Skip to main content
Schrems II and the ePrivacy Stalemate: Your Transfer Mechanism AuditPrivacy Regulations
5 min readFor Data Protection Officers

Schrems II and the ePrivacy Stalemate: Your Transfer Mechanism Audit

Scope

This guide focuses on cross-border data transfer mechanisms facing legal challenges and the compliance gap due to the delayed ePrivacy Regulation. You'll learn how to audit your current transfer tools, prepare for potential invalidation scenarios, and document your transfer decisions.

This guide does not cover intra-EU transfers, binding corporate rules details, or cookie consent mechanics, though ePrivacy will eventually address the latter.

Key Concepts and Definitions

Privacy Shield: The EU-U.S. framework that replaced Safe Harbor. It's currently under review by the European Court of Justice in the Schrems II case. If invalidated, many organizations will lose their primary transfer mechanism overnight.

Standard Contractual Clauses (SCCs): Pre-approved contract templates issued by the European Commission under Article 46(2)(c) of the GDPR. These are also under scrutiny in Schrems II. SCCs may not be sufficient if the receiving country's surveillance laws undermine the protections they promise.

Supplementary Measures: Additional technical and organizational safeguards you add to SCCs when the receiving country's legal framework doesn't provide essential equivalence to GDPR protections.

ePrivacy Regulation: The pending legislation meant to modernize the 2002 ePrivacy Directive. Originally expected to launch alongside GDPR in 2018, it remains stalled. When it arrives, expect stricter rules on electronic communications metadata, terminal equipment access, and consent requirements.

Requirements Breakdown

Chapter V GDPR Transfer Requirements

Article 44: You can only transfer personal data outside the EU/EEA if you comply with Chapter V conditions. No exceptions.

Article 45: Adequacy decisions provide the cleanest path. The European Commission has approved 14 jurisdictions as providing essential equivalence. Privacy Shield operates under this article but may be invalidated.

Article 46: Without an adequacy decision, you need appropriate safeguards. SCCs fall here, along with binding corporate rules, approved codes of conduct, and approved certification mechanisms.

Article 49: Derogations for specific situations. These are narrow exceptions (Informed Consent, contract necessity, vital interests) that don't scale for routine business transfers.

What Schrems II Challenges

The European Court of Justice is questioning whether Privacy Shield and SCCs remain valid given U.S. surveillance laws. The central question: Can contractual promises override a receiving country's legal framework that compels data access without adequate redress mechanisms?

If the Court invalidates Privacy Shield, you'll need an alternative transfer mechanism immediately. If it imposes conditions on SCCs, you'll need to document why your specific transfer satisfies those conditions or implement supplementary measures.

Implementation Guidance

Audit Your Current Transfer Mechanisms

Create a transfer inventory that maps:

  • Data categories leaving the EU/EEA
  • Receiving countries and entities
  • Current legal basis (Privacy Shield, SCCs, adequacy decision, derogation)
  • Volume and frequency
  • Sensitivity level

For each Privacy Shield transfer, identify your fallback mechanism now. Don't wait for the ruling.

Evaluate Supplementary Measures

If you rely on SCCs for transfers to countries with invasive surveillance laws, assess whether the clauses alone provide adequate protection. Consider:

Encryption in transit and at rest: Can the data importer access plaintext, or do you retain sole control of encryption keys?

Pseudonymization: Have you separated identifiers from attributes so the Data Importer can't re-identify individuals without additional information you control?

Access controls: Does the data importer's access align with the specified processing purposes, or do they have broader access than the SCC permits?

Contractual audit rights: Can you verify the data importer's compliance, or are you relying on their assurances?

Document your supplementary measures analysis. Supervisory authorities expect you to show your work, not just assert compliance.

Prepare for ePrivacy When It Arrives

The ePrivacy Regulation's delay creates planning challenges, but you can anticipate its direction:

Consent requirements will tighten: Expect Informed Consent for processing communications metadata beyond what's strictly necessary for transmission. Your current cookie consent flows may not suffice.

B2B communications come into scope: Unlike the current directive, the regulation will likely cover business email and messaging metadata more explicitly.

Metadata retention limits: Plan for stricter rules on how long you can retain communications metadata for non-billing purposes.

Start documenting your communications data processing now. Map what metadata you collect, why you need it, and how long you keep it. When ePrivacy arrives, you'll have the foundation for a rapid compliance assessment.

Common Pitfalls

Assuming Privacy Shield survives: Many organizations treat Privacy Shield as permanent infrastructure. It's under active judicial review. Build contingency plans.

Treating SCCs as checkbox compliance: Signing the clauses doesn't end your analysis. You must assess whether they provide adequate protection given the receiving country's legal framework.

Relying on derogations for routine transfers: Article 49 derogations are narrow exceptions, not business-as-usual tools. Informed Consent for transfers works for occasional cases, not systematic processing.

Waiting for ePrivacy to plan: The regulation's delay isn't permission to ignore it. Review your communications metadata practices now so you're not starting from zero when it passes.

Ignoring the data importer's legal obligations: Your SCC analysis must account for what laws bind the Data Importer. If their government can compel disclosure without adequate safeguards, the contract alone won't protect the data.

Quick Reference Table

Transfer Mechanism Legal Basis Current Status Action Required
Privacy Shield Article 45 adequacy decision Under ECJ review in Schrems II Identify fallback mechanism; document alternative basis
Standard Contractual Clauses Article 46(2)(c) appropriate safeguards Under ECJ review in Schrems II Assess need for supplementary measures; document analysis
Adequacy decisions (other) Article 45 Stable for approved jurisdictions Monitor for updates; maintain transfer records
Binding Corporate Rules Article 46(2)(b) Not challenged in Schrems II Continue use; ensure approval remains current
Informed Consent Article 49(1)(a) derogation Available for specific situations Limit to non-routine transfers; document necessity
Contract necessity Article 49(1)(b) derogation Available for specific situations Use only when transfer necessary to perform contract with data subject

Your transfer mechanisms aren't set-and-forget infrastructure. They're legal positions you must defend with documented analysis and appropriate safeguards. The Schrems II ruling will clarify requirements, but your preparation starts now.

You Might Also Like