Scc Implementation logo

Scc Implementation

Community
mukul975
scc-implementation

Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.

Overview

Publishermukul975
RepositoryPrivacy-Data-Protection-Skills
Skill namescc-implementation
Stars
279
Forks
59
Bundled files
4
LicenseApache-2.0
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 4 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by mukul975 on GitHub. Read the source before you install it.

Installation

Install the Scc Implementation AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git /tmp/Privacy-Data-Protection-Skills
mkdir -p .claude/skills
cp -r /tmp/Privacy-Data-Protection-Skills/plugins/cross-border-transfers-skills/skills/scc-implementation .claude/skills/scc-implementation
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Scc Implementation in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Scc Implementation on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Scc Implementation is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Implementing Standard Contractual Clauses

Overview

Commission Implementing Decision (EU) 2021/914 of 4 June 2021 introduced modernised Standard Contractual Clauses (SCCs) for the transfer of personal data to third countries under Regulation (EU) 2016/679. These SCCs replaced the prior sets adopted under Directive 95/46/EC and became the mandatory instrument from 27 December 2022. The modular architecture allows parties to select the appropriate clause set based on their roles in the transfer relationship.

Module Selection Decision Framework

Module 1: Controller to Controller (C2C)

When to use: The data exporter is a controller and the data importer independently determines the purposes and means of processing the imported data as a separate controller.

Typical scenarios at Athena Global Logistics:

  • Sharing shipment tracking data with overseas partner logistics firms that independently process that data for their own route optimisation
  • Providing employee data to a foreign group entity that acts as an independent controller for local employment law compliance
  • Transferring customer data to an overseas insurance partner that underwrites cargo policies under its own controllership

Key Module 1 clauses:

  • Clause 8.1 — Data protection safeguards: The data importer must process data only for the specific purposes described in Annex I, with an independent legal basis under the importer's applicable law
  • Clause 8.2 — Purpose limitation: The importer shall not process data for purposes incompatible with those for which the data was transferred
  • Clause 8.3 — Transparency: The importer must provide data subjects with a copy of the clauses and Annex I information upon request
  • Clause 8.4 — Accuracy: Both parties must take reasonable steps to ensure data is accurate and up to date
  • Clause 8.5 — Duration and erasure: Data processed only for the duration specified in Annex II; erasure or return upon termination

Module 2: Controller to Processor (C2P)

When to use: The data exporter is a controller and the data importer processes data on behalf of the exporter as a processor.

Typical scenarios at Athena Global Logistics:

  • Engaging a cloud infrastructure provider headquartered in a third country to host the transport management system
  • Using an overseas payroll processing bureau to calculate salaries for locally-hired staff
  • Contracting a third-country call centre to handle customer service inquiries on behalf of the company

Key Module 2 clauses:

  • Clause 8.1 — Instructions: The processor shall process data only on documented instructions from the controller as specified in Annex II
  • Clause 8.2 — Purpose limitation: Processing solely for the specific purposes set out in Annex I
  • Clause 8.3 — Transparency: Controller must inform data subjects of the transfer and identity of the importer
  • Clause 8.5 — Sub-processing: Sub-processors only with prior specific or general written authorisation; same data protection obligations imposed by contract
  • Clause 8.6 — International onward transfers: Sub-processor transfers require the same level of protection
  • Clause 8.8 — Security: Technical and organisational measures as described in Annex II
  • Clause 8.9 — Documentation and compliance: Processor must maintain records and allow audits

Module 3: Processor to Processor (P2P)

When to use: The data exporter is a processor (acting on behalf of an EU controller) and the data importer is a sub-processor.

Typical scenarios at Athena Global Logistics:

  • The company acts as a data processor for a European shipping consortium and sub-contracts warehousing data management to a third-country sub-processor
  • A managed IT services provider contracted by the company further sub-processes personal data with an offshore development centre

Key Module 3 clauses:

  • Clause 8.1 — Instructions: Sub-processor processes only under the chain of instructions ultimately originating from the controller
  • Clause 8.5 — Onward sub-processing: Further sub-processing only with prior specific or general written authorisation from the controller (obtained through the initial processor)
  • Clause 8.8 — Security measures: Annex II security measures apply equivalently
  • Clause 8.9 — Documentation and compliance: Full audit chain maintained back to the controller

Module 4: Processor to Controller (P2C)

When to use: The data exporter is a processor and the data importer is the controller whose data is being returned or transferred.

