This blog post discusses the consequences of the Schrems II decision for data transfers with the EU. Please contact Thales for more information on how Thales data protection solutions can help.
What did the Schrems II decision change for EU–US data transfers?
On July 16, 2020, the Court of Justice of the European Union issued the Schrems II decision in the case Data Protection Commission v. Facebook Ireland. This ruling:
- Invalidated the EU–US Privacy Shield Framework, which more than 5,000 US companies had relied on to conduct trans-Atlantic trade in compliance with EU data protection rules.
- Impacts other personal data transfers from Europe to the US and potentially to other non-EU countries.
- Requires companies and regulators to perform case-by-case analyses to determine whether foreign protections around government access to transferred data meet EU standards.
For your business, this means you can no longer assume that a single framework like Privacy Shield is enough. You need to:
- Review your cross-border data flows, especially EU–US transfers.
- Assess whether the destination country’s laws and practices provide protections equivalent to EU requirements.
- Be prepared that, in some cases, terminating certain data transfers may be necessary. For some organizations, this could mean a partial or even complete shutdown of specific services or business lines if no compliant alternative is found.
The overall impact depends on your geography, industry vertical, and how much strategic privacy planning you have already done to sustain GDPR compliance.
How should we adapt our data protection strategy after Schrems II and Brexit?
The Schrems II decision, combined with Brexit and increased cloud adoption, is reshaping how organizations need to manage data beyond borders. Several trends are converging:
- Work-from-home and COVID-19 have increased reliance on public cloud infrastructures.
- The EU–UK post-Brexit agreement and guidance from regulators such as the EDPS emphasize risk assessments before transferring data.
- Organizations can no longer rely only on legal tools; they need stronger technical safeguards.
Practical steps to adapt your strategy include:
- Perform transfer risk assessments
Before moving personal data outside the EU or UK, evaluate the legal environment and government access risks in the destination country.
- Supplement contracts with technical controls
Standard contractual clauses and legal remedies are no longer sufficient on their own. You may need to add controls such as strong encryption, key management, and access controls to keep transfers transparent, safe, and lawful.
- Cover both direct and third-party transfers
Safeguards should apply not only to your own transfers but also to those performed by cloud providers and other third parties acting on your behalf.
- Invest in data discovery and classification
Not all data is created equal. Use solutions that identify and classify all data you hold so you can apply heightened protection to the most sensitive categories and reduce complexity when securing data at rest and in transit.
- Embed security-by-design and accountability
Make data protection, transparency, and responsible development part of how you deploy emerging technologies, to reduce risks such as marginalization or discrimination of social groups.
By combining legal, organizational, and technical measures, you can reimagine your data protection strategy to stay compliant while continuing to use cloud and cross-border services effectively.
Why is strong data protection becoming a business differentiator?
Data protection is no longer just a compliance checkbox; it is increasingly a market differentiator.
From the Thales perspective, several factors are driving this shift:
- Customers care about their data and how it is handled. They are willing to take action—such as switching providers—if they feel their privacy is not respected.
- Studies like the Thales Digital Trust Index focus on how digital experiences affect trust across consumers, partners, and employees, underscoring that trust is now a measurable business asset.
- Emerging risks, including AI-enabled bot attacks (which Thales reports have grown from 2 million to 25 million daily in a single year), are raising awareness of security as a core expectation, not a nice-to-have.
To turn data protection into a business advantage, organizations are:
- Embedding security-by-design into products and services.
- Prioritizing transparency and accountability in how data is collected, stored, and shared.
- Adopting responsible development practices for emerging technologies to limit unintended impacts such as marginalization or discrimination.
When you demonstrate that you protect sensitive data wherever it is created, shared, or stored, you not only reduce the risk of breaches and regulatory issues—you also build digital trust that can strengthen relationships with customers, partners, and employees.