Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here's what's changed — and what hasn't.
What Schrems II decided
On 16 July 2020, the Court of Justice of the European Union ruled in Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems (C-311/18) that the EU-US Privacy Shield framework — the dominant legal basis for transferring personal data from the EU to the United States — did not provide adequate protection. The court's reasoning centred on US surveillance law, specifically FISA Section 702 and Executive Order 12333, which permit bulk collection of data from US-based providers without judicial review by EU-recognised standards.
The immediate effect: thousands of organisations that had relied on Privacy Shield woke up the next morning with no clear legal basis for the EU-US transfers they were already making.
The Transfer Impact Assessment era
The European Data Protection Board's June 2021 guidance (Recommendation 01/2020) introduced the Transfer Impact Assessment (TIA). For every Standard Contractual Clause (SCC)-based transfer, controllers must assess the legal regime of the third country and determine whether supplementary measures — technical, contractual, organisational — are needed to bring the transfer in line with GDPR.
The TIA process has become a major operational burden. Most legal teams produce templated TIAs that gesture at supplementary measures without specifying what would actually work. The reason: contractual and organisational measures cannot defeat a foreign surveillance regime. Only technical measures can — and most technical measures aren't strong enough.
Why the EU-US Data Privacy Framework didn't end the conversation
In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), succeeding the invalidated Privacy Shield. The DPF introduces new safeguards: a Data Protection Review Court within the US Department of Justice, additional limitations on signals intelligence collection, redress mechanisms for EU data subjects.
Schrems himself, alongside privacy NGO noyb, signalled within hours that the DPF would face challenge — the same FISA 702 mechanisms remain, and the redress court is an executive-branch body, not an independent judiciary by EU standards. Most experts now expect a Schrems III ruling within 18-36 months.
The pragmatic answer for any organisation building infrastructure today: do not architect your data flows assuming the DPF survives. Architect them assuming it doesn't.
What "supplementary technical measures" actually look like
EDPB guidance lists three categories of supplementary measures: contractual, organisational, technical. Only technical measures defeat foreign surveillance regimes. Among technical measures, only end-to-end encryption with keys held outside the third country provides robust protection — and only if the third-country provider literally cannot derive the decryption key.
This is where most "GDPR-ready" cloud postures fail. Customer-managed keys held in the provider's KMS do not defeat the FISA 702 vector. Region selection within a US-headquartered provider does not defeat it. Zero-knowledge architecture — where the server has no API path that returns plaintext — does.
What sovereignty by architecture means in this context
SkyeConnex makes the TIA mechanically simpler. Every file is encrypted client-side with a key derived on the client; the server never holds the key in unwrapped form. The file is Reed-Solomon erasure-coded across providers in jurisdictions the customer chooses — no single provider, in no single country, can decrypt or reassemble the file.
For a TIA, this means: even if data were physically routed through a US-controlled provider, the legal regime of that provider would have no path to readable data. The "supplementary technical measures" question answers itself.
What to do now
- Treat the DPF as a temporary bridge, not a permanent settlement.
- Architect new data flows assuming a Schrems III decision lands in 2027-2028.
- Push storage decisions toward architectures where the technical layer enforces sovereignty — making the legal question moot.
If you're rewriting your TIA framework this quarter and want a sovereign-by-architecture default for your EU data, book a briefing. We will walk you through how SkyeConnex maps to every Schrems II requirement, live, in 45 minutes.
Published June 4, 2026 · Written by SkyeConnex Inc. · More from the SkyeConnex blog
Hand-picked for what you just read
The CLOUD Act and why data residency isn't enough
What a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read → Regulation · 6 min readWhy 'Canadian-flag cloud' is not Canadian sovereignty
A US-headquartered hyperscaler with a Canadian holding company is still subject to US legal process. Sovereignty by corporate paperwork is f…
Read → Cryptography · 7 min readWhy customer-managed keys aren't zero-knowledge
Customer-managed keys (CMK) are hyperscalers' answer to the sovereignty question. They're better than provider-managed keys. They don't deli…
Read →