This blog post contains information about the EDPB guidance for data protection, how to establish a trusted security framework for moving forward, and how the unified approach to data protection that Thales employs can help organizations. Please contact Thales for more information about Thales Data Protection solutions.
How does Schrems II impact transatlantic data transfers?
The Schrems II ruling by the European Court of Justice invalidated the EU–US Privacy Shield framework. This means organizations can no longer rely on Privacy Shield (or its predecessor, Safe Harbor) as a legal basis for transferring personal data from the EU to the US.
Instead, companies now depend on Standard Contractual Clauses (SCCs) plus additional safeguards to meet EU data protection requirements. The European Data Protection Board (EDPB) has made it clear that:
- Contractual and organizational measures alone are not enough to ensure GDPR compliance.
- Technical measures, especially strong encryption or pseudonymization, are necessary to mitigate the risk of access to personal data by public authorities.
This is a significant challenge because transatlantic data flows are central to global business. Today, they account for more than half of Europe’s data flows and about half of US data flows globally. Organizations now need to rethink how they secure these flows to maintain compliance and preserve customer trust.
What technical measures does the EDPB recommend after Schrems II?
The EDPB’s recommendations focus on strengthening technical controls so that personal data remains protected even when transferred outside the EU. Key measures include:
- Encrypt data before transfer
Data should be encrypted prior to leaving the European Economic Area (EEA), especially when the data importer does not need to see it in clear text. This applies to data in motion and at rest in cloud environments and data centers.
- Keep encryption keys under EU control
The EDPB places special emphasis on key management. Encryption keys must remain under the sole control of the data exporter within the EEA. In practice, this means:
- The cloud or service provider should not control or access your keys.
- Keys should be created, stored, and managed in the country of origin of the data.
- Use encryption and pseudonymization as primary safeguards
While contractual and organizational measures are useful, the EDPB is clear that they are only complementary. Robust technical measures—encryption, pseudonymization, and strong access controls—are essential to meet the EU level of data protection.
By combining these measures, organizations can build a more trusted privacy framework for transatlantic data flows and better align with GDPR expectations.
How can Thales help implement Schrems II and EDPB recommendations?
Thales helps organizations reimagine their data protection strategy so they can comply with Schrems II, operationalize the EDPB’s guidance, and address broader security risks.
Key capabilities include:
- Unified data discovery and classification
Thales solutions help you discover and classify data wherever it resides, so you know what is sensitive and which GDPR-aligned controls to apply.
- Robust encryption and independent key control
Thales enables strong encryption for data in motion and at rest, including in cloud and data center environments. Crucially, you can create, store, and manage encryption keys in the data’s country of origin, ensuring you—not your cloud provider—control access.
- Advanced access controls and tokenization
With fine-grained user and application access controls, plus support for BYOE (Bring Your Own Encryption) and tokenization, Thales helps protect sensitive data both in EU (data exporter) and non-EU (data processor) locations.
- Support for emerging threats
The 2026 Thales Bad Bot Report shows daily AI-enabled bot attacks jumped from 2 million to 25 million in a single year, and that 46% of account takeover attacks target Financial Services while 20% of AI bot attacks target Retail websites. Thales provides AI runtime security and data-centric controls to help mitigate these risks. In parallel, Thales offers guidance and assessments to prepare for post-quantum threats, encouraging organizations to plan now for post-quantum readiness.
By taking this unified approach—data discovery, classification, protection, and access control—Thales helps reduce the resources needed for day-to-day security operations, improve compliance coverage, and lower overall business risk, while maintaining trust in digital services across consumers, partners, and employees.