What Schrems II decided

On 16 July 2020, the Court of Justice of the European Union ruled in Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems (C-311/18) that the EU-US Privacy Shield framework — the dominant legal basis for transferring personal data from the EU to the United States — did not provide adequate protection. The court's reasoning centred on US surveillance law, specifically FISA Section 702 and Executive Order 12333, which permit bulk collection of data from US-based providers without judicial review by EU-recognised standards.

The immediate effect: thousands of organisations that had relied on Privacy Shield woke up the next morning with no clear legal basis for the EU-US transfers they were already making.

The Transfer Impact Assessment era

The European Data Protection Board's June 2021 guidance (Recommendation 01/2020) introduced the Transfer Impact Assessment (TIA). For every Standard Contractual Clause (SCC)-based transfer, controllers must assess the legal regime of the third country and determine whether supplementary measures — technical, contractual, organisational — are needed to bring the transfer in line with GDPR.

The TIA process has become a major operational burden. Most legal teams produce templated TIAs that gesture at supplementary measures without specifying what would actually work. The reason: contractual and organisational measures cannot defeat a foreign surveillance regime. Only technical measures can — and most technical measures aren't strong enough.

Why the EU-US Data Privacy Framework didn't end the conversation

In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), succeeding the invalidated Privacy Shield. The DPF introduces new safeguards: a Data Protection Review Court within the US Department of Justice, additional limitations on signals intelligence collection, redress mechanisms for EU data subjects.

Schrems himself, alongside privacy NGO noyb, signalled within hours that the DPF would face challenge — the same FISA 702 mechanisms remain, and the redress court is an executive-branch body, not an independent judiciary by EU standards. Most experts now expect a Schrems III ruling within 18-36 months.

The pragmatic answer for any organisation building infrastructure today: do not architect your data flows assuming the DPF survives. Architect them assuming it doesn't.

What "supplementary technical measures" actually look like

EDPB guidance lists three categories of supplementary measures: contractual, organisational, technical. Only technical measures defeat foreign surveillance regimes. Among technical measures, only end-to-end encryption with keys held outside the third country provides robust protection — and only if the third-country provider literally cannot derive the decryption key.

This is where most "GDPR-ready" cloud postures fail. Customer-managed keys held in the provider's KMS do not defeat the FISA 702 vector. Region selection within a US-headquartered provider does not defeat it. Zero-knowledge architecture — where the server has no API path that returns plaintext — does.

What sovereignty by architecture means in this context

SkyeConnex makes the TIA mechanically simpler. Every file is encrypted client-side with a key derived on the client; the server never holds the key in unwrapped form. The file is Reed-Solomon erasure-coded across providers in jurisdictions the customer chooses — no single provider, in no single country, can decrypt or reassemble the file.

For a TIA, this means: even if data were physically routed through a US-controlled provider, the legal regime of that provider would have no path to readable data. The "supplementary technical measures" question answers itself.

What to do now

  • Treat the DPF as a temporary bridge, not a permanent settlement.
  • Architect new data flows assuming a Schrems III decision lands in 2027-2028.
  • Push storage decisions toward architectures where the technical layer enforces sovereignty — making the legal question moot.

If you're rewriting your TIA framework this quarter and want a sovereign-by-architecture default for your EU data, book a briefing. We will walk you through how SkyeConnex maps to every Schrems II requirement, live, in 45 minutes.


Published June 4, 2026 · Written by SkyeConnex Inc. · More from the SkyeConnex blog

See SkyeConnex live.