AeternaData
Compliance Reference

EU Standard Contractual Clauses, Module 2.

Commission Implementing Decision EU 2021/914. Controller-to-Processor. Annexed to every Data Processing Agreement before any personal data is transferred from the EEA to Aeterna Data in Indonesia.

EU 2021/914Legal Basis
Module 2Controller → Processor
Day OneExecuted Before Data Sharing
Art. 46(2)cGDPR Transfer Mechanism

What Are EU Standard Contractual Clauses?

EU Standard Contractual Clauses — known as EU SCCs — are a set of contractual clauses approved by the European Commission that provide an adequate safeguard for personal data transferred from the European Economic Area to third countries that do not benefit from an EU adequacy decision. They are the primary legal mechanism used by EU data controllers and processors to transfer personal data outside the EEA in compliance with GDPR Article 46(2)(c).

The current EU SCCs were adopted under Commission Implementing Decision (EU) 2021/914 on June 4, 2021 — replacing the previous 2001 and 2010 SCCs that were invalidated by the Schrems II ruling of the Court of Justice of the European Union in July 2020. The new SCCs took full mandatory effect on December 27, 2022. Any data transfer arrangement relying on the old SCCs after that date is invalid under GDPR.

The EU SCCs are not a privacy policy. They are a binding contract between the data exporter (the EU-based party) and the data importer (the non-EEA party) that incorporates specific obligations directly from the GDPR into the relationship — ensuring that the personal data transferred outside the EEA continues to receive a level of protection essentially equivalent to that guaranteed within it.

Legal instrument
Commission Implementing Decision EU 2021/914
GDPR basis
Article 46(2)(c)
Mandatory since
27 December 2022

Module 2: Controller-to-Processor

The 2021 EU SCCs are structured in four modules, each covering a different transfer relationship between data controllers and processors. The applicable module depends on the roles of the data exporter and data importer in the specific transfer.

Module 1

Controller → Controller

Both the exporter and importer independently determine the purposes and means of processing. Used when two data controllers transfer data between themselves.

Module 2

Controller → Processor

The exporter is a data controller. The importer is a data processor acting only on the controller's instructions. This is the module that governs Aeterna Data's relationships with EU clients.

Applies to Aeterna Data
Module 3

Processor → Processor

The exporter is a processor acting on a controller's instructions. The importer is a sub-processor. Used when a processor engages a sub-processor in a third country.

Module 4

Processor → Controller

The exporter is a processor. The importer is a controller in a third country. A less common configuration used in specific outsourcing arrangements.

Under Module 2, Aeterna Data is the data importer — a data processor that processes personal data on behalf of EU-based clients (the data exporters / data controllers) strictly in accordance with their documented instructions, as specified in the Data Processing Agreement to which the EU SCCs are annexed.

Why Indonesia Requires EU SCCs

Indonesia is not a third country that benefits from an EU adequacy decision under GDPR Article 45. The European Commission has issued adequacy decisions for a limited number of countries — including Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States (under the Data Privacy Framework). Indonesia is not on this list.

The absence of an adequacy decision does not mean personal data cannot be transferred to Indonesia. It means the transfer requires an appropriate safeguard under GDPR Article 46 — and EU SCCs Module 2 is that safeguard for Aeterna Data's client relationships.

Indonesia enacted its own Personal Data Protection Law (Law No. 27 of 2022, UU PDP) in October 2022, which came into full force in October 2024. While this demonstrates a maturing Indonesian data protection framework, the existence of a national data protection law does not constitute an EU adequacy decision. EU SCCs remain required for EEA-to-Indonesia personal data transfers regardless of Indonesian domestic law developments.

Aeterna Data is registered as PT Aeterna Data Intentio Logic under Indonesian law and is subject to Indonesian Personal Data Protection Law No. 27 of 2022 as a data processor. Compliance with UU PDP is complementary to, not a substitute for, the EU SCCs required for EEA personal data transfers.

The Relationship Between the SCCs and the DPA

The EU SCCs and the Data Processing Agreement are complementary instruments that work together in every Aeterna Data client engagement. They are not the same document — and neither is sufficient without the other.

Data Processing Agreement (DPA)

GDPR Article 28 instrument
  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Type of personal data and categories of data subjects
  • Obligations and rights of the controller
  • Technical and organisational security measures (TOMs)
  • Sub-processor rules
  • Data subject rights assistance
  • Deletion and return of data at engagement end

EU SCCs Module 2

GDPR Article 46 transfer mechanism
  • Legal basis for EEA-to-Indonesia transfer
  • Binding obligations on data importer (Aeterna Data) toward data subjects
  • Government access provisions
  • Liability allocation between parties
  • Data subject third-party beneficiary rights
  • Governing law and jurisdiction
  • Supervisory authority cooperation
  • Termination and data deletion on SCC breach

In Aeterna Data's standard engagement flow, the DPA and EU SCCs are executed together — as a single document package — after the NDA is signed and after the discovery call confirms the project scope. The SCCs are not a separate negotiation. They are annexed to the DPA and executed simultaneously.

