Legal

Standard Contractual Clauses

Last updated: 2026-08-24

Where Zotniq processes Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland, the transfer of that data to a country not recognised as providing an adequate level of protection is governed by the Standard Contractual Clauses ("SCCs") adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, incorporated into the Zotniq Data Processing Agreement by reference.

Applicable modules

  • Module 2 (controller-to-processor) applies to transfers where Customer is the data controller and Zotniq is the data processor. This is the default posture for Zotniq customers.
  • Module 3 (processor-to-processor) applies where Customer is itself a processor for a downstream controller, and engages Zotniq as a sub-processor of that Customer's controller.

Official text

Zotniq does not rewrite the SCCs. The controlling text is the version published by the European Commission at eur-lex.europa.eu/eli/dec_impl/2021/914/oj. References to specific clauses in the DPA (for example, breach notification, sub-processor authorisation, audit rights) map to the numbered clauses in the official SCC text.

Annexes populated for Zotniq

The SCCs contain three Annexes that must be completed for each processing arrangement. For the Zotniq service, they are populated as follows:

  • Annex I — Description of processing. Data exporter is Customer. Data importer is Zotniq. Categories of data subjects, categories of personal data, nature and purpose of processing, and duration are as set out in Annex A of the DPA.
  • Annex II — Technical and organisational measures. As set out in Annex C of the DPA (on-device inspection, TLS 1.3, per-region residency, incident response, access control, backups).
  • Annex III — List of sub-processors. The current list is maintained at zotniq.ai/legal/subprocessors and reproduced in Annex B of the DPA.

United Kingdom

For Customer Personal Data originating in the United Kingdom, the UK International Data Transfer Addendum ("IDTA") issued by the UK Information Commissioner's Office applies as the transfer mechanism, incorporating the same SCCs as varied by the IDTA. The IDTA text is available at ico.org.uk.

Switzerland

For Customer Personal Data originating in Switzerland, the SCCs apply with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) for the Swiss Federal Act on Data Protection (nFADP).

Contact

Questions about SCCs, transfer impact assessments, or supplementary measures: [email protected]

Legal and contract questions: [email protected]