Why transatlantic data transfers keep businesses awake
Almost every European business sends personal data to the United States – through cloud services, analytics tools, email platforms and support software. Under the GDPR, such transfers are only lawful if the data enjoys essentially the same protection abroad as it does inside the EU. Twice before, the legal basis for EU–US transfers has been struck down by the Court of Justice: Safe Harbor in 2015 and Privacy Shield in 2020. The current mechanism, the EU–US Data Privacy Framework, is now facing pressure of its own, and companies need a plan that survives whatever comes next.
The Data Privacy Framework today
The EU–US Data Privacy Framework rests on an adequacy decision the European Commission adopted on 10 July 2023. It allows personal data to flow to US organisations that self-certify under the Framework, without additional safeguards. As things stand, the Framework remains valid and businesses can continue to rely on it for transfers to certified recipients.
The legal challenges hanging over it
The Framework’s future is contested. A challenge brought by MEP Philippe Latombe was dismissed by the EU General Court, but an appeal is pending before the Court of Justice. Separately, privacy campaigners have signalled a fresh challenge – a potential “Schrems III” – arguing that recent developments in the United States undermine the independent oversight the Framework depends on. Businesses should assume the position could change and avoid building on the Framework as if it were permanent.
Standard contractual clauses as a fallback
If the adequacy decision were to fall, transfers would need another legal basis under Chapter V of the GDPR – most commonly the Commission’s standard contractual clauses (SCCs). SCCs are not a rubber stamp: they require a transfer impact assessment that examines whether the laws of the destination country could undermine the clauses, and supplementary measures such as encryption or pseudonymisation where they might. Keeping SCCs and assessments ready is the practical hedge against a sudden change.
Practical example
A Swedish company uses a US cloud provider certified under the Data Privacy Framework. To stay resilient, it records which supplier relationships rely on the Framework, ensures each contract also contains up-to-date standard contractual clauses as a backstop, and keeps a transfer impact assessment on file. If the adequacy decision were invalidated, the company could switch its legal basis to the SCCs already in place without interrupting the service.
Common mistakes companies make
The first mistake is not knowing where data actually goes – many transfers happen through sub-processors a business has never mapped. The second is relying solely on the Framework with no fallback, leaving no legal basis if it is struck down. The third is treating standard contractual clauses as a formality and skipping the transfer impact assessment that gives them substance.
Recommended actions
Map your international data flows, including sub-processors. For each US transfer, confirm whether the recipient is certified under the Data Privacy Framework and ensure standard contractual clauses are also in place as a backstop. Carry out and document transfer impact assessments. Watch the pending litigation, and prepare a contingency plan so a change in the Framework’s status does not leave you exposed.
Frequently asked questions
Is the EU–US Data Privacy Framework still valid?
At the time of writing, yes – transfers to certified US organisations remain lawful under the 2023 adequacy decision, though the Framework faces pending legal challenges.
What happens if the Framework is invalidated?
Transfers would need another Chapter V basis, most often standard contractual clauses supported by a transfer impact assessment and, where needed, supplementary measures.
Do we need SCCs if our provider is certified?
Certification is enough today, but keeping SCCs in place as a backstop is prudent given the uncertainty over the Framework’s future.
Conclusion
EU–US data transfers rest on ground that has shifted twice before and is under pressure again. The businesses that stay compliant are those that map their flows, keep standard contractual clauses and assessments ready as a backstop, and plan for change rather than assume permanence. Lawgent helps companies audit their international transfers, put robust safeguards in place and prepare for the next chapter of transatlantic data law. Get in touch to make your data transfers resilient.