These questions keep landing in legal team Slack channels, compliance officer inboxes, and DPO office hours. They're coming from product teams launching new features, procurement officers vetting SaaS contracts, and HR departments rolling out global systems. The questions sound casual, but the stakes aren't.
I've gathered the most common questions teams face when dealing with the post-Schrems II reality of moving data between the EU and the U.S. The answers cite specific requirements, not general reassurances.
Do We Still Need Standard Contractual Clauses if We're Only Using U.S. Cloud Providers?
Yes. Standard Contractual Clauses (SCCs) are mandatory for EU-to-U.S. transfers unless you qualify for one of the narrow derogations in Article 49 GDPR (Informed Consent for specific transfers, contract performance, vital interests, or public interest). Chapter V GDPR doesn't exempt cloud services, and the Schrems II decision clarified that SCCs alone aren't enough.
You need SCCs plus a transfer impact assessment to evaluate whether U.S. surveillance law creates risks the SCCs can't mitigate. Document that assessment. If you identify risks, implement supplementary measures like encryption with EU-held keys, data minimization, or pseudonymization, or halt the transfer.
The recent action by the Portugal supervisory authority, which stopped census data transfers to the U.S. after complaints, shows that data protection authorities will act on transfer violations, even for government data flows.
What's a "Transfer Impact Assessment" and Do I Really Have to Do One for Every Vendor?
A transfer impact assessment evaluates whether the laws of the recipient country allow government access to your data in ways that undermine GDPR protections. The European Data Protection Board's Recommendations 01/2020 lay out the framework.
You assess:
- The nature of the data you're transferring
- The legal basis and purpose
- The recipient country's surveillance laws and their scope
- Whether the data exporter or importer could be compelled to provide access
- What supplementary measures could prevent that access
You don't need a separate assessment for every vendor if the transfer scenarios are functionally identical (same data types, same legal framework, same technical architecture). You can create a template assessment for common scenarios, then apply it with vendor-specific details. But you can't skip the exercise entirely. Supervisory authorities expect documented analysis, not checkbox compliance.
Our U.S. Vendor Says They've Never Received a FISA Request. Does That Help Us?
Not much. The absence of past requests doesn't mean future requests won't happen. Your transfer impact assessment must evaluate whether the vendor could be compelled under Section 702 of the Foreign Intelligence Surveillance Act or Executive Order 12333, not whether they have been.
The Foreign Intelligence Surveillance Court decision that renewed a surveillance program despite finding FBI employees illegally accessed email data underscores that oversight mechanisms don't always prevent access. Your assessment should assume the legal framework permits access, then determine whether your supplementary measures make that access meaningless.
If you're transferring encrypted data and the vendor never holds the decryption keys, that's a supplementary measure worth documenting. If the vendor processes data in plaintext to deliver the service, you can't rely on their clean compliance record as a safeguard.
Can We Just Get Informed Consent from Users and Skip All This?
Only if the transfer is occasional, not repetitive, and you can genuinely make the service optional. Article 49(1)(a) GDPR allows transfers based on Informed Consent, but the EDPB has made clear this derogation applies narrowly.
Consent for transfers must be:
- Separate from general service consent
- Specific about the transfer destination and risks
- Truly optional (the data subject can refuse without losing access to the service)
- Informed (you've explained the risks, including that U.S. law may permit government access without EU-level protections)
If you're running a B2B SaaS platform and every customer interaction generates a transfer, that's not occasional. If the service doesn't work without the transfer, consent isn't freely given. Most operational transfers don't qualify.
What Supplementary Measures Actually Work for U.S. Transfers?
The measures that work are the ones that make data unintelligible or inaccessible to anyone who might be compelled to hand it over.
Effective measures:
- End-to-end encryption where only the data subject holds keys
- Encryption where the data exporter (your EU entity) holds keys and the U.S. processor never accesses plaintext
- Pseudonymization with the identifier table held in the EU, if the pseudonymized data isn't useful for surveillance purposes
- Multi-party computation or confidential computing environments that prevent the processor from accessing data in the clear
Ineffective measures:
- Encryption where the U.S. vendor holds the keys (they can be compelled to decrypt)
- Contractual promises not to disclose (FISA requests often include gag orders that override contracts)
- Data minimization alone (if you're still transferring personal data, you still need legal grounds)
Document your technical architecture and explain why your measures prevent access. If you can't prevent access, you need a different legal mechanism or a different vendor.
We're Negotiating a New SaaS Contract. What Should We Ask For?
Ask the vendor:
- Where data is processed and stored (specific regions, not "global infrastructure")
- Whether they can commit to EU-only processing (some vendors offer this)
- What supplementary measures they support (client-side encryption, key management options)
- Whether they've received government data requests and how many (transparency reports)
- How they handle conflicting legal obligations between GDPR and U.S. law
Get these answers in the contract or a data processing addendum, not in a sales deck. If the vendor can't commit to EU-only processing, make sure your SCCs include the EDPB-recommended clauses on supplementary measures and government access transparency.
And run your transfer impact assessment before you sign. Finding out the transfer doesn't work after the contract is live means renegotiating or ripping out the system.
Where Do I Go for the Actual Legal Text?
Start with:
- EDPB Recommendations 01/2020 on supplementary measures (the transfer impact assessment framework)
- EDPB Recommendations 02/2020 on European Essential Guarantees (what "Essential Equivalence" means)
- Chapter V GDPR, particularly Articles 44-49 (the legal mechanisms for transfers)
- Your supervisory authority's guidance (many have published sector-specific transfer guidance)
If you're negotiating SCCs, use the European Commission's 2021 standard clauses, not the old 2010 versions. The new clauses include modules for controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers.
And if your transfer impact assessment identifies risks you can't mitigate, document why you're suspending the transfer. Supervisory authorities enforce Chapter V. The Portugal action on census data transfers proves they're watching.



