(109) The controller's or processor's ability to use the standard data protection clauses adopted by the Commission or a supervisory authority should not prevent the controller or processor from incorporating the standard data protection clauses into a broader contract, such as a contract between said processor and another processor, or from adding other clauses or additional safeguards, provided that they do not directly or indirectly conflict with the standard contractual clauses adopted by the Commission or a supervisory authority or prejudice the fundamental rights or freedoms of data subjects. Controllers and processors should be encouraged to provide for additional safeguards in addition to the standard protection clauses through contractual obligations.
„We are perfectly capable of assessing the risk ourselves."
Are you sure about that?

