Since the “Schrems II” judgment of 16 July 2020, personal data transfers outside the EU/EEA can rely only on safeguards that are truly effective. The new 2021 Standard Contractual Clauses (SCCs) are the key tool for securing your flows, provided you conduct a Transfer Impact Assessment (TIA), add appropriate supplementary measures and choose the right contractual module.
What Schrems II changes for your transfers outside the EU
The Court of Justice invalidated the Privacy Shield and reiterated that the exporter must verify, case by case, that the third country's laws and practices do not prevent a level of protection “essentially equivalent” to the GDPR (CJEU, C-311/18, Schrems II). The EDPB confirmed this requirement and detailed the practical consequences in its dedicated FAQ (EDPB, Schrems II FAQ).
In practice, using SCCs is no longer sufficient “in itself”: you must analyse the risk of access by the importing country's authorities, the possibility of challenging access requests and, where necessary, deploy supplementary measures. Otherwise, the transfer must be suspended.
2021 SCCs in practice: modules, obligations and the end of the transitional period
On 4 June 2021, the European Commission adopted the new SCCs through Implementing Decision (EU) 2021/914, structured into modules according to the parties' roles (European Commission, Decision (EU) 2021/914). The transitional period ended on 27 December 2022: the old clauses can no longer be used or maintained (CNIL, statement of 21/12/2022).
Choosing the right module
- Module 1 – Controller to Controller (C→C)
- Module 2 – Controller to Processor (C→P) – incorporates GDPR Article 28 requirements
- Module 3 – Processor to Processor (P→P)
- Module 4 – Processor to Controller (P→C)
The 2021 SCCs include a “docking clause” allowing new entities to join by amendment, notification obligations for public-authority access requests, and the possibility of suspension/termination where compliance with the clauses becomes impossible.
Before signing, check whether an adequacy decision exists for the destination country. Otherwise, apply GDPR Article 46 and the appropriate SCCs (consult decisions and the GDPR text on EUR‑Lex). For the French framework and operational guidelines, see the CNIL page “Transferring data outside the EU” (CNIL).
TIA step by step: your Transfer Impact Assessment
The EDPB proposes a six-step method to assess and document a transfer's legality and security (EDPB, Recommendations 01/2020):
- 1) Map flows and identify third countries and recipients (including remote access from a third country, which constitutes a transfer – see CNIL).
- 2) Check the applicable legal mechanism (adequacy decision or 2021 SCCs).
- 3) Assess the importing country's laws and practices (authority access, remedies, effective safeguards).
- 4) Determine supplementary technical, organisational and contractual measures where necessary.
- 5) Document the analysis (TIA file) and obtain internal approval (DPO, management).
- 6) Reassess periodically and monitor legislative or technical changes.
Good TIA practices: classify data (sensitive/non-sensitive, purposes, volumes), map subprocessors, record residual risks and document effectiveness testing of measures (e.g. audits, penetration tests, key-management evidence).
Effective supplementary measures (technical, organisational, contractual)
SCCs may be insufficient if local law allows disproportionate access to data. The EDPB then recommends supplementary measures tailored to the use case (EDPB, Recommendations 01/2020):
- Technical: robust encryption in transit and at rest, ideally with keys managed by the exporter or a separate provider in the EU; irreversible pseudonymisation on the exporter's side; dataset segmentation; minimisation and short retention.
- Organisational: zero-trust access policies, detailed logging, regular access reviews, security/GDPR training, response plan for public-authority requests.
- Contractual: importer commitment to notify any access request without unjustified delay, challenge it where unfounded, provide transparency reports and allow suspension/termination if compliance is no longer possible (obligations under the 2021 SCCs – Decision (EU) 2021/914).
SaaS, cloud and AI use cases: common pitfalls and responses
- SaaS with EU servers but US support: remote access from a third country is a transfer. Deploy encryption and access restrictions, and sign the appropriate SCCs.
- AI tools through APIs outside the EU: check the role (controller/processor), SCC module, location of logs and models, and key governance. For an overview of GDPR obligations applied to AI, see our dedicated analysis GDPR and artificial intelligence: legal obligations.
- Long processing chain: use the docking clause and processor authorisation procedure. Our processing agreement guide covers Art. 28 obligations and subprocessor monitoring.
Governance and operational compliance
Structure your transfer programme around three pillars:
- Up-to-date mapping and records of processing and cross-border flows. Well-maintained processing records will save weeks during TIAs.
- Consistent documentation: signed SCCs, technical annexes (security measures), list of authorised processors, audit evidence. Align notices and your privacy policy with declared transfers.
- Roles and responsibilities: DPO, security, procurement, business teams. If resources are limited, an outsourced DPO can oversee the programme and your TIAs.
Penalties, inspections and the end of the old SCCs
Maintaining old clauses after 27 December 2022 is non-compliant according to the CNIL (CNIL statement). Transfers without appropriate safeguards expose you to administrative fines of up to €20 million or 4% of worldwide turnover, as well as transfer-suspension orders (see the GDPR framework on EUR‑Lex). The CNIL reiterates the available tools and the need for a documented TIA (CNIL – Transferring data outside the EU).
30‑60‑90-day action plan
- Day +30: map all transfers (including remote access), check for an adequacy decision, select the SCC module, launch priority TIAs.
- Day +60: sign the 2021 SCCs, complete security annexes, deploy encryption/pseudonymisation, define key management, formalise the response procedure for public-authority requests.
- Day +90: test effectiveness (audits, access reviews), update records and the privacy policy, schedule annual TIA review and compliance reporting. To scale this work, explore our guidance on contract and GDPR automation in your processes.
Further reading
Related resources
Frequently asked questions
FAQ
Are the old SCCs still valid?
No. The transitional period ended on 27/12/2022. Only the 2021 SCCs now apply (CNIL, statement of 21/12/2022).
Must I carry out a TIA for every transfer?
Yes, case-by-case assessment is required after Schrems II to evaluate the effective level of protection and define supplementary measures.
Which SCC module should I choose?
According to roles: C→C (Module 1), C→P (Module 2), P→P (Module 3), P→C (Module 4). Module 2 also covers GDPR Article 28.
Which technical measures are most effective?
Strong encryption with keys managed in the EU/by the exporter, prior pseudonymisation, data minimisation and segmentation.
Is remote access by support outside the EU a transfer?
Yes. Access from a third country is treated as a transfer and must be governed by SCCs/TIAs and appropriate measures.
References
Sources used
- EDPB - Frequently asked questions on the Schrems II judgment
- European Commission - 2021 Standard Contractual Clauses
- EDPB - Recommendations 01/2020 on post-Schrems II supplementary measures
- CJEU - Schrems II judgment (C-311/18)
- EDPB — European Data Protection Board
- CNIL - Transferring data outside the EU
- CNIL - Statement on the end of the SCC transitional period
- Overview of the CJEU's Schrems II judgment - CNIL
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.