# Standard Contractual Clauses (SCCs) — EU Commission 2021

**For the transfer of personal data from the European Economic Area (EEA) to third countries that do not have an adequacy decision under Article 45 GDPR.**

This document is a Corvalon-prepared **template** that incorporates the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021 (the "2021 SCCs"). The 2021 SCCs are mandatory; this template wraps them with Corvalon-specific Annexes (Part B below) and the module selection that applies to Corvalon's processing relationship with its EEA-resident customers.

---

## How to use this template

1. **Read first:** the Data Processing Agreement (`DPA_Template.md`) and the Sub-Processor List (`Sub_Processor_List.md`). The SCCs do not replace the DPA; they supplement it for international transfers.
2. **Confirm the module:** Corvalon defaults to **Module Two — Transfer Controller to Processor** because EEA-resident customers are the controllers of their employee data, and Corvalon processes that data on their behalf. If your relationship is different (e.g., Corvalon receives controller-to-controller data), engage Corvalon Legal before signing.
3. **Fill the placeholders** in Part B (Annexes I, II, III) below. Placeholders are `[in brackets]`.
4. **Attach as an exhibit** to the DPA. The SCCs are incorporated by reference; this exhibit identifies the parties, the data transferred, and the supplementary measures.
5. **Pair with a Transfer Impact Assessment** (`Transfer_Impact_Assessment.md`) per EDPB Recommendations 01/2020. The TIA is a separate deliverable from the SCCs themselves; both are required.
6. **For UK-controller data:** use this document together with the UK IDTA Addendum (`UK_IDTA_Addendum.md`), which modifies the 2021 SCCs for UK GDPR purposes.

---

## Part A — Incorporation of the 2021 SCCs

The Customer ("data exporter") and Corvalon, Inc. ("data importer") agree that:

1. The 2021 SCCs adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are **hereby incorporated by reference** into and form an integral part of the Data Processing Agreement between the parties.
2. The applicable module is **Module Two — Transfer Controller to Processor**.
3. Where the 2021 SCCs require party selection (Clause 7 — Docking Clause, Clause 9(a) — General Written Authorisation, Clause 11 — Independent Recourse Mechanism, Clause 17 — Governing Law, Clause 18 — Choice of Forum and Jurisdiction), the parties make the elections set out in the Election Table below.
4. Where the 2021 SCCs require Annexes (I, II, III), the parties adopt the Annex contents in Part B below.
5. In the event of any conflict between (a) the 2021 SCCs and (b) the DPA or any other Customer-Corvalon agreement, the 2021 SCCs prevail with respect to international transfers from the EEA.

**Official text of the 2021 SCCs:** https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (always consult the official EU OJ version — this template does not reproduce the operative clauses verbatim).

### Election Table

| Clause | Topic | Election |
|---|---|---|
| 7 | Docking Clause (additional entities joining post-signing) | **Opted in.** Additional Corvalon affiliates listed on the Sub-Processor List may dock to the SCCs by countersigning Annex I.A. |
| 9(a) | Sub-processor authorisation method | **Option 2 — General written authorisation.** Corvalon maintains the Sub-Processor List at the trust center URL listed in the DPA; new sub-processors are added with 30 days' prior written notice per DPA §6.1. |
| 11 | Independent recourse mechanism | **Not applied.** Data subjects retain the direct rights set out in Clause 11(a), and may complain to the Customer's lead Supervisory Authority. |
| 17 | Governing law of the SCCs | **Law of the EU Member State in which the Customer's establishment is located.** Where the Customer is established in multiple Member States, the law of the lead establishment under Article 4(16) GDPR. |
| 18 | Choice of forum and jurisdiction | **Courts of the EU Member State whose law governs the SCCs under Clause 17.** Without prejudice to a data subject's right to bring proceedings in their habitual residence under Clause 18(c). |

---

## Part B — Annexes

### Annex I — List of Parties; Description of Transfer; Competent Supervisory Authority

#### A. List of Parties

**Data Exporter (Controller):**

- Name: `[Customer Legal Name]`
- Address: `[Customer Registered Address]`
- Contact person: `[Name, Title, Email]`
- Activities relevant to the transfer: Engages Corvalon to provide human resource management, payroll, benefits, time-and-attendance, talent acquisition, performance management, and compliance reporting services for its EEA-resident workforce. Acts as Controller of employee personal data under Article 4(7) GDPR.
- Role: **Controller**
- Signature & date: `[Signature]` / `[Date]`

