Scope
This guide focuses on cross-border data transfer mechanisms facing legal challenges and the compliance gap due to the delayed ePrivacy Regulation. You'll learn how to audit your current transfer tools, prepare for potential invalidation scenarios, and document your transfer decisions.
This guide does not cover intra-EU transfers, binding corporate rules details, or cookie consent mechanics, though ePrivacy will eventually address the latter.
Key Concepts and Definitions
Privacy Shield: The EU-U.S. framework that replaced Safe Harbor. It's currently under review by the European Court of Justice in the Schrems II case. If invalidated, many organizations will lose their primary transfer mechanism overnight.
Standard Contractual Clauses (SCCs): Pre-approved contract templates issued by the European Commission under Article 46(2)(c) of the GDPR. These are also under scrutiny in Schrems II. SCCs may not be sufficient if the receiving country's surveillance laws undermine the protections they promise.
Supplementary Measures: Additional technical and organizational safeguards you add to SCCs when the receiving country's legal framework doesn't provide essential equivalence to GDPR protections.
ePrivacy Regulation: The pending legislation meant to modernize the 2002 ePrivacy Directive. Originally expected to launch alongside GDPR in 2018, it remains stalled. When it arrives, expect stricter rules on electronic communications metadata, terminal equipment access, and consent requirements.
Requirements Breakdown
Chapter V GDPR Transfer Requirements
Article 44: You can only transfer personal data outside the EU/EEA if you comply with Chapter V conditions. No exceptions.
Article 45: Adequacy decisions provide the cleanest path. The European Commission has approved 14 jurisdictions as providing essential equivalence. Privacy Shield operates under this article but may be invalidated.
Article 46: Without an adequacy decision, you need appropriate safeguards. SCCs fall here, along with binding corporate rules, approved codes of conduct, and approved certification mechanisms.
Article 49: Derogations for specific situations. These are narrow exceptions (Informed Consent, contract necessity, vital interests) that don't scale for routine business transfers.
What Schrems II Challenges
The European Court of Justice is questioning whether Privacy Shield and SCCs remain valid given U.S. surveillance laws. The central question: Can contractual promises override a receiving country's legal framework that compels data access without adequate redress mechanisms?
If the Court invalidates Privacy Shield, you'll need an alternative transfer mechanism immediately. If it imposes conditions on SCCs, you'll need to document why your specific transfer satisfies those conditions or implement supplementary measures.
Implementation Guidance
Audit Your Current Transfer Mechanisms
Create a transfer inventory that maps:
- Data categories leaving the EU/EEA
- Receiving countries and entities
- Current legal basis (Privacy Shield, SCCs, adequacy decision, derogation)
- Volume and frequency
- Sensitivity level
For each Privacy Shield transfer, identify your fallback mechanism now. Don't wait for the ruling.
Evaluate Supplementary Measures
If you rely on SCCs for transfers to countries with invasive surveillance laws, assess whether the clauses alone provide adequate protection. Consider:
Encryption in transit and at rest: Can the data importer access plaintext, or do you retain sole control of encryption keys?
Pseudonymization: Have you separated identifiers from attributes so the Data Importer can't re-identify individuals without additional information you control?
Access controls: Does the data importer's access align with the specified processing purposes, or do they have broader access than the SCC permits?
Contractual audit rights: Can you verify the data importer's compliance, or are you relying on their assurances?
Document your supplementary measures analysis. Supervisory authorities expect you to show your work, not just assert compliance.
Prepare for ePrivacy When It Arrives
The ePrivacy Regulation's delay creates planning challenges, but you can anticipate its direction:
Consent requirements will tighten: Expect Informed Consent for processing communications metadata beyond what's strictly necessary for transmission. Your current cookie consent flows may not suffice.
B2B communications come into scope: Unlike the current directive, the regulation will likely cover business email and messaging metadata more explicitly.
Metadata retention limits: Plan for stricter rules on how long you can retain communications metadata for non-billing purposes.
Start documenting your communications data processing now. Map what metadata you collect, why you need it, and how long you keep it. When ePrivacy arrives, you'll have the foundation for a rapid compliance assessment.
Common Pitfalls
Assuming Privacy Shield survives: Many organizations treat Privacy Shield as permanent infrastructure. It's under active judicial review. Build contingency plans.
Treating SCCs as checkbox compliance: Signing the clauses doesn't end your analysis. You must assess whether they provide adequate protection given the receiving country's legal framework.
Relying on derogations for routine transfers: Article 49 derogations are narrow exceptions, not business-as-usual tools. Informed Consent for transfers works for occasional cases, not systematic processing.
Waiting for ePrivacy to plan: The regulation's delay isn't permission to ignore it. Review your communications metadata practices now so you're not starting from zero when it passes.
Ignoring the data importer's legal obligations: Your SCC analysis must account for what laws bind the Data Importer. If their government can compel disclosure without adequate safeguards, the contract alone won't protect the data.
Quick Reference Table
| Transfer Mechanism | Legal Basis | Current Status | Action Required |
|---|---|---|---|
| Privacy Shield | Article 45 adequacy decision | Under ECJ review in Schrems II | Identify fallback mechanism; document alternative basis |
| Standard Contractual Clauses | Article 46(2)(c) appropriate safeguards | Under ECJ review in Schrems II | Assess need for supplementary measures; document analysis |
| Adequacy decisions (other) | Article 45 | Stable for approved jurisdictions | Monitor for updates; maintain transfer records |
| Binding Corporate Rules | Article 46(2)(b) | Not challenged in Schrems II | Continue use; ensure approval remains current |
| Informed Consent | Article 49(1)(a) derogation | Available for specific situations | Limit to non-routine transfers; document necessity |
| Contract necessity | Article 49(1)(b) derogation | Available for specific situations | Use only when transfer necessary to perform contract with data subject |
Your transfer mechanisms aren't set-and-forget infrastructure. They're legal positions you must defend with documented analysis and appropriate safeguards. The Schrems II ruling will clarify requirements, but your preparation starts now.