Typical scenarios at Athena Global Logistics:

  • Returning processed analytics results to a non-EU client controller who originally provided the raw shipment data
  • A European cloud processor returning personal data to its non-EU controller client upon contract termination

Key Module 4 clauses:

  • Clause 8.1 — The importer shall process data in compliance with its obligations under the GDPR (where applicable) or equivalent standards
  • Clause 8.2 — Purpose limitation and transparency obligations on the importer as controller

Module Selection Decision Tree

START: Identify the role of the data EXPORTER (EU-based party)
  |
  ├── Exporter is a CONTROLLER
  |     |
  |     ├── Importer determines its OWN purposes → MODULE 1 (C2C)
  |     |
  |     └── Importer processes ON BEHALF of exporter → MODULE 2 (C2P)
  |
  └── Exporter is a PROCESSOR
        |
        ├── Importer is a SUB-PROCESSOR → MODULE 3 (P2P)
        |
        └── Importer is the CONTROLLER (data return) → MODULE 4 (P2C)

Annex I: List of Parties and Transfer Details

Section A — List of Parties

FieldData ExporterData Importer
NameAthena Global Logistics GmbHTransPacific Freight Solutions Ltd
AddressFriedrichstrasse 112, 10117 Berlin, Germany88 Harbour Road, Wan Chai, Hong Kong SAR
Contact personElisa Brandt, Head of Data ProtectionJames Leung, Chief Privacy Officer
Activities relevant to transferInternational freight forwarding, customs brokerage, warehouse management for European operationsRegional freight consolidation, last-mile delivery coordination, customs clearance for Asia-Pacific operations
RoleControllerProcessor (Module 2)

Section B — Description of Transfer

ElementDetail
Categories of data subjectsShipping customers (consignors and consignees), employees of customer companies, customs brokers, warehouse workers
Categories of personal dataFull name, business email, business phone number, company name, shipping address, customs identification numbers, consignment reference numbers, delivery scheduling preferences
Sensitive dataNone transferred under this agreement
Frequency of transferContinuous real-time transfer via API integration; batch file transfer daily at 02:00 UTC
Nature of processingStorage, retrieval, matching of consignment records, generation of customs documentation, delivery status tracking, exception reporting
Purpose of transferFulfilment of freight forwarding contracts requiring regional processing of shipment data for customs clearance and last-mile delivery in Asia-Pacific jurisdictions
Retention period36 months from completion of the relevant shipment, after which data is securely deleted in accordance with Annex III procedures

Section C — Competent Supervisory Authority

The competent supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), identified in accordance with Clause 13 as the supervisory authority of the Member State in which the data exporter is established.

Annex II: Technical and Organisational Measures

Measure CategorySpecific Measures Implemented
Encryption of data in transitTLS 1.3 for all API communications; SFTP with AES-256 encryption for batch transfers
Encryption of data at restAES-256 encryption on all database storage volumes; encrypted backup tapes with separate key management
Access controlRole-based access control (RBAC) with least-privilege principle; multi-factor authentication for all administrative access; quarterly access reviews
Data minimisationAPI payloads stripped of fields not required for the specific processing purpose; data masking applied to non-essential personal identifiers in development and testing environments
Logging and monitoringCentralised SIEM with 12-month log retention; real-time alerting on anomalous access patterns; daily log review by security operations centre
Incident responseDocumented incident response plan with 24-hour initial assessment SLA; notification to data exporter within 48 hours of confirmed breach; annual tabletop exercises
Physical securityISO 27001-certified data centres; biometric access controls; 24/7 CCTV surveillance; clean desk policy in processing areas
Business continuityRPO of 4 hours and RTO of 8 hours; geographically separated disaster recovery site; annual DR testing with documented results
Staff measuresMandatory data protection training upon onboarding and annually thereafter; background checks for all staff with access to personal data; confidentiality agreements
Sub-processor managementDue diligence assessment before engagement; contractual flow-down of equivalent security obligations; annual audit of sub-processor compliance

