GDPR international data transfers after Schrems II
The Schrems II ruling fundamentally changed the landscape of international data transfers by making the 'set and forget' approach to compliance a dangerous liability. For founders and security leaders, managing data flows now requires a deep dive into foreign surveillance laws and the implementation of robust technical safeguards. This guide outlines how to move beyond basic legal paperwork to build a defensible, audit-ready transfer architecture.
Michael McCarroll— Founder · 20+ yrs GRC, ISO 27001 lead implementer 16 min read Updated June 2026
The New Reality of Data Sovereignty
Since the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield in July 2020, the burden of proof for data protection has shifted squarely onto the shoulders of the data exporter. You are now legally responsible for ensuring that the personal data of EU citizens is protected to a 'essentially equivalent' standard, regardless of where in the world it is processed. This is not a mere bureaucratic hurdle; it is a fundamental shift in how private equity and enterprise clients vet their SaaS vendors.
The ruling made it clear that Standard Contractual Clauses (SCCs) are not a magic wand. While SCCs remain a valid transfer mechanism, they must be accompanied by a Case-by-Case assessment of the recipient country's legal landscape. If a foreign intelligence agency can access the data in a way that exceeds what is necessary and proportionate in a democratic society, the SCCs are considered ineffective on their own.
Executing a Defensible Transfer Impact Assessment (TIA)
The Transfer Impact Assessment (TIA) is the most critical document in your privacy file post-Schrems II. Regulators expect to see a documented, systematic review of every non-adequate third-country transfer. This is not a task for the legal department alone; it requires input from your DevOps and Security teams to understand exactly how data is routed and protected.
A robust TIA should evaluate the Article 45 factors of the GDPR, looking specifically at the rule of law and the existence of an independent supervisory authority in the recipient nation. For many US-based services, this involves scrutinising Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333. You must document why you believe these laws do or do not impact the specific data you are transferring.
Identify the specific SCC module required (C2P, P2P, P2C, or C2C).
Verify the legal status of the data importer and their jurisdiction's surveillance laws.
Document if the data is encrypted in transit and at rest, including key management location.
Assess the likelihood of government access requests based on the importer’s transparency reports.
Determine if additional technical measures—like pseudonymisation—are required to mitigate risk.
Technical vs. Organisational Supplementary Measures
When your TIA concludes that the recipient country’s laws may interfere with the SCC protections, you must apply 'supplementary measures.' These aren't just suggestions; they are requirements to make the transfer legal. In my experience, technical measures are the only ones that truly satisfy the most stringent EU regulators, particularly the European Data Protection Board (EDPB).
Encryption is the primary technical measure, but it must be implemented correctly. If the service provider in the third country holds the decryption keys, the measure is useless because they can be compelled to hand those keys to local authorities. To achieve 'Schrems-compliant' encryption, the exporter should ideally manage the keys within the EU or a country with an adequacy decision.
Legal and organisational measures, such as requiring the importer to challenge every access request in court or providing 'Warrant Canaries,' are helpful but rarely sufficient on their own. They act as supporting evidence of a company's commitment to privacy but do not physically prevent data interception. You should aim for a layered approach that combines technical barriers with legal obligations.
A Tactical Guide to GDPR Chapter V Compliance
Navigating the GDPR means living in the detail of Chapter V. While most firms focus on SCCs, don't overlook Binding Corporate Rules (BCRs) for intra-group transfers, though these are notoriously difficult and expensive to get approved. For smaller firms, staying within the 'Adequacy' zones—such as the UK, Japan, or Canada—is the simplest path to compliance, as these require no TIAs or SCCs.
Always be wary of relying on Article 49 derogations, such as 'explicit consent' or 'performance of a contract,' for systematic, large-scale transfers. Regulators view these as exceptional measures, not a business-as-usual strategy for international operations. If your business model relies on a US-based CRM, you cannot claim it's 'necessary for the contract' to transfer that data without the proper Article 46 safeguards in place.
Article 45: Adequacy Decisions (The 'Green List' countries).
Article 46: Transfers subject to appropriate safeguards (SCCs and BCRs).
Article 49: Derogations for specific situations (Consent, contract necessity).
SCC Module 2: Controller-to-Processor (The most common SaaS configuration).
SCC Clause 14: The specific requirement to conduct the TIA.
Continuous Monitoring and the Vendor Risk Lifecycle
Compliance is not a static state; it is a continuous monitoring obligation. Your TIA for a specific vendor in 2022 may be invalidated by a change in their local law or a change in their sub-processor bridge in 2024. Founders must implement a vendor risk management (VRM) cycle that re-evaluates international data flows at least annually or upon any 'significant change' to the processing activity.
Internal audits should specifically look for 'shadow IT'—instances where employees have signed up for foreign cloud services without the security team's knowledge. Each of these represents an undocumented and likely illegal international data transfer. Building a central registry of data flows isn't just a GDPR requirement under Article 30; it is the only way to maintain control over your international liability.
Turn GDPR Compliance into a Competitive Edge
Automate your Transfer Impact Assessments and maintain a living record of your international data flows with ISO-STANDARD.app. Our platform helps you prove compliance to global partners, closing deals faster by removing privacy friction.
ISO-STANDARD.app ships a ready-to-adopt GDPR workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.
Frequently asked questions
What is a Transfer Impact Assessment (TIA)?
A TIA is a risk assessment where you evaluate if the laws of the recipient country undermine the protections of the GDPR. You must consider the legal framework of the third country, specifically regarding government surveillance and the availability of judicial redress for data subjects. If the risk is high and cannot be mitigated, the transfer must not proceed.
Are SCCs still valid after the Schrems II ruling?
Standard Contractual Clauses (SCCs) are modular sets of terms provided by the European Commission. They provide a predictable contractual framework for data transfers. However, post-Schrems II, you cannot simply sign them and walk away; they must be supported by a TIA to ensure the recipient can actually honour the terms in their local jurisdiction.
Can I transfer data to the US without SCCs now?
The EU-U.S. Data Privacy Framework (DPF) is a valid adequacy decision as of July 2023. If your US-based processor is certified under the DPF, you can transfer data without needing a TIA or SCCs for that specific flow. However, you must still document the legal basis and verify the certification is active.
What are 'supplementary measures' in the context of data transfers?
Supplementary measures are technical, organisational, or legal safeguards added to SCCs when the recipient country’s laws are insufficient. The gold standard is end-to-end encryption where the keys are held by the exporter in the EU. Other measures include strict pseudonymisation or legal commitments to challenge every government access request in court.
Action checklist PDF
Mirrors this guide with owners, artefacts & a 30/60/90-day plan.