← Back to glossary

What the court decided

The court found that Privacy Shield's protections were not "essentially equivalent" to GDPR's, because US surveillance programs allow bulk collection of data from US-based providers without judicial review by EU-recognised standards. The ruling did not invalidate Standard Contractual Clauses (SCCs) entirely, but required controllers to assess whether the destination country's surveillance regime renders the SCCs ineffective.

The TIA framework that emerged

The European Data Protection Board's June 2021 guidance (Recommendation 01/2020) introduced the Transfer Impact Assessment. For every SCC-based transfer, controllers must assess the third country's legal regime and determine whether supplementary measures — technical, contractual, organisational — are needed.

The TIA process has become a substantial operational burden. Most legal teams produce templated TIAs that gesture at supplementary measures without specifying what would actually work — because contractual and organisational measures cannot defeat a foreign surveillance regime. Only technical measures can.

The EU-US Data Privacy Framework

In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), succeeding Privacy Shield. The DPF introduces a Data Protection Review Court and additional limitations on signals intelligence — but the same FISA 702 mechanisms remain, and the redress court is an executive-branch body. Most experts now expect a Schrems III challenge within 18-36 months.

The architectural answer

For organisations transferring personal data to the US (or to US-controlled providers wherever physically located), the practical advice is: do not architect assuming the DPF survives. Architect assuming it doesn't.

Technical supplementary measures that actually defeat foreign surveillance regimes require end-to-end encryption with keys held outside the third country, and where the third-country provider literally cannot derive the decryption key. Zero-knowledge architecture combined with multi-cloud erasure coding makes the TIA mechanically straightforward.

Read the full analysis →

Related terms

See also

Want to see this in production?