Clauses Overview

The EU SCCs Module 2 are structured in four sections. The following is a summary of each section and its practical implications for Aeterna Data's client relationships.

Section I — General ProvisionsClauses 1–4

Establishes the purpose of the SCCs, the definitions of key terms (data exporter, data importer, personal data, processing, controller, processor), the hierarchy between the SCCs and any broader commercial agreement, and the docking clause that allows additional parties to accede to the SCCs.

Key Implication for Clients

Clause 4 establishes that in case of conflict between the SCCs and any other agreement between the parties, the SCCs prevail in relation to data protection obligations. This protects clients — the SCCs cannot be overridden by commercial contract terms.

Section II — Obligations of the PartiesClauses 8–15

The core operational obligations. Covers: instructions for processing (data importer may only process on documented instructions), purpose limitation, data minimisation, accuracy, storage limitation, security, sub-processing, data subject rights assistance, and notification obligations.

Key Implication for Clients

Clause 8.1 requires Aeterna Data to process personal data only on documented instructions from the client. This is operationalised through the SOW, which specifies the annotation task, the data types to be processed, and the permissible processing activities.

Section III — Data Subject RightsClauses 10–11

Establishes data subjects as third-party beneficiaries of the SCCs — meaning they can enforce the SCCs against both the data exporter and data importer directly. Covers data subject rights to information, access, rectification, erasure, and restriction.

Key Implication for Clients

Data subjects whose personal data is processed by Aeterna Data as part of your annotation pipeline can invoke their GDPR rights directly against Aeterna Data under the SCCs. Aeterna Data is obligated to assist the client in fulfilling data subject requests.

Section IV — Final ProvisionsClauses 16–18

Covers the governing law of the SCCs (which must be the law of an EU member state), the choice of supervisory authority and courts, the liability regime between parties, and the circumstances under which the SCCs may be terminated.

Key Implication for Clients

The governing law for Aeterna Data's SCCs is the law of the Netherlands, which also determines supervisory authority jurisdiction. Disputes under the SCCs are subject to Dutch courts.

Data Subject Rights Under the SCCs

One of the most significant features of the 2021 EU SCCs — compared to the previous versions — is the explicit recognition of data subjects as third-party beneficiaries. Under Clause 3 of the SCCs, data subjects whose personal data is transferred under the SCCs have enforceable rights against both the data exporter (the EU client) and the data importer (Aeterna Data).

This means data subjects are not dependent on the client to enforce their GDPR rights in relation to Aeterna Data's processing. They can approach Aeterna Data directly to exercise their rights — and Aeterna Data is contractually and legally obligated to respond appropriately.

Right to Information

Data subjects have the right to receive information about how their personal data is processed. Under the SCCs, Aeterna Data is obligated to provide or assist in providing this information when requested.

Right of Access

Data subjects have the right to request access to their personal data processed by Aeterna Data. Aeterna Data is obligated to respond to access requests within GDPR timelines and to notify the client of any such request.

Right to Rectification

Where personal data processed by Aeterna Data is inaccurate, data subjects may request rectification. Aeterna Data will notify the client and assist in fulfilling the request.

Right to Erasure

Data subjects may request deletion of their personal data. Aeterna Data will notify the client of any erasure request and will delete data as directed by the client — or as required by the SCCs where the engagement has ended.

Right to Restriction

Data subjects may request restriction of processing under GDPR Article 18. Aeterna Data will suspend processing of the relevant data upon client instruction while the restriction request is resolved.

Data subjects wishing to exercise their rights in relation to personal data processed by Aeterna Data should contact: [email protected]

Security Obligations Under the SCCs

Clause 8.6 of the EU SCCs Module 2 requires the data importer to implement technical and organisational security measures appropriate to the risk posed by the processing — taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of natural persons.

Aeterna Data's technical and organisational measures (TOMs) are documented in the DPA and encompass Aeterna Data's annotation workflow security practices and internal security protocols. A core security measure is that annotation is performed inside the client's own annotation environment — personal data does not traverse Aeterna Data's infrastructure.

Technical and Organisational Measures

Data Residency

Personal data remains in the client's own environment throughout the annotation engagement. Aeterna Data's annotators access the data via client-provisioned credentials — the data does not leave the client's infrastructure at any point.

