Skip to main content
Category: International Data Transfers

Ad Hoc Contractual Clauses

Also known as: Ad Hoc Clauses
Simply put

Ad hoc contractual clauses are custom-drafted contract terms that organizations create to govern the transfer of personal data, rather than relying on pre-approved standard templates. In the EU data protection context, they have been used to set out the responsibilities between parties involved in processing personal data, such as between a processor and a sub-processor. Their content is negotiated for a specific arrangement rather than adopted from a fixed, officially approved form.

Formal definition

Ad hoc contractual clauses are bespoke contractual provisions drafted to establish data protection obligations between parties, typically in the context of personal data transfers. In one documented usage, draft ad hoc clauses were prepared by the Article 29 Working Party to address transfers from processors to sub-processors established outside the EU, clarifying, for example, that the data controller must authorize sub-processing in writing (whether by general or specific authorization). Such clauses are distinct from Standard Contractual Clauses (SCCs), which are pre-formulated model clauses intended to support compliance with Regulation (EU) 2016/679 (EU GDPR); ad hoc clauses are individually negotiated rather than adopted from an officially issued template. The term is also used outside the data protection field, for instance to describe ad hoc arbitration clauses in commercial contracts, which are unrelated to data transfer mechanics. This entry describes the concept and its documented usage only; it does not address the current legal validity, approval status, or enforceability of any specific ad hoc clause set, nor the full mechanics of lawful cross-border transfer, controller and processor obligations in detail, retention, or enforcement. Treatment differs across jurisdictions and regimes, and validity depends on context and applicable law at the time of use.

Why it matters

For organizations transferring personal data across borders, the choice between bespoke contractual terms and pre-approved templates carries real accountability consequences. Ad hoc contractual clauses represent an attempt to tailor data protection obligations to a specific processing arrangement rather than adopting a fixed, officially issued form. This flexibility can be attractive where a standard template does not neatly map to the relationship in question, such as a processor engaging a sub-processor established outside the EU. However, custom drafting generally shifts the burden of demonstrating adequacy onto the parties themselves, and the accountability principle under the EU GDPR requires demonstrable evidence that a transfer mechanism is appropriate, not merely a well-worded contract.

Understanding this term also matters because it is frequently confused with Standard Contractual Clauses (SCCs). SCCs are pre-formulated model clauses issued to support compliance with Regulation (EU) 2016/679, whereas ad hoc clauses are individually negotiated. Treating the two as interchangeable can lead a compliance team to assume a level of pre-vetted approval that does not exist for a custom-drafted set. The documented usage of ad hoc clauses includes draft clauses prepared by the Article 29 Working Party to address processor-to-sub-processor transfers, which clarified, for example, that the data controller must authorize sub-processing in writing, whether through general or specific authorization.

A further source of confusion is that the same phrase appears outside the data protection field entirely. "Ad hoc clauses" is also used to describe ad hoc arbitration clauses in commercial contracts across jurisdictions, which are unrelated to data transfer mechanics. Practitioners should confirm which sense is meant before relying on the term. This entry does not address the current legal validity, approval status, or enforceability of any specific ad hoc clause set, nor the full mechanics of lawful cross-border transfer; those depend on the applicable law at the time of use.

Who it's relevant to

Data Protection Officers and Privacy Counsel
DPOs and privacy lawyers evaluating cross-border transfer arrangements need to distinguish ad hoc clauses from Standard Contractual Clauses and understand that custom drafting does not carry the pre-approved status of an issued template. They should note the Article 29 Working Party's documented usage in the processor-to-sub-processor context, including the requirement for written controller authorization of sub-processing, while confirming current validity against applicable law rather than assuming the historical draft clauses remain in force.
Vendor and Contract Management Teams
Teams negotiating agreements involving processors and sub-processors outside the EU should recognize where bespoke data protection terms are being proposed instead of standard clauses, and ensure that responsibilities and authorization requirements are clearly allocated. Because accountability generally requires demonstrable evidence, they should retain documentation of how a chosen mechanism was assessed.
Compliance and Governance Leads
Those responsible for demonstrating accountability need to understand that a well-drafted custom clause set is not, by itself, proof that a transfer is lawful. Governance covers documenting the basis and evidence for transfer decisions, which is distinct from the security controls applied to the data itself. They should also be alert that the same term is used for unrelated ad hoc arbitration clauses in commercial contracts.

Inside Ad Hoc Contractual Clauses

Bespoke Transfer Terms
Contractual provisions drafted specifically for a given data transfer arrangement, rather than adopting pre-approved template wording. Under the EU GDPR, such clauses may serve as a transfer mechanism for personal data to third countries, but generally require prior authorisation from the competent supervisory authority. Treatment under the UK GDPR follows a broadly similar structure but is administered separately by the UK authority, and neither approach maps directly onto obligations under regimes such as the CCPA/CPRA or HIPAA.
Controller and Processor Obligations
Allocation of responsibilities between the parties, identifying which entity acts as data controller (determining purposes and means) and which acts as data processor (processing on the controller's documented instructions). Ad hoc clauses should make this allocation explicit, since the underlying accountability for the transfer generally rests with the exporting controller regardless of the drafting.
Data Subject Safeguards
Provisions intended to ensure that individuals whose personal data is transferred continue to benefit from an appropriate level of protection. These typically address enforceable rights and available redress, though the specific content depends on the arrangement and the jurisdictions involved.
Authorisation Requirement
A distinguishing feature of ad hoc clauses under the EU GDPR framework: unlike Standard Contractual Clauses adopted by the European Commission, tailored clauses generally do not carry pre-existing approval and typically must be submitted for authorisation before they can be relied upon as a valid transfer mechanism.

