Skip to main content
Privacy Shield Is Gone: Five Myths That Will Get You in TroubleInternational Data Transfers
5 min readFor Legal and Compliance Teams

Privacy Shield Is Gone: Five Myths That Will Get You in Trouble

The invalidation of the EU-U.S. Privacy Shield on July 16, 2020, didn't just eliminate a transfer mechanism. It exposed how many legal and compliance teams had built their cross-border data strategies on wishful thinking rather than regulatory reality.

These myths persist because they're comforting. They let you believe your current setup might still work, that you can wait for clarity, or that a workaround exists that doesn't require real operational change. But the Court of Justice of the European Union doesn't care about your comfort level, and neither will your supervisory authority when they audit your transfer mechanisms.

Here's what you need to stop believing.

Myth 1: Standard Contractual Clauses Are a Drop-In Replacement

The Reality: The court upheld standard contractual clauses, but with conditions that require you to assess whether the legal environment in the destination country undermines the protections those clauses promise.

You can't just swap Privacy Shield for SCCs and call it done. Article 46 GDPR requires that SCCs provide "appropriate safeguards" for transfers. The court made clear that contractual promises mean nothing if the receiving jurisdiction's surveillance laws or data access frameworks can override them.

Your immediate action: conduct a transfer impact assessment for every jurisdiction where you send personal data. Document the laws that govern data access in that country, evaluate whether they conflict with GDPR protections, and determine whether supplementary measures (encryption in transit and at rest, pseudonymization, data minimization) can bridge the gap. If they can't, you need to stop the transfer or find an alternative processing location.

Myth 2: You Can Wait for Privacy Shield 2.0

The Reality: Regulatory uncertainty is not a compliance strategy, and supervisory authorities will not grant forbearance while governments negotiate.

Some teams assumed that because Privacy Shield existed once, a replacement framework would arrive quickly. That assumption ignores the structural issues the court identified: U.S. surveillance programs and the lack of effective redress mechanisms for EU citizens. Those problems don't disappear because businesses need a convenient transfer tool.

Your retention period for transferred data doesn't pause while diplomats talk. Your Chapter V GDPR obligations remain active. If you're transferring data today under an invalid mechanism, you're operating outside the law today.

What to do instead: treat every current transfer as if no replacement framework will arrive. Build your compliance infrastructure around mechanisms you control (SCCs with supplementary measures, binding corporate rules if you're a multinational, data localization where feasible) rather than waiting for a political solution.

Myth 3: Encryption Alone Fixes the Problem

The Reality: Encryption is a supplementary measure, not a standalone transfer solution, and it only helps if the data exporter retains sole control of the keys.

Some teams argue that because their data is encrypted in transit and at rest, they've satisfied the "appropriate safeguards" requirement. That logic fails the moment the data importer can decrypt the data to use it, which is the entire point of most business transfers.

The European Data Protection Board's recommendations on supplementary measures are explicit: if the data importer needs access to data in the clear to perform the contracted service, encryption doesn't prevent a government authority in that jurisdiction from compelling disclosure. You've protected the data from opportunistic breaches, but not from lawful access requests under foreign surveillance laws.

Encryption works as a supplementary measure only when the data exporter holds the decryption keys and the importer processes only encrypted data (for storage or transmission purposes). For analytics, customer support, or any use case requiring plaintext access, you need additional or alternative measures.

Myth 4: Your Processor's Compliance Covers Your Obligation

The Reality: You remain the data controller, and Chapter V GDPR compliance is your responsibility regardless of what your vendor claims.

When you transfer personal data to a processor in a third country, you're the data exporter. Article 28 GDPR requires that your processing agreement include appropriate safeguards, but it doesn't transfer your accountability. If your processor can't demonstrate essential equivalence to GDPR protections, your transfer is unlawful, and you're the party in violation.

This matters acutely for SaaS platforms and cloud providers. Your vendor may offer SCCs as part of their standard terms, but those clauses are only the starting point. You still need to assess whether the jurisdiction where they operate undermines those protections, and whether they've implemented supplementary measures that address identified gaps.

Ask your processors: Where is data physically stored and processed? What legal frameworks govern data access requests in those locations? What technical measures prevent unauthorized access, including access compelled by foreign governments? If they can't answer with specificity, you can't rely on them for compliant transfers.

Myth 5: Consent Legitimizes Any Transfer

The Reality: Consent under Article 49(1)(a) GDPR is a derogation for specific, occasional transfers, not a blanket authorization for systematic data flows.

Some teams looked at the Article 49 derogations and saw consent as an escape hatch: if we tell users we're transferring their data to the U.S. and they agree, we're compliant. That interpretation ignores the Article 29 Working Party guidelines (now EDPB) that make clear these derogations apply only when no other transfer mechanism is available and the transfer is not repetitive.

If you're running a business that systematically transfers employee data to a U.S. parent company, customer data to a U.S. analytics platform, or applicant data to a U.S. recruitment tool, you're not in "occasional transfer" territory. Consent won't cover you.

Additionally, consent must be freely given. For employee data, the power imbalance makes free consent nearly impossible. For customer data, if your service doesn't function without the transfer, the consent isn't freely given.

What to Do Instead

Stop looking for shortcuts and build a transfer strategy that assumes supervisory authorities will scrutinize your mechanisms.

First, inventory every cross-border data flow. Document the legal basis for each transfer, the destination country, the categories of data, and the business purpose. You can't assess risk for transfers you haven't identified.

Second, conduct transfer impact assessments for each destination jurisdiction. The EDPB's recommendations on supplementary measures provide the framework: evaluate the laws and practices of the third country, assess whether they impinge on the effectiveness of your transfer mechanism, and identify supplementary measures that address specific risks.

Third, implement Technical and Organisational Measures that reduce reliance on contractual promises. Pseudonymize data before transfer where possible. Minimize the data you transfer to only what's necessary for the specific purpose. Segregate high-risk data (special category data, data about children) and process it only in jurisdictions with adequacy decisions.

Fourth, document everything. Your supervisory authority will want evidence that you assessed the risks, considered alternatives, and implemented appropriate safeguards. A transfer impact assessment isn't a checkbox exercise; it's a defensible record of your compliance decision-making.

The post-Privacy Shield landscape rewards organizations that build resilient, evidence-based transfer strategies over those that wait for regulatory rescue. Your cross-border data flows are your responsibility to secure, regardless of what framework governments eventually negotiate.

You Might Also Like