Per-Annotator Access Controls

Each annotator is provisioned with individual, unique access credentials by the client. Credentials are not shared between annotators. Access is revoked immediately upon annotator rotation or engagement end.

Individual NDA Binding

Every annotator who accesses personal data in the client's environment has signed an individual NDA that binds them to confidentiality obligations specific to the engagement — creating individual-level contractual accountability beyond the entity-level DPA.

Breach Notification — 72 Hours

In the event of a personal data breach at Aeterna Data, the client is notified within 72 hours of Aeterna Data becoming aware of the breach — consistent with GDPR Article 33 timelines. Breach notification procedures are specified in the DPA.

Data Minimisation in Processing

Annotators are assigned access to only the data items required for their annotation task. Where the platform supports task-level data scoping, annotators do not have access to the full dataset beyond their assigned task queue.

Engagement End — Data Deletion

Upon engagement end, Aeterna Data confirms in writing that no copies of client data are retained in any Aeterna Data system or annotator device. Access credentials are revoked and the deletion confirmation is provided within the timeline specified in the SOW.

Sub-Processing Under the SCCs

Clause 9 of the EU SCCs Module 2 governs sub-processing — the engagement of further processors by the data importer (Aeterna Data) to carry out processing activities on behalf of the data exporter. The SCCs provide two options: a general authorisation for sub-processing (where the controller has pre-approved sub-processor engagement subject to specific conditions) or a specific authorisation requirement for each individual sub-processor.

Aeterna Data's standard DPA uses the specific authorisation model — meaning Aeterna Data will not engage any sub-processor for processing client personal data without prior written approval from the client. Sub-processors in the context of Aeterna Data's annotation services are typically platform providers whose infrastructure is used in the annotation workflow.

Individual Annotators and Sub-Processing

Individual annotators engaged by Aeterna Data as independent contractors who process client personal data as part of the annotation task are not sub-processors in the GDPR sense — they are natural persons acting under the authority of and on behalf of Aeterna Data, bound by individual NDAs and the DPA's security provisions. This is consistent with GDPR Article 29, which permits processors to engage natural persons to process personal data provided those persons are contractually bound to process only on the controller's instructions.

Sub-Processor List

Aeterna Data's current approved sub-processor list — where any sub-processor is engaged — is maintained and made available to clients on request via the DPA review process. Clients are notified in writing at least 14 days before any new sub-processor is engaged, allowing time to object if the new sub-processor raises concerns.

Supervisory Authority and Jurisdiction

Under Clause 13 of the EU SCCs Module 2, the supervisory authority of the member state in which the data exporter is established has authority over the SCCs. If multiple EU member state supervisory authorities could claim jurisdiction, the parties may designate a lead supervisory authority.

Aeterna Data's standard SCCs designate the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) as the lead supervisory authority, and Dutch law as the governing law of the SCCs. For clients established in other EU member states, the SCCs can be executed with the relevant national supervisory authority designated instead — this is specified during DPA negotiation.

Competent Courts

Under Clause 18 of the SCCs, disputes arising from the SCCs that cannot be resolved through cooperation between the parties and the supervisory authority are subject to the jurisdiction of the courts of the member state whose law governs the SCCs. For Aeterna Data's standard SCCs under Dutch law, this means the competent courts of the Netherlands. Data subjects may bring proceedings before the courts of any EU member state in which they reside.

Cooperation with Supervisory Authorities

Aeterna Data is obligated under Clause 14 of the SCCs to make itself available to the competent supervisory authority on request, to respond to supervisory authority enquiries, to abide by supervisory authority decisions, and to submit to audits and inspections by the supervisory authority. This obligation is binding and cannot be contractually limited or excluded.

EU AI Act Intersection

The EU AI Act and the EU SCCs operate in parallel — and for AI teams building high-risk systems with personal data, both frameworks are simultaneously applicable to the training data annotation pipeline. The EU AI Act's data governance requirements for high-risk AI systems (Article 10) require documented quality measures for training data. The EU SCCs establish the legal basis for the transfer of personal data used in that training.

The practical consequence is that for an EU AI team outsourcing annotation of personal data to Aeterna Data — for example, a Dutch healthtech company annotating medical records for a diagnostic AI system — the engagement requires both the EU SCCs (for the data transfer legal basis) and documented IAA measurement (for the EU AI Act data quality requirement). Aeterna Data delivers both as integrated parts of every engagement.

Training Data Legal Basis

The EU SCCs establish the legal basis for transferring personal data in the training dataset from the EU client to Aeterna Data for annotation. Without valid SCCs, the transfer of personal data for annotation is a GDPR violation — regardless of the quality of the annotation work performed.

