The Schrems II ruling reshaped EU-US data transfers by invalidating the Privacy Shield in July 2020 and holding that Standard Contractual Clauses, while still valid, are no longer enough on their own. If you send personal data from the European Economic Area to the United States, you now have three practical routes: rely on a US importer certified under the 2023 EU-US Data Privacy Framework, sign the updated SCCs and back them with a documented Transfer Impact Assessment plus supplementary safeguards, or use Binding Corporate Rules for intra-group flows. Getting this wrong is expensive. The Irish Data Protection Commission fined Meta €1.2 billion in 2023 for transatlantic transfers that lacked adequate protections.
What Schrems II Actually Decided
Case C-311/18 started with a complaint by Austrian privacy activist Maximillian Schrems about how Facebook Ireland moved his personal data to servers in the United States. The Court of Justice of the European Union had to decide whether US law protects personal data to the standard European law requires before that data leaves the EU. It concluded that it does not, and struck down the Privacy Shield framework thousands of companies had been relying on.1European Parliamentary Research Service. The CJEU Judgment in the Schrems II Case
Two US surveillance authorities drove the outcome. FISA Section 702 lets intelligence agencies collect communications data on non-US persons at a scale the court found incompatible with European proportionality requirements, because the legal bases do not limit collection to what is strictly necessary. Executive Order 12333 compounded the problem by allowing bulk collection of communications flowing into the US with minimal targeting.
The court also found that European citizens had no meaningful way to challenge US government access to their data. The Privacy Shield Ombudsperson lacked independence from the executive branch and could not issue binding decisions against intelligence agencies. Without genuine judicial redress, the whole framework failed. Every company that had used Privacy Shield as its sole legal basis for transatlantic transfers lost that basis the day the judgment came down.
SCCs survived the ruling, but with a new condition: before you transfer, you have to independently assess whether the destination country’s laws let the importer actually honor the protections it signed up to. If a government can compel access despite the contract, you either add safeguards strong enough to close the gap or you stop the transfer.
Your Options for Transferring Data to the US Today
Four legal routes exist in practice, and most organizations will use a combination.
The EU-US Data Privacy Framework, adopted by the European Commission in July 2023, is the Privacy Shield’s successor.2European Commission. Adequacy Decision for Safe EU-US Data Flows It rests on Executive Order 14086, which requires US signals intelligence to be necessary and proportionate and permits bulk collection only when targeted methods cannot reasonably get the information.3Federal Register. Enhancing Safeguards for United States Signals Intelligence Activities The framework created the Data Protection Review Court, an independent body that hears complaints from Europeans about US intelligence access to their data and issues binding decisions.4eCFR. 28 CFR Part 201 – Data Protection Review Court Only US companies under FTC or Department of Transportation jurisdiction can self-certify, and only after the International Trade Administration places them on the Data Privacy Framework List. More than 2,800 companies had certified as of the framework’s first annual review.5European Commission. Report on the First Periodic Review of the EU-US Data Privacy Framework If your US recipient is on that list, no further transfer safeguards are needed for the data covered by its certification.
Standard Contractual Clauses remain the workhorse mechanism for transfers where the importer is not DPF-certified or where you want a fallback if the framework is invalidated.6General Data Protection Regulation (GDPR). GDPR Article 46 – Transfers Subject to Appropriate Safeguards They now have to be paired with a Transfer Impact Assessment and, where the assessment shows gaps, supplementary measures.
Binding Corporate Rules allow multinational groups to move personal data between their own entities under a single set of enforceable privacy standards approved by a supervisory authority. BCRs must be legally binding on every group member, grant enforceable rights to individuals, and cover the full range of GDPR principles. Approval is lengthy and resource-intensive, so BCRs tend to be practical only for large organizations with significant intra-group flows.
Article 49 derogations are the narrow fallback for situations none of the above cover. Explicit informed consent, transfers needed to perform a contract with the individual, important public-interest transfers, and transfers needed to establish or defend legal claims all qualify.7General Data Protection Regulation (GDPR). GDPR Article 49 – Derogations for Specific Situations These are intentionally narrow. They must be occasional and limited in scope, so they cannot serve as the primary basis for routine large-scale transfers.
How the Updated Standard Contractual Clauses Work
The European Commission issued updated SCCs in June 2021, replacing the older versions. The transition deadline passed on December 27, 2022, so any organization still running pre-2021 SCCs has no valid transfer mechanism in place.8European Commission. European Commission Adopts New Tools for Safe Exchanges The updated clauses use a modular structure covering four relationships:
- Module 1 covers controller-to-controller transfers, where both sides independently decide how and why they process the data. A European retailer sharing customer data with a foreign hotel chain for booking purposes fits here.
- Module 2 covers controller-to-processor transfers, where the exporter controls the data and the importer processes it on the exporter’s behalf. This is the most common scenario and covers things like outsourcing payroll or customer support outside the EEA.
- Module 3 covers processor-to-processor transfers, such as an EEA cloud services company engaging a foreign lab to run analytics on data it processes for a client.
- Module 4 covers processor-to-controller transfers, where an EEA-based processor returns data to a non-EEA controller.
Parties can combine modules in a single contract when their relationship involves different roles for different data flows. An optional docking clause lets new parties join an existing SCC contract with the consent of current signatories, which is useful when a new sub-processor needs to be brought under the same contractual protections without a fresh agreement.9European Commission. New Standard Contractual Clauses – Questions and Answers Overview
Running a Transfer Impact Assessment
The European Data Protection Board’s six-step process is the documented evidence a regulator will ask for during an investigation.10European Data Protection Board. Recommendations 01/2020 on Measures That Supplement Transfer Tools
- Map your transfers. Identify every flow of personal data leaving the EEA, including onward transfers by processors and sub-processors. Many organizations discover flows they did not know existed, particularly through cloud infrastructure and analytics. Confirm that the data transferred is limited to what is actually necessary.