**Data Importer (Processor):**

- Name: Corvalon, Inc.
- Address: `[Corvalon Registered Address — to be confirmed post-LLC migration]`
- Contact person: `[Privacy Officer Name], privacy@corvalonhrm.com`
- Activities relevant to the transfer: Provides the Corvalon HRM Platform (SaaS) to the Customer. Processes Customer's employee personal data per the DPA and the underlying Master Services Agreement. Processing locations: AWS us-east-1 (Virginia, USA) for primary processing; backup and disaster recovery in AWS us-west-2 (Oregon, USA) once cross-region replication is enabled per CMP-09. No EEA processing region currently offered (see DPA §6 for Sub-Processor List).
- Role: **Processor**
- Signature & date: `[Signature]` / `[Date]`

#### B. Description of Transfer

- **Categories of data subjects:** Current and former employees, job applicants, contractors and contingent workers, dependents and beneficiaries enrolled in employer-sponsored benefits, emergency contacts. (Mirrors DPA §3.)
- **Categories of personal data:** Identity (name, date of birth, employee ID, photo); contact (email, phone, address); employment (title, department, hire date, status, manager); financial (bank account numbers, salary, tax withholdings) — **stored encrypted via Vault Transit with per-tenant key derivation**; government IDs (national ID number, passport, driver's licence) — **encrypted**; benefits enrolment and dependents; performance reviews and goals; time and attendance records; recruiting data (resumes, interview notes, offer details, EEO data where the Customer collects it).
- **Sensitive data:** Health-related data (FMLA records, workers' compensation claims, ADA accommodations); biometric data (if the Customer enables biometric time-clock per BIPA workflow, see DPA Schedule); EEO data classified as special category under Article 9 GDPR. Sensitive categories are encrypted at rest with per-tenant key derivation.
- **Frequency of transfer:** Continuous (on-demand) for the duration of the MSA.
- **Nature of processing:** Automated and manual operations: collection, storage, retrieval, encryption, pseudonymisation, aggregation, analysis, transmission, erasure, destruction.
- **Purpose of processing:** Service provision per the MSA — payroll calculation and disbursement; benefits administration; time-and-attendance; talent acquisition; performance management; compliance reporting (EEO-1, ACA 1095-C, W-2, OSHA 300A, etc.); AI features with explicit Customer opt-in.
- **Duration of processing / retention:** Duration of the MSA plus the retention periods set out in DPA §5, then deletion or return per DPA §10.
- **Sub-processors:** As listed in `Sub_Processor_List.md`; recipients in the USA include AWS (us-east-1, us-west-2), Stripe (billing — limited to billing contact data, not employee data), and others as listed. Updated with 30 days' prior notice per DPA §6.

#### C. Competent Supervisory Authority

The competent Supervisory Authority is the Supervisory Authority of the EU Member State where the Customer (data exporter) has its main establishment under Article 4(16) GDPR, OR the Supervisory Authority designated by the Customer in writing to Corvalon prior to signature. Default for Customers without a single main establishment: `[Customer to specify; default = the Supervisory Authority of the Member State where the Customer's lead privacy officer is based]`.

---

### Annex II — Technical and Organisational Measures (TOMs)

Corvalon implements the following technical and organisational measures to ensure an appropriate level of security per Article 32 GDPR and the 2021 SCCs Clause 8.6:

#### 1. Encryption

- **At rest:** AES-256 database encryption (AWS RDS). Vault Transit field-level encryption for sensitive data (SSN, bank accounts, EIN, MFA secrets, biometric templates) with per-tenant key derivation. Per-tenant data keys are wrapped under tenant-scoped Vault master keys.
- **In transit:** TLS 1.2+ on all connections (client→ALB, ALB→ECS, ECS→RDS, ECS→Vault, ECS→Kafka pre-D-521). HTTPS-only on the public API; webhook receivers must present valid HTTPS endpoints (D-499 GAP-007). PostgreSQL TLS verify-full/verify-ca/require enforced at startup (DPA §7.1).

#### 2. Pseudonymisation

- Employee identifiers (`user_id`, `person_id`) are UUID v4 surrogate keys; correlation to natural-person identity requires access to the tenant's `users` and `persons` tables which are gated by RBAC + RLS.
- Sensitive fields (SSN, bank accounts, EIN) are stored as encrypted blobs; decryption requires both the tenant's Vault master key access AND the application-level role-based permission to read the field.

#### 3. Access Control

- 15-role RBAC with field-level security per `internal/rbac/fieldsecurity.go`.
- Multi-factor authentication enforced for 10 of 15 roles (HR Admin, Payroll Admin, System Admin, HR Generalist, Benefits Specialist, Compensation Analyst, Payroll Specialist, Compliance Officer, Grant Manager — see DPA §7.2).
- Argon2id password hashing (D-355). Account lockout after configurable failed attempts.
- JWT access tokens with 15-minute expiry; refresh tokens with sliding session per tenant policy.
- Per-tenant SSO support (OIDC + SAML 2.0) with optional `force_sso` per D-537.

