Schrems II & Cross-Border Data Transfers under GDPR: A Professional Compliance Guide
Under the European Union’s General Data Protection Regulation (GDPR), protecting the rights and freedoms of data subjects is paramount, even when their personal data crosses international borders. GDPR Chapter V establishes the strict rules governing these transfers. However, navigating cross-border compliance has become one of the most critical legal challenges for corporate counsels, compliance officers, and DPOs globally following the landmark rulings of the Court of Justice of the European Union (CJEU).
The Fallout of Case C-311/18 (Schrems II)
In July 2020, the CJEU issued its decision in Case C-311/18, widely known as Schrems II. The court invalidated the EU-US Privacy Shield framework because of concerns over sweeping government surveillance programs under United States law (such as FISA Section 702 and Executive Order 12333) and the lack of judicial remedies for European citizens.
While the CJEU upheld the validity of the Standard Contractual Clauses (SCCs), it placed a major condition: exporters must assess, on a case-by-case basis, whether the recipient country's legal landscape provides an "essentially equivalent" level of protection to the GDPR. If it does not, they must implement supplementary measures.
The Role of the Transfer Impact Assessment (TIA)
A Transfer Impact Assessment (TIA) is a documented risk assessment of an international transfer. In accordance with the EDPB Recommendations 01/2020, a compliant TIA follows a structured six-step methodology:
- Identify the Transfer: Map all personal data exported outside the European Economic Area (EEA).
- Determine the Safeguard: Select the transfer tool under GDPR Article 46 (e.g. SCCs, BCRs).
- Analyze the Law of the Recipient Country: Assess whether local laws (particularly on law enforcement and national intelligence access) undermine the effectiveness of the safeguards.
- Adopt Supplementary Measures: Implement Technical, Organizational, and Legal measures to address any deficiencies.
- Execute Formal Steps: Integrate the selected safeguards into transfer agreements and operational policies.
- Re-evaluate Periodically: Monitor legal and geopolitical updates in the recipient country that may affect risk.
Technical and Organizational Supplementary Measures (TOMs)
To successfully defend a cross-border transfer under Schrems II, organizations must demonstrate that intelligence agencies cannot access cleartext personal data. The EDPB explicitly outlines that technical measures are the primary defense, as contractual and legal measures alone cannot prevent physical government intercept.
- EEA-Held Encryption Keys: Data is encrypted before export, and keys are held strictly by the exporter in Europe. Even if a foreign government subpœnas the importer, they cannot decrypt the data.
- State-of-the-Art Pseudonymization: Exporters strip direct identifiers so that the data is meaningless to any external interloper.
- Contractual Commitments to Appeal: Importers must legally bind themselves to resist, contest, and appeal all surveillance subpoenas in competent courts.