Skip to main content
Should You Bet on a Multilateral Treaty for Cross-Border Transfers?International Data Transfers
5 min readFor Data Governance Teams

Should You Bet on a Multilateral Treaty for Cross-Border Transfers?

The Schrems II decision left you with a choice: patch your existing transfer mechanisms with supplementary measures, wait for a new adequacy decision, or explore alternative frameworks. Now, a third option has entered the conversation: a multilateral privacy treaty among democratic nations. Brian Hengesbaugh from Baker MacKenzie has proposed this approach, and the Biden administration's appointment of Christopher Hoff signals renewed attention to trans-Atlantic data flows.

But should your governance team plan around this possibility? Here's how to evaluate whether a multilateral treaty path makes strategic sense for your organization.

The Decision You're Facing

You need to choose a transfer strategy that will remain defensible for the next 3-5 years. Your options:

  1. Bilateral adequacy path: Wait for a U.S.-EU Privacy Shield replacement.
  2. Supplementary measures path: Layer technical and organizational controls onto Standard Contractual Clauses.
  3. Multilateral treaty path: Position your organization to benefit from a broader international framework.

Each path carries different implementation costs, legal risk, and timeline assumptions.

Key Factors That Affect Your Choice

Volume and sensitivity of your EU-to-U.S. transfers. If you process high volumes of personal data from EU data subjects and transfer it to U.S. infrastructure, the stability of your transfer mechanism directly affects operational continuity. A single adequacy decision can be challenged; a treaty ratified by multiple nations creates broader legal grounding.

Your organization's geographic footprint. Companies that transfer data among multiple jurisdictions (UK, Switzerland, Canada, Australia, U.S.) face compounding compliance complexity. A multilateral framework could simplify this; bilateral agreements cannot.

National security law exposure. The core Schrems II concern centers on U.S. surveillance laws under FISA 702 and Executive Order 12333. If your data could interest intelligence agencies, no adequacy decision solves this without legislative change. A treaty could establish shared standards for lawful access that satisfy EU courts.

Your risk tolerance for legal challenges. Adequacy decisions can be invalidated. The Article 29 Working Party (predecessor to the European Data Protection Board) and privacy advocates will scrutinize any new U.S.-EU agreement. A treaty among democratic nations sharing values around human rights and national security would face different legal tests than a bilateral adequacy decision.

Path A: Rely on Bilateral Adequacy (U.S.-EU Agreement)

Choose this path if:

  • Your transfers are primarily between the EU and U.S.
  • You need a solution within 12-24 months.
  • Your organization can implement supplementary measures as a fallback.
  • You process data categories unlikely to trigger national security interest.

Implementation requirements:

The U.S. Department of Commerce and European Commission are actively negotiating. When an adequacy decision arrives, you'll need to verify your U.S. recipients meet any new framework requirements (likely an enhanced Privacy Shield with stronger redress mechanisms). Budget for certification costs and annual recertification.

Risk exposure:

Without changes to U.S. surveillance laws, any new adequacy decision faces the same Article 45 GDPR challenge that invalidated Privacy Shield. The European Data Protection Supervisor and civil society groups have already signaled they'll scrutinize the legal basis. Plan for a 3-5 year validity window before potential re-litigation.

Path B: Build Supplementary Measures Now

Choose this path if:

  • You transfer data to multiple non-EU jurisdictions.
  • You can implement technical controls (encryption, pseudonymization, access restrictions).
  • Your supervisory authority has issued guidance on acceptable supplementary measures.
  • You need a defensible position today, not in 18 months.

Implementation requirements:

Layer Technical and Organisational Measures onto your Standard Contractual Clauses per the European Data Protection Board's Recommendations 01/2020. Document your transfer impact assessment under Article 46 GDPR. For U.S. transfers, this means analyzing FISA 702 and E.O. 12333 exposure, then implementing controls that make accessed data unintelligible or legally protected.

Risk exposure:

Supervisory authorities interpret "adequate supplementary measures" differently. The Irish Data Protection Commission has challenged Facebook's Standard Contractual Clauses; the French CNIL issued guidance requiring encryption at rest and in transit for certain transfers. Your measures may satisfy one authority but not another.

Path C: Position for a Multilateral Framework

Choose this path if:

  • You operate across multiple democratic nations with aligned privacy regimes.
  • Your planning horizon extends beyond 3 years.
  • You can absorb uncertainty while the treaty develops.
  • You want to influence the framework through industry consultation.

What this requires:

A multilateral treaty would need ratification by participating nations' legislatures. The U.S. Senate requires a two-thirds vote for treaty ratification. This process typically takes 2-4 years minimum, assuming political alignment. Democratic nations would need to harmonize their national security laws around shared standards for lawful access to data.

Strategic positioning:

Implement supplementary measures as your baseline (Path B), but engage in treaty consultation processes. The OECD, Council of Europe, and trade policy forums will likely shape any multilateral approach. Your legal team should monitor these developments and submit comments when drafts circulate.

Risk exposure:

A multilateral treaty may never materialize. Even if it does, participating nations may not include all your key transfer destinations. China and Russia would not join a democratic-values framework, so you'd still need separate mechanisms for those transfers.

Summary Matrix

Factor Bilateral Adequacy Supplementary Measures Multilateral Treaty
Timeline 12-24 months Implement now 3-5+ years
Geographic scope U.S.-EU only Any jurisdiction Participating democracies
Legal stability Medium (challenge risk) Medium (interpretation varies) High (if ratified)
Implementation cost Low (certification) High (technical controls) Low (once active)
Surveillance law risk High (unchanged laws) Medium (technical mitigation) Low (harmonized standards)
Fallback needed Yes (SCCs + measures) No (already layered) Yes (until ratified)

The practical answer: Implement Path B now. Monitor Path A actively. Treat Path C as a 2025+ planning assumption, not a 2023 strategy. No governance team can afford to wait for a multilateral treaty that may take half a decade to ratify, but the concept signals where international data governance is heading: toward frameworks that address surveillance law directly rather than working around it.

If you're transferring data to the U.S. today, you need Standard Contractual Clauses with documented supplementary measures. If a new adequacy decision arrives, you can layer it on top. And if a multilateral treaty eventually emerges, you'll have built the technical and organizational foundation that any robust framework would require anyway.

You Might Also Like