In What Other Way, Besides an Audit, Can a Processor Demonstrate Compliance with the Requirements Arising from the SCCs?
ANSWER
A processor may rely on other mechanisms to demonstrate to the controller that it properly fulfills its obligations under the SCCs or under the GDPR directly, for example by adhering to an approved code of conduct under Article 40 GDPR or an approved certification mechanism under Article 42 GDPR.
It should be noted that this does not affect the controller's ability to decide to audit processing activities covered by the SCCs.
The above answer is based on an official document of the European Commission.
You can review it at: https://ec.europa.eu/info/sites/default/files/questions_answers_on_sccs_en.pdf
A translated version of this document is also available on our blog under the title: "Standard Contractual Clauses (SCCs) – Questions and Answers".


