Firm News
Bridge the Gap 2026 – Fordham School of Law
January 17, 2026 | 9:55 AM – 11:10 AM ET
Virtual
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.
Articles + Publications September 27, 2022
Don’t Hyperventilate. There are new United Kingdom (UK), European Union (EU), U.S., and global regulatory requirements that just went into effect or will be effective before or soon after year-end that will impact contracts addressing privacy and data protection, including but not limited to:
New EU standard contractual clause (SCC) modules;
New UK personal data transfer mechanisms;
New enforcements and contractual requirements for service providers handling personal information in California (and other U.S. states); and
Additional countries globally introducing their own forms of SCCs and personal data transfer mechanisms.
This alert will help you keep track of the deadlines and develop simple step-by-step, global, holistic approaches for implementing the new requirements in a timely and cost-effective manner to meet all of the 2022 and other subsequent deadlines.
Post-Brexit UK Data Transfer Contract Requirements Now in Effect and Required! If you’re relying on the old versions of the EU SCCs to transfer personal data out of the UK, the deadline has passed. Specifically, for all new agreements after September 22, 2022, you can only use the new UK contract data transfer mechanisms. Existing agreements must be updated by March 21, 2024.
Two Options for UK Data Transfer Mechanisms. After Brexit, the UK passed its own version of the EU’s GDPR, as well as two mechanisms for transferring personal data out of the UK:
Option 1: International Data Transfer Agreement (UK IDTA). The UK IDTA is the UK version of the EU SCCs, and largely is a standalone data transfer mechanism for UK personal data compliance only.
Option 2: The UK Addendum. The UK International Data Transfer Addendum (UK Addendum) is a much more streamlined approach that gets attached as an additional addendum to a new EU SCC module and covers both EU and UK compliance.
Other Notable Year-End or Soon-After Deadlines. In addition to the newly effective UK requirements, to keep data transfers flowing, companies should be aware of the following additional contractual obligations:
Five Emerging Best Practices to Act on Now to Keep the Data Flowing. Rather than rolling out updated contracts, master service agreements, and data processing addendums at the time of each new requirement, many companies are taking global, holistic approaches. The following are five emerging best practices used by other companies for implementing the new requirements in a cost-effective and timely manner to meet all deadlines in one coordinated set of initiatives:
Identify Regulated and High-Risk Areas by Developing and Updating Data Inventory and Records of Processing. The first step companies are taking to comply with the UK, EU, and other global data transfer requirements is to establish and maintain an inventory of the personal data that your company processes and to document (e.g., through data mapping, records of processing, data inventory, and other procedures) how the personal data is transferred to/from vendors and third parties in/outside of the UK, EEA, or other regulated jurisdiction.
Update DPAs and Existing Agreements for Multiple Law Changes Simultaneously With a Cost-Effective and Global Approach. The second step companies are taking is to update form agreements/MSAs, existing contracts, and template data processing addendums (DPAs) to contemplate both the new privacy laws and updates to existing privacy laws. Instead of creating undue EU and UK-specific obligations and rolling out new templates and updates multiple times with every new law, many companies are taking a holistic approach and updating form agreements and DPAs designed also to comply with the California Privacy Rights Act (CPRA)/California Consumer Privacy Act (CCPA) and/or other pending, new, or updated privacy laws (e.g., UK post-Brexit, Thailand, Brazil, Saudi Arabia, Egypt, New Zealand, Singapore, South Africa, or other jurisdictions).
Implementation Tip: Develop Upstream and Downstream Forms of DPAs. Many companies typically develop downstream DPA for when they entrust/share customer, consumer, and employee personal information with a vendor that incorporates many security, indemnification, and other provisions that go beyond what is required under the law. Increasingly, many companies that receive such data (e.g., service providers and vendors) are developing lighter touch DPAs that stick to only the minimum requirements in the hopes to use their template with customers to avoid heightened obligations, risk, and exposure.
Establish a Risk-Based Implementation Plan. Given the potential for an overwhelming volume of legacy contracts that will have to be updated for UK, EU, U.S., and other laws, many companies are creating a phased, risk-based implementation plan to update legacy agreements. For example, high-risk, business critical agreements and/or agreements with significant EU and/or UK data flows or processing are done first, while other agreements/DPAs that use the old SCCs as the transfer mechanism are done next or, if lower risk or business impact, deferred to contract renewal.
Implementation Tip: Define Secondary Use, Sharing, and Sale Rights. Given the increasing use of data by service providers for analytics and/or other secondary uses, analyze the new versions of the SCCs and ensure that the appropriate version of the new SCCs is implemented (and also aligns with your data use, sharing, and sales position under CCPA/CPRA and other U.S. state laws).
Create or Update Intra-Group Agreements. Many companies have established intra-group agreements (IGAs) based on the old SCCs that govern a global company’s customer and employee personal data transfers between affiliates involving EU, UK, and Swiss personal information around the world. While companies that implemented IGAs are updating them for the new EU SCC forms and the UK Addendum, other companies that previously did not have IGAs in place are increasingly implementing them as a global data transfer baseline to address EU, UK, and Swiss requirements, as well as other global requirements beyond just the EU, UK, and Switzerland.
Train Internal Stakeholders. To promote compliance and help close contract negotiations quicker and with consistency, many companies are training internal employees and contractors who may be impacted by the changes to personal data transfer practices and contractual obligations (e.g., procurement, sales, legal) on the company’s updated DPAs and the company’s approach for cross-border and global data transfers. Many companies are also creating and/or updating prepared statements that can be issued to customers and data exporters to explain their DPA updates, as well as describing the company’s approach to protecting EU, UK, and other personal data and dealing with law enforcement requests.
Questions. To learn more about the impact on your company and how to implement the new SCCs and/or the UK Addendum, please contact Jim Koenig, Joel Lutz, Robyn Lin, or any member of our Privacy + Cyber team.
Firm News
Bridge the Gap 2026 – Fordham School of Law
January 17, 2026 | 9:55 AM – 11:10 AM ET
Virtual
Sponsored Events
ACG OC – 23rd Annual Private Equity Marketplace Deal Flow & Wine Tasting
January 15, 2026 | 5:30 PM – 8:30 PM PT
Ritz-Carlton
1 Ritz Carlton Drive, Dana Point, CA 92629
Articles + Publications
A Costly Recipe: Flat-Rate Pay, Long Hours, and Retaliation Lead to DOL Consent Judgment
December 19, 2025
Articles + Publications
Liquidate Now, Litigate Later: Court Rejects Bid to Halt Liquidation of Entries Subject to IEEPA Tariffs
December 19, 2025
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.