- Identify your legal basis. If the destination country has an adequacy decision (as the US does under the DPF), and your importer is certified, you are done. Otherwise, identify whether you are relying on SCCs, BCRs, or another Article 46 mechanism.
- Assess destination country law. Evaluate whether the laws or government practices there undermine the protections your transfer tool provides. Focus on surveillance powers, government data access rights, and enforceable individual redress. This is where most organizations struggle, because it requires genuine legal analysis of foreign law.
- Adopt supplementary measures. If step three reveals a gap, identify technical, contractual, or organizational safeguards that bring protection up to the European standard. If no combination closes the gap, you must suspend or terminate the transfer.
- Complete procedural requirements. Some supplementary measures require consultation with your supervisory authority, particularly if they modify the SCCs or contradict any clause.
- Monitor and reassess. Track legal and political developments in the destination country and revisit the analysis at regular intervals.
Your documentation should record the nature of the personal data (particularly sensitive categories like health or financial records), every entity in the processing chain, and whether data is encrypted in transit and at rest and who holds the keys. Fines for inadequate transfer practices reach €20 million or 4% of global annual turnover, whichever is higher.11General Data Protection Regulation (GDPR). GDPR Article 83 – General Conditions for Imposing Administrative Fines A thin or generic assessment will not hold up.
Supplementary Measures That Actually Work
When the assessment shows that destination-country law compromises the protections in your SCCs, supplementary measures are the only thing standing between you and a mandatory suspension. Technical measures carry the most weight because they operate regardless of what foreign law permits.
Encryption is the most commonly cited safeguard, but the details matter. The EDPB considers encryption effective only when the algorithm meets current standards, the key length reflects how long the data needs protection, and the decryption keys sit exclusively with the exporter or a trusted entity inside the EEA or an equivalent jurisdiction. If the importer needs to decrypt the data to do its job, encryption alone does not solve the problem. This is the limitation that caught Meta: even with updated SCCs and supplementary measures, the data had to be readable for Facebook’s service to function, so US authorities could still compel access.
Pseudonymization replaces identifying information with artificial identifiers, so the data cannot be linked to a specific person without additional information held separately under strict access controls.12General Data Protection Regulation (GDPR). GDPR Article 4 – Definitions It is most useful when the importer does not need to know whose data it is processing, such as a research organization analyzing anonymized health trends.
Contractual measures reinforce the technical ones. The EDPB recognizes warrant canaries, where the importer publishes a cryptographically signed statement at regular intervals confirming it has not received any government orders to disclose personal data. If the statement stops appearing, the exporter knows something has changed. Warrant canaries are never sufficient on their own; they work only alongside encryption and automated monitoring. Other contractual commitments include pledges that the importer has not built backdoors into its systems and will challenge government access requests in court before complying.
Sovereign cloud solutions are an infrastructure-level approach: cloud environments run within the EEA with technical controls that prevent the provider’s personnel outside Europe from accessing the data, sometimes with customer-managed keys the provider itself cannot use. The value depends entirely on the architecture. Marketing a product as “sovereign” does not make it legally sufficient.
What Enforcement Has Looked Like
In May 2023 the Irish Data Protection Commission fined Meta Platforms Ireland €1.2 billion for continuing to transfer EU user data to the United States after Schrems II. Meta had adopted the 2021 SCCs and supplementary measures, but the DPC concluded the arrangements did not address the risks the CJEU had identified. Meta was ordered to suspend future US transfers within five months and to stop the unlawful storage of EU user data in the US within six.13Data Protection Commission. Inquiry Concerning Data Transfers from the EU/EEA to the US by Meta Platforms Ireland Limited
In April 2025 the Irish DPC hit TikTok Technology Limited with a €530 million combined penalty. The DPC found that TikTok had transferred EEA user data to China through remote access by ByteDance personnel without verifying that the data received EU-equivalent protection. TikTok was fined €485 million for the transfer violation and €45 million for failing to tell users their data was accessible from China, and was ordered to suspend the transfers and stop the processing of already-transferred EEA data in China.14Data Protection Commission. Inquiry into TikTok Technology Limited – April 2025
Both cases carry the same lesson. Having SCCs on paper is not a defense if the underlying Transfer Impact Assessment was inadequate or if the supplementary measures do not actually prevent government access. Regulators are looking at substance, not signatures.
What Could Change Next
The Data Privacy Framework is not permanently settled. A legal challenge by French politician Philippe Latombe was dismissed by the General Court in September 2024, but an appeal filed in October 2025 is pending before the CJEU. The privacy advocacy group NOYB has signaled it may bring its own challenge once the Latombe case resolves. A successful challenge could trigger another Privacy Shield-style invalidation.
FISA Section 702, one of the surveillance laws behind Schrems II, was reauthorized in April 2024 through the Reforming Intelligence and Securing America Act and is scheduled to sunset on April 20, 2026.15Congress.gov. FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act The reauthorization made some changes, including a permanent ban on “abouts” collection and new querying safeguards for the FBI, but also expanded the definition of electronic communication service providers subject to government data demands. How Congress handles the next reauthorization will directly affect the framework’s legal foundations. In January 2025, three of five members of the Privacy and Civil Liberties Oversight Board were removed, leaving the board without a quorum and unable to perform its oversight role over the framework’s intelligence safeguards.
The most defensible position is not to bet on any single mechanism. Keep valid SCCs in place with current Transfer Impact Assessments and effective supplementary measures, even for transfers currently covered by DPF certification. If the framework goes, your compliance survives it.