International Data Transfers After Schrems II: The SCC Problem
Schrems II invalidated Privacy Shield and put Standard Contractual Clauses under new scrutiny. Here's what the ruling actually requires for transferring EU personal data outside the EEA.
If you’ve seen “Schrems II” referenced in privacy discussions and weren’t sure what it actually changed, here’s the short version: it’s the 2020 EU Court of Justice ruling that invalidated the EU-US Privacy Shield framework, and, more importantly for most businesses, put real teeth into the requirement that Standard Contractual Clauses (SCCs) alone aren’t automatically sufficient for transferring EU personal data outside the EEA.
What Schrems II actually decided
The case (brought by privacy activist Max Schrems, following an earlier case that struck down the Safe Harbor framework) challenged whether US surveillance law was compatible with the level of protection GDPR requires for transferred data. The court’s answer: Privacy Shield wasn’t adequate, and even where you’re relying on SCCs instead, you can’t just sign the standard contract and assume you’re done, you have to actually assess whether the recipient country’s laws let the data importer meet those contractual commitments in practice.
Why this created the “SCC problem”
Before Schrems II, using SCCs was largely a paperwork exercise, sign the standard clauses, transfer the data, move on. After Schrems II, the ruling implied you need a transfer impact assessment: evaluating whether the destination country’s government surveillance regime could override the protections in the SCCs, and if so, what supplementary measures (encryption, pseudonymization, technical access controls) you’d need to add. This is exactly the mechanism behind the Google Analytics rulings we cover in our GA4-specific piece, several regulators concluded SCCs alone didn’t suffice for transfers to Google’s US infrastructure, given US surveillance law.
How the EU-US Data Privacy Framework changes this, for the US specifically
In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, which addressed the specific concerns Schrems II raised about US surveillance access, for companies certified under it. If your vendor is DPF-certified, you don’t need to run the full transfer impact assessment for that transfer, the adequacy decision does that work. If your vendor isn’t certified, or you’re transferring to a country without an adequacy decision, the Schrems II analysis still applies in full.
CookieYes
Transfer mechanism aside, the consent layer for any tool sending data internationally still needs to be right, CookieYes helps confirm what's actually firing and where it's going before you even get to the transfer-assessment question.
What this means practically for a small or mid-size business
- Map where your data actually goes. For every vendor that processes EU personal data, note which country their infrastructure is in. This overlaps with the data inventory step in our GDPR compliance checklist.
- Check for an adequacy decision first. The EU maintains a list of countries (and, for the US, DPF-certified companies specifically) already deemed adequate, if your vendor and destination qualify, you’re largely done.
- If no adequacy decision applies, confirm SCCs are in place as part of your data processing agreement with that vendor, and ask the vendor directly whether they’ve done a transfer impact assessment, most larger vendors have already done this work and can point you to documentation.
- Don’t assume every transfer is high-risk. The rigor Schrems II calls for should scale with actual risk, a US-based email platform with strong technical safeguards is a different assessment than transferring sensitive data to a jurisdiction with a weaker legal framework.
The honest state of play
This area has moved a lot since 2020 and isn’t fully settled, the DPF itself may face future legal challenges, similar to its predecessors. Treat this as an area to periodically re-check rather than a box you tick once.
This guide reflects the legal landscape as of publication and is not legal advice. International transfer requirements are genuinely complex and fact-specific. Consult a privacy attorney for guidance on your specific vendor relationships and transfer mechanisms.