Zum Inhalt springen
Startseite Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Seqlense IMMO Krypto-Untersuchung OSINT-Untersuchung Schulung & Beratung Preise Unterstützte Blockchains Academy Blog Partner Kontakt
EN FR DE
Mein Seqlense Loslegen
Back to blog

Cross-border data transfers after Schrems II

Practical steps to keep transfers lawful, mapped and documented.

Cross-border data transfers are still one of the most audited parts of a GDPR programme, and for good reason. Since the Court of Justice struck down the Privacy Shield in July 2020, every controller and processor that sends personal data outside the European Economic Area has been expected to prove, not just assert, that the data stays protected. The rules have not gotten simpler. They have gotten more procedural. This is a practical guide to keeping your transfers lawful, mapped and documented.


What Schrems II actually changed

The 2020 judgment (often called Schrems II) did two things. It invalidated the EU-US Privacy Shield, and it kept Standard Contractual Clauses (SCCs) valid but attached a heavy condition: a transfer mechanism is only good enough if the destination country offers protection that is essentially equivalent to EU law. If it does not, you must add supplementary measures or stop the transfer.

In short, the paperwork is no longer the finish line. The clauses are a starting point, and you carry the burden of showing they hold up in practice.


The toolkit you have today

Under Chapter V of the GDPR, a transfer to a third country needs a legal basis. In descending order of how much work they leave you:

  • Adequacy decision. The Commission has declared certain countries (and specific frameworks) to provide adequate protection. Where one applies, you can transfer without extra safeguards.
  • Appropriate safeguards. Most commonly the 2021 SCCs, but also Binding Corporate Rules for intra-group transfers, or approved codes of conduct and certifications.
  • Derogations. Article 49 exceptions such as explicit consent or contractual necessity. These are narrow, situational and not built for routine or bulk transfers.

The European Commission adopted the modernised SCCs on 4 June 2021. They use a modular structure covering four scenarios: controller to controller, controller to processor, processor to sub-processor, and processor to controller. Pick the module that matches the real data flow, not the one that is easiest to sign.


The step nobody can skip: the Transfer Impact Assessment

Clause 14 of the 2021 SCCs bakes Schrems II directly into the contract. Before you rely on the clauses, you must assess whether the laws and practices of the destination country could stop your counterparty from honouring them. This is the Transfer Impact Assessment (TIA), and it is where most audit findings land.

A defensible TIA usually documents:

  1. The transfer in concrete terms: what data, whose data, which recipients, the sector, and how long the processing chain runs.
  2. The destination legal environment: government access powers, surveillance laws, and available redress for data subjects.
  3. Practical experience: whether the importer has actually received access requests, and how it handled them.
  4. Supplementary measures where needed: technical (strong end-to-end encryption, pseudonymisation), contractual, and organisational safeguards, guided by the EDPB Recommendations 01/2020.
  5. The conclusion and sign-off: either the transfer can proceed, proceeds with named measures, or is halted.

Treat the TIA as a living document. Re-open it when the law in the destination country changes, when you add a new sub-processor, or on a fixed review cycle.


Where the EU-US route stands now

For transatlantic flows, the picture improved but did not fully settle. In July 2023 the Commission issued an adequacy decision for the EU-US Data Privacy Framework (DPF). US organisations that self-certify to the framework can receive EU personal data without SCCs for that specific channel.

The DPF was challenged almost immediately. On 3 September 2025 the EU General Court, in Case T-553/23 (Latombe v Commission), dismissed the action and upheld the adequacy decision. That is reassuring, but two caveats matter for planning. The ruling can still be appealed to the Court of Justice on points of law, and adequacy only covers importers that are actually certified under the DPF. For any US recipient outside the framework, you are back to SCCs plus a TIA.

The practical takeaway: check the certification status of each US vendor, and keep SCCs ready as a fallback so a future court decision does not leave a transfer unlawful overnight.


Building the record that survives an audit

The common thread is documentation. A supervisory authority will not accept "we use SCCs" without the evidence behind it. A workable baseline:

  • A transfer register listing each flow, the data categories, the importer, the country, and the legal basis relied on.
  • The signed mechanism (SCC module, BCRs, or DPF reliance) for each entry.
  • A completed TIA with supplementary measures and a review date.
  • A link between each transfer and the vendor or sub-processor that carries it, so a new tag or a swapped hosting provider does not slip through undeclared.

That last point is where transfers quietly break. A marketing tool starts loading a new third-party script, or a processor moves data to a new region, and nobody updates the register. This is exactly the kind of drift Seqlense GDPR is built to catch: it renders your live pages in a real browser, captures the full network waterfall, and flags any host that is not in your declared vendor register. Pairing that continuous check with a documented TIA closes the gap between what your paperwork says and what your site actually does.


The short version

Map every transfer, choose a valid mechanism, run and record a TIA, verify DPF certification where you rely on it, and keep the whole record current. Schrems II did not ban international transfers. It just made proof mandatory.


Sources

Related articles

Turning regulatory noise into a prioritised action list

From raw feed to the few things your team must actually do this week.

Corporate structures and UBOs: following ownership across borders

Untangling who really controls an entity through layered ownership.