Common questions

Answers to the questions practitioners most commonly ask about Ad Hoc Contractual Clauses.

Are ad hoc contractual clauses the same as the Standard Contractual Clauses issued by the European Commission?
No. Standard Contractual Clauses (SCCs) are pre-approved template sets adopted by the European Commission (and, separately, the UK's International Data Transfer Agreement or Addendum under the UK GDPR), which can be relied upon without prior authorisation when used unmodified in substance. Ad hoc contractual clauses are bespoke terms drafted by the parties themselves. Under the EU GDPR framework, ad hoc clauses used as a transfer safeguard generally require authorisation from the competent supervisory authority before they can be relied upon, whereas SCCs do not. Treating the two as interchangeable is a common error. This entry does not cover the detailed authorisation procedure or how it differs across supervisory authorities.
Do ad hoc contractual clauses on their own guarantee that a cross-border transfer is compliant?
No single mechanism guarantees compliance. Ad hoc clauses are one possible safeguard among the transfer tools recognised in the EU and UK GDPR frameworks, but their use typically requires supervisory authority authorisation and, following the relevant case law affecting international transfers, may also require a transfer impact assessment and supplementary measures depending on the destination and the risks involved. Compliance depends on context, jurisdiction, and implementation. This entry does not address the substance of transfer impact assessments, supplementary measures, or enforcement outcomes.
When might an organisation choose ad hoc clauses instead of Standard Contractual Clauses?
Organisations generally consider ad hoc clauses where a standard template does not fit the specific transfer scenario, party structure, or processing arrangement. Because ad hoc clauses typically require supervisory authority authorisation and bespoke drafting, they are usually a fallback rather than a default. Many organisations prefer SCCs precisely to avoid the authorisation step. The choice should be assessed case by case with legal advice; this entry does not recommend one approach over another for any given scenario.
Which party is responsible for putting ad hoc clauses in place and demonstrating their adequacy?
Responsibility generally rests with the parties to the transfer, most often the data exporter, who must be able to demonstrate that an appropriate safeguard is in place. Where the exporter is a controller and the importer a processor, the controller typically bears the primary accountability obligation to evidence the safeguard, though processors also carry obligations under their own arrangements. Accountability requires demonstrable evidence, not merely stated intent. This entry does not allocate liability for breach or specify indemnity arrangements between the parties.
What should be documented when relying on ad hoc clauses?
Organisations typically retain the executed clauses, evidence of any supervisory authority authorisation obtained, and records supporting the assessment that the arrangement provides appropriate safeguards, such as any transfer risk assessment. This documentation supports the accountability principle by making the reliance demonstrable to a supervisory authority. This entry does not prescribe retention periods for such records or the format of any inventory in which they are held.
How do ad hoc clauses interact with obligations that are separate from the transfer safeguard itself?
Ad hoc clauses address the transfer safeguard question but do not by themselves satisfy other requirements, such as identifying a lawful basis for the underlying processing, meeting transparency duties, or maintaining records of processing activities. These obligations operate independently and must be addressed on their own terms. This entry is scoped to the ad hoc clause mechanism and does not cover lawful basis selection, retention rules, or enforcement penalties.

Common misconceptions

Ad hoc contractual clauses are interchangeable with Standard Contractual Clauses and can be used freely once drafted.
They are distinct. Standard Contractual Clauses are pre-approved templates that can generally be relied upon without further authorisation, whereas ad hoc clauses are bespoke and typically require prior authorisation from the relevant supervisory authority under the EU GDPR before use. The approach differs under the UK GDPR and does not map onto non-EU regimes.
Signing ad hoc clauses guarantees the lawfulness of a cross-border transfer.
No single contractual instrument guarantees compliance. Whether a transfer is lawful depends on context, jurisdiction, the underlying lawful basis for processing, obtaining any required authorisation, and the practical protections in place. Contractual wording alone does not substitute for these conditions.
The clauses shift accountability for the transfer onto the data importer.
Contractual allocation does not remove the exporting controller's accountability. Under governance and data protection frameworks, accountability generally requires demonstrable evidence that the transfer is adequately protected, and this responsibility typically remains with the controller determining the purposes of processing.

Best practices

Confirm whether a pre-approved mechanism such as Standard Contractual Clauses would suffice before investing in bespoke drafting, since ad hoc clauses generally add an authorisation step.
Obtain the required authorisation from the competent supervisory authority under the EU GDPR (or the relevant UK authority for UK GDPR transfers) before relying on the clauses, and retain evidence of that authorisation.
Clearly identify and document each party's role as controller or processor within the clauses, and align the drafting with the actual processing arrangement.
Do not treat the clauses as a standalone compliance guarantee; assess them alongside the lawful basis, jurisdictional requirements, and practical safeguards for the specific transfer.
Maintain demonstrable evidence supporting the arrangement so that accountability obligations can be met, rather than relying on stated intent.
Scope the clauses to the transfer at hand and confirm separately how retention, cross-border transfer mechanics beyond this instrument, and enforcement considerations are addressed, as these are not automatically covered by the clauses themselves.