Skip to main content
Schrems II: How One Court Ruling Exposed a Decade of Transfer FailuresPrivacy Regulations
4 min readFor Privacy Officers

Schrems II: How One Court Ruling Exposed a Decade of Transfer Failures

What Happened

On July 16, 2020, the Court of Justice of the European Union invalidated the EU-US Privacy Shield framework in its Schrems II decision. This ruling highlighted a major issue: organizations were treating adequacy decisions and Standard Contractual Clauses as mere formalities instead of starting points for assessing transfer risks.

The decision came at a time when cross-border data flows were crucial for remote work. Privacy teams had to choose between conducting transfer impact assessments for every third-party tool or knowingly violating Chapter V GDPR.

Timeline

July 16, 2020: The Court of Justice issues the Schrems II judgment, invalidating Privacy Shield and requiring case-by-case assessment of third-country transfers.

August-September 2020: The European Data Protection Board begins drafting guidance on supplementary measures while organizations scramble to inventory US-based processors.

November 2020: The EDPB publishes recommendations on supplementary measures, confirming that Standard Contractual Clauses alone cannot legitimize transfers to jurisdictions with surveillance laws incompatible with EU fundamental rights.

December 2020: Organizations realize their 2021 budgets don't cover the engineering work needed to implement technical measures like encryption key separation and pseudonymization at scale.

Which Controls Failed or Were Missing

Incomplete or absent transfer mapping. Most organizations couldn't answer basic questions: Which vendors store EU personal data in the US? Which subprocessors does your primary SaaS provider use? Where do backup copies reside?

Checkbox compliance in risk assessment. Teams signed Standard Contractual Clauses without evaluating whether the data importer could actually honor them. If a US cloud provider receives a FISA 702 order, the contractual promise to "only process on documented instructions" becomes legally impossible to fulfill.

Lack of technical measures. The court made it clear that legal instruments alone don't satisfy Article 44. Organizations needed technical controls, encryption with EU-held keys, pseudonymization, data minimization, to ensure transferred data remained protected despite the destination country's legal framework. Most had none of these in place.

Vendor due diligence ignored jurisdiction. Procurement teams evaluated security certifications and SLAs but didn't assess whether a vendor's legal obligations in its home country would conflict with GDPR requirements.

What the Relevant Standard Requires

Chapter V GDPR establishes a hierarchy for lawful transfers. Article 45 adequacy decisions are first-tier. When those aren't available, Article 46 appropriate safeguards (including Standard Contractual Clauses) are second-tier. But Article 44 sets an overarching requirement: transfers must ensure the level of protection guaranteed by GDPR isn't undermined.

Schrems II clarified that Article 46 safeguards must be effective, not merely formal. If the destination country's laws allow government access incompatible with Articles 7 and 8 of the Charter of Fundamental Rights, you must implement supplementary measures that restore essential equivalence.

Article 5(2) requires you to demonstrate compliance. You can't claim ignorance if your US vendor routes data through servers subject to surveillance laws. The accountability principle demands documented transfer risk assessments.

Article 28 requires processor agreements that ensure processors only act on your instructions. When a processor faces conflicting legal obligations, say, a national security letter versus your processing instructions, the contract fails to satisfy Article 28's requirements.

Lessons and Action Items for Your Team

Build a transfer inventory before the next adequacy decision falls. Map every cross-border flow: vendor name, data categories, legal basis, destination country, and whether supplementary measures are in place. Update it quarterly. When the next jurisdiction loses adequacy status, you'll know your exposure immediately.

Conduct transfer impact assessments for high-risk destinations. Don't limit this to US transfers. Evaluate whether the destination country's laws allow government access to your data categories in ways that conflict with GDPR. Document your assessment. If you can't mitigate the risks, don't make the transfer.

Implement technical supplementary measures now. Encryption alone isn't sufficient if the processor holds the keys. Separate key management from data storage. Pseudonymize personal data before transfer when possible. These measures take months to implement, start before you're in breach.

Rewrite your Standard Contractual Clauses. The European Commission adopted new SCCs in June 2021, but even before that, your existing clauses should have included specific obligations: the importer must notify you of government access requests, must challenge legally questionable requests, and must conduct its own assessment of local law compatibility.

Stop treating adequacy decisions as permanent. Privacy Shield lasted four years. Safe Harbor lasted fifteen. Adequacy decisions are revocable. Build your transfer architecture to withstand the loss of adequacy for any jurisdiction you depend on.

Question vendors who claim compliance without technical measures. If a US-based vendor says they're "Schrems II compliant" but stores unencrypted data in US datacenters and holds the encryption keys, they're not. Either they don't understand the ruling or they're misrepresenting their posture.

Prepare for California's turn. Proposition 24 passed in November 2020, strengthening the California Consumer Privacy Act. As US state privacy laws proliferate, expect increased scrutiny of how US companies handle data, and whether that handling satisfies essential equivalence for inbound transfers from the EU.

The real lesson of Schrems II isn't about Privacy Shield. It's that your legal basis for transfers is only as strong as your ability to enforce it technically and contractually. Every transfer mechanism you rely on, adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, can fail if the destination country's legal framework changes or if a court examines it closely.

Map your transfers. Assess the risks. Implement technical measures. Document everything. The next invalidation is coming.

You Might Also Like