#### 4. Tenant Isolation

- Schema-per-tenant database architecture (`t_<slug>` schemas, ~303 tables per tenant) per D-345.
- PostgreSQL Row-Level Security (RLS) as defense-in-depth, enforced under `hrm_app` role which lacks `BYPASSRLS`.
- Per-tenant Vault Transit key derivation: each tenant's sensitive data is encrypted with keys derived from a tenant-scoped master key.

#### 5. Logging & Monitoring

- Append-only audit trail with 7-year retention. `hrm_app` role has INSERT+SELECT only on `audit_log`; no DELETE/UPDATE grants (D-498).
- Bi-temporal versioning (valid_from/valid_to + system_from/system_to) on all mutable entities for time-travel reconstruction of historical state.
- OpenTelemetry distributed tracing with tenant_id propagation.
- SIEM admin-action detector logs all System Admin operations.

#### 6. Integrity & Confidentiality

- Continuous vulnerability scanning: SAST (Semgrep), DAST (ZAP baseline + full), dependency audit (Trivy, govulncheck, Dependabot, npm audit).
- Pre-commit hooks: test-coverage gate (D-525) + staged-file lint (D-538) — all changes pass before they can be committed.
- All commits require code review through GitHub PR; CI gates on lint, build, test, and cross-layer drift checks.

#### 7. Resilience & Recovery

- RDS automated backups with 30-day retention (CMP-09, D-524). AWS Backup vault provides cross-region copy to us-west-2 for the production environment.
- RDS Multi-AZ failover for production.
- ECS service health checks with automatic task replacement.
- DR runbook documented; quarterly drills planned (OP-02 — operator-scheduled).

#### 8. Personnel

- Background checks for personnel with production data access.
- Annual security awareness training including handling of personal data.
- Least-privilege production access; per-action approval via change-management workflow.

#### 9. Sub-processor Management

- Sub-processors listed in `Sub_Processor_List.md`; new sub-processors added with 30 days' prior notice per DPA §6.
- Sub-processors are bound by data protection obligations no less protective than this Annex II.

#### 10. Cross-Border Transfer Safeguards

- Where personal data is transferred from the EEA to the USA (or other third country), the 2021 SCCs (this document) apply.
- For each transfer, Corvalon maintains a Transfer Impact Assessment per `Transfer_Impact_Assessment.md` and the supplementary measures identified therein.

---

### Annex III — List of Sub-processors

The Customer authorises Corvalon to engage the sub-processors set out in `Sub_Processor_List.md`. The list as in effect on the date of this exhibit is incorporated by reference; the current version is available at the trust center URL specified in the DPA.

For each sub-processor, the following information is maintained on the Sub-Processor List:

- Name and registered office
- Description of processing performed
- Categories of personal data processed
- Location of processing
- Sub-processor's own technical and organisational measures (where contractually disclosed)

**Material changes** (addition or removal of a sub-processor; change in processing location) are notified to the Customer with at least 30 days' prior written notice, during which the Customer may object per DPA §6.3.

---

## Appendix — Module selection rationale

Corvalon's processing relationship with EEA-resident customers is **Controller-to-Processor** under Module Two of the 2021 SCCs because:

1. The Customer (employer) determines the **purposes** of processing (which employees to hire, what compensation to pay, what benefits to offer, what performance metrics to track). This makes the Customer the Controller under Article 4(7) GDPR.
2. Corvalon determines the **means** of processing only at the technical level (database design, encryption mechanisms, audit logs) — Corvalon does not determine which data subjects are added, what data is collected, or what business decisions are made from the data.
3. Corvalon does not use Customer personal data for its own purposes. AI features that ingest Customer data (per DPA AI usage clauses) are scoped to delivering services back to that Customer and require explicit tenant opt-in.

If the relationship changes (e.g., Customer enables a Corvalon-controlled feature that processes data on Corvalon's own legal basis), the parties will execute Module One (C2C) or Module Four (P2C) as appropriate.

---

## References

- Commission Implementing Decision (EU) 2021/914 — https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
- EDPB Guidelines 07/2020 on the concepts of controller and processor — https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-072020-concepts-controller-and-processor-gdpr_en
- EDPB Recommendations 01/2020 on supplementary measures — https://www.edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en
- DPA Template: `DPA_Template.md`
- Sub-Processor List: `Sub_Processor_List.md`
- Transfer Impact Assessment template: `Transfer_Impact_Assessment.md`
- UK IDTA Addendum (for UK-controller data): `UK_IDTA_Addendum.md`

---

**Document status:** Template. Requires customisation per Customer in Annex I before execution. Engage Corvalon Legal before deviating from the module selection or election table.

**Last revised:** 2026-05-20 (D-540).
