contracts.
Two practical notes. The Addendum requires the parties to identify which version of the EU SCCs it modifies, so keep your SCC version and date recorded. And the UK regulator’s own transfer risk assessment tool is an acceptable alternative to a Schrems-style analysis for UK transfers; using it is usually faster than adapting an EU assessment.
Ukraine, and what to say about it in 2026
Ukraine is a common location for CEE development capacity and a frequent question in client diligence. The position to state accurately: Ukraine is not the subject of a European Commission adequacy decision, so transfers there require a mechanism — in this fact pattern, Module 3 SCCs. Ukraine has been reforming its data protection framework towards GDPR alignment as part of its EU accession process, and an adequacy assessment is a live topic, but until a decision is adopted the SCCs are what you rely on.
Clients also ask about continuity and physical security given the war. That is a business-continuity question rather than a transfer question, and it belongs in the security addendum: where the infrastructure sits, what the failover is, and whether personnel can work from a second location. Answer it there rather than in the DPA, and answer it specifically.
Putting it in the subcontractor agreement
The SCCs are between you and the sub-processor, which means the sub-processor has to sign them. For a corporate sub-processor that is straightforward. For an individual B2B contractor it needs a little care: the contractor agreement should incorporate the SCC obligations, flow down the controller’s instructions, oblige the contractor to assist with data-subject requests and breach notification, prohibit onward transfer without your authorisation, and commit them to the same technical measures you promised your client.
Keep a signed copy per contractor, keep the annexes current when a project changes, and keep the sub-processor list in one place that you can produce in an audit. The administrative discipline is the whole of the work here; the legal analysis rarely changes.
In our experience, four things: does the sub-processor list name countries; is there a dated transfer impact assessment; do the SCC annexes describe this engagement rather than a generic one; and is there a UK Addendum if UK data is in scope. Prepare those four and the transfer section of a vendor review closes without a second round.
The shortcut that is not one
Some vendors handle this by promising EEA-only processing and then quietly granting repository access to a contractor outside the EEA. It survives until the first audit, the first breach, or the first time a client’s privacy team reads the commit history. If you need non-EEA capacity, paper it properly — the paperwork is a day’s work and the alternative is a misrepresentation in a signed contract.
Next step
Have a contract like this on your desk?
Send it over. We will mark it up and walk you through it in twenty minutes — no cost, and you will know whether the desk is worth it.