Data Quality Documentation

The EU AI Act requires high-risk AI providers to document the quality measures applied to training data. Aeterna Data's IAA reports — delivered with every batch — constitute the quality documentation required. The SCCs and the IAA reports together provide both the legal basis and the quality audit trail.

Processor Accountability

The EU AI Act requires providers of high-risk AI systems to ensure that third parties involved in the training data pipeline are contractually accountable. The DPA and EU SCCs establish precisely this accountability — with binding obligations on Aeterna Data that the client can enforce.

EU AI Act high-risk system requirements take full effect August 2, 2026. For AI teams annotating personal data for high-risk applications within scope of the Act, the time to establish a compliant annotation processor relationship with documented IAA measurement is before the deadline. Procurement and legal review typically takes 4–8 weeks.

How Aeterna Data Executes the SCCs

The EU SCCs are not an afterthought in Aeterna Data's engagement process. They are executed as a standard step — before any personal data is shared — as part of the staged contract execution that governs every engagement.

Stage 01

Discovery Call

The discovery call establishes whether your project involves personal data processing. If it does — or if there is any ambiguity — we proceed with the full DPA and EU SCCs regardless. It is safer to have them in place than to determine after the fact that they were needed.

Stage 02

DPA and SCCs Drafted

Aeterna Data provides a standard DPA with EU SCCs Module 2 annexed. The SCCs are the Commission's standard text — unmodified. The DPA covers project-specific processing details: data types, processing purposes, security measures, and sub-processor rules.

Stage 03

Legal Review and Execution

The client's legal team reviews the DPA and SCCs. Standard review period: 1–3 business days. Both documents are executed electronically. No in-person signature required. Once executed, the SCCs provide the legal basis for all personal data transfers in the engagement.

Stage 04

Ongoing Compliance

Aeterna Data maintains compliance with SCC obligations throughout the engagement — including breach notification within 72 hours, sub-processor notification 14 days in advance, data subject rights assistance, and written deletion confirmation at engagement end.

Common Questions from Legal Teams

The following questions are frequently raised by client legal and compliance teams during DPA and SCC review.

Are Aeterna Data's SCCs the standard Commission text or a custom version?

The EU SCCs we use are the standard text adopted under Commission Implementing Decision EU 2021/914, unmodified. We do not use a custom or abbreviated version of the SCCs. The standard text is used in full, with Module 2 selected and the annexes completed with project-specific information.

Which module applies to our engagement?

Module 2 — Controller-to-Processor — applies to all standard Aeterna Data client engagements. Your organisation is the data controller (data exporter). Aeterna Data is the data processor (data importer). If your organisation is itself a processor acting on behalf of a controller, Module 3 may apply — this is assessed during the DPA negotiation.

Do we need to conduct a Transfer Impact Assessment?

Following Schrems II, EU data exporters are responsible for assessing whether the law of the destination country prevents the data importer from fulfilling SCC obligations. Aeterna Data has prepared a Transfer Impact Assessment for Indonesia that is available to clients on request. Whether your organisation needs to conduct its own TIA depends on your internal DPO's assessment and your supervisory authority's guidance.

Can we use our own DPA template rather than Aeterna Data's?

Yes. We will review client-provided DPA templates. Where a client DPA template is used, we verify that it meets GDPR Article 28 requirements and that the EU SCCs Module 2 are correctly annexed. The SCCs themselves are always the standard Commission text — neither party can modify the standard clauses.

Who is the lead supervisory authority?

Aeterna Data's standard SCCs designate the Dutch Data Protection Authority (AP) and Dutch law. For clients established in other EU member states, the relevant national authority can be designated instead — specified during DPA negotiation.

How are annotators bound by the SCCs?

Individual annotators are not parties to the SCCs — they are natural persons acting under Aeterna Data's authority and bound by individual NDAs. Aeterna Data is responsible under the SCCs for ensuring that annotators comply with the same data protection obligations that Aeterna Data has accepted — which it does through individual NDAs and internal processing protocols.

What happens if there is a data breach?

In the event of a personal data breach, Aeterna Data notifies the client within 72 hours of becoming aware of the breach — consistent with GDPR Article 33. The notification includes the nature of the breach, the categories and approximate number of data subjects concerned, likely consequences, and measures taken or proposed to address the breach.

What happens to the data at engagement end?

Upon engagement end, Aeterna Data provides written confirmation that all client data has been deleted from any Aeterna Data system or annotator device, within the timeline specified in the SOW. The timeline is typically 5 business days after the final delivery date. No copies are retained unless retention is specifically required by applicable law.

Ready to Review the Contract Stack?

DPA and EU SCCs Module 2 available for legal review before any commitment. NDA signed first. DPA and SCCs after discovery call. No data shared until both documents are executed.

CELEXSchrems IIDutch DPA