Annex III: List of Sub-Processors

Sub-ProcessorLocationProcessing ActivitySafeguard Mechanism
CloudVault Asia Pte LtdSingaporeCloud infrastructure hosting for the regional freight management platformSCCs Module 3 (P2P) executed 15 March 2025
Pinnacle Data Services Co LtdBangkok, ThailandData entry and validation for customs documentationSCCs Module 3 (P2P) executed 22 January 2025

Clause-by-Clause Implementation Checklist

Section I — General Clauses (All Modules)

ClauseSubjectImplementation Action
Clause 1Purpose and scopeConfirm selected module is recorded in the preamble; verify parties have initialled the correct module
Clause 2Effect and invariabilityVerify no modifications to the standard text; confirm any additional safeguards are in a separate addendum, not in the SCC body
Clause 3Third-party beneficiariesConfirm data subjects can enforce Clauses 1-3, 8, 9, 12, 15-17 as third-party beneficiaries
Clause 4InterpretationConfirm interpretation aligned with GDPR; terms have the same meaning as in the Regulation
Clause 5HierarchyVerify that in case of contradiction, the SCCs prevail over other contractual arrangements
Clause 6Description of transferVerify Annex I.B is complete with all required elements
Clause 7Docking clauseDetermine if additional parties will accede; if so, prepare Annex I.A amendment procedure

Section II — Obligations of the Parties

ClauseSubjectImplementation Action
Clause 8Data protection safeguardsModule-specific; verify all sub-clauses completed per selected module
Clause 9Use of sub-processorsModule 2/3: Document prior authorisation mechanism (specific or general); maintain sub-processor list; establish notification procedure for changes
Clause 10Data subject rightsEstablish procedure for the importer to handle data subject requests; define response timelines (within 30 days per GDPR Art. 12(3))
Clause 11RedressConfirm independent dispute resolution body identified; verify importer will accept jurisdiction of competent courts
Clause 12LiabilityConfirm liability allocation between parties; verify insurance or financial capacity to meet potential claims

Section III — Local Laws and Government Access

ClauseSubjectImplementation Action
Clause 14Local laws affecting complianceDocument the Transfer Impact Assessment results; identify specific laws in the importer's jurisdiction that may impinge on SCC protections
Clause 15Government access obligationsImporter must notify exporter of government access requests (unless legally prohibited); importer must challenge disproportionate requests; importer must provide transparency report

Section IV — Final Provisions

ClauseSubjectImplementation Action
Clause 16Non-compliance and terminationEstablish escalation procedure: notification → 30-day cure period → suspension → termination; data return or deletion upon termination
Clause 17Governing lawSelect law of the EU Member State of the exporter (Germany, for Athena Global Logistics)
Clause 18Choice of forum and jurisdictionSelect courts of the EU Member State of the exporter (Berlin, Germany)

SCC Execution and Record-Keeping

  1. Version control: Maintain a register of all executed SCCs with version numbers, execution dates, parties, and selected modules.
  2. Periodic review: Review all executed SCCs at least annually or upon any material change in processing, importer jurisdiction law, or sub-processor arrangements.
  3. Regulatory updates: Monitor EDPB guidance and European Commission updates for any revision to the SCC instrument or supplementary guidance.
  4. Integration with TIA: Each SCC must reference the corresponding Transfer Impact Assessment documenting the assessment of the importer's jurisdiction under Clause 14.
  5. Supervisory authority cooperation: Maintain readiness to provide all SCC documentation to the competent supervisory authority upon request under Art. 46(2)(c) and Art. 58(1).

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Scc Implementation AI skill do?

Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.

Why use Scc Implementation on TypingMind?

Because you install it once and use it with any model. Scc Implementation is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Scc Implementation in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/cross-border-transfers-skills/skills/scc-implementation. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Scc Implementation?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Scc Implementation?

As many as you like. As long as a model supports skills, you can use Scc Implementation with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Scc Implementation AI skill free?

Yes. It is published on GitHub by mukul975 under the Apache-2.0 license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