Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

The good, the bad and the ugly: Standard contractual clauses after Schrems II

By Mike Slipsky, Saad Gul
Outsourcing Data: Don't Take a Fairytale Approach
August 7, 2020

Countless businesses export data from the European Union to the United States. Does your human resources office have information on European employees? The sales department information on European clients? That is personal data. The question is if data exports can continue in the wake of the Court of Justice of the European Union’s (CJEU) ruling in the “Schrems II” case.

In Schrems II, the CJEU held that standard contractual clauses (SCCs) were an acceptable data transfer mechanism – provided these came with “adequate safeguards.” As EU Data Protection Authorities (DPA) release their interpretations, it becomes clear that adequate safeguards, like beauty, are in the eyes of the beholder. Thus whether SCCs remain viable turns on the identity of the DPA. So much for a uniform EU-wide privacy regime.

DPAs have released widely divergent assessments in the wake of Schrems II. From an American perspective, these assessments can be classified into three broad categories. The good. The bad. And the ugly.

First, there is the good. These DPAs take the view that Schrems II has actually confirmed the legal validity of SCCs. Denmark’s Datatilsynet has stated that SCCs are “still valid,” generally. The European Data Protection Board (EDPB) cautiously noted that the CJEU judgment allowed SCC enabled data transfers to proceed. France, Lithuania, Poland, Romania, Slovenia, and Spain also took a similar view. The United Kingdom and Switzerland, non-EU members still affected by the ruling, were also optimistic.

Second, there is the bad. These are the DPAs that clearly disfavor EU data transfers to the United States, but stopped short of finding them categorically unlawful. These DPAs stress the SCCs must be used in combination with “adequate safeguards.” The assessment of the adequacy of these safeguards is the responsibility of the sending company. If the protection of personal data cannot be guaranteed, the transfer is unlawful.

For example, Germany’s Commissioner for Data Protection and Freedom of Information has observed that transferring data to the United States relying on SCCs is risky. Estonia takes a similar tack. Companies must undertake an assessment. If the protection of personal data cannot be guaranteed, the transfer is prohibited. The Rhineland-Palatinate DPA likewise emphasized the sending company’s due diligence obligations.

This view holds the SCC-based data transfers are problematic. Without alternative transfer instruments, such data transfers “are no longer possible.” So the Thuringia DPA considers it “unlikely” that SCCs can still be used to legally transfer data to the U.S. Perhaps the biggest surprise here is Ireland. The Irish Data Protection Commission stated that SCC transfer mechanisms are now “questionable.” The validity of each transfer must be determined “on a case by case basis.”

Third, there is the ugly. Some DPAs have suggested that data transfers to the United States are categorically unlawful if they hinge on SCCs. These include the Berlin and Netherlands DPAs. These DPAs have suggested that companies limit the data to the EU itself. Alternatively, the data should be sent to a third country with an adequacy determination. But transferring data to the United States stops just short of being verboten.

So what is the takeaway? The diverse array of responses suggests that not all DPAs are looking at Schrems II the same way. And the validity of SCC enabled data transfers remains in doubt. The pivotal question is what “additional measures” – if any – enable SCCs to provide personal data the same protection as EU law. The EDPB and multiple DPAs, including Ireland, Denmark, Switzerland, Lithuania, Liechtenstein, France, the Netherlands, and Norway have suggested that guidance will be forthcoming. The data processing world will be waiting.

KEYWORDS: data protection European security information security privacy concerns risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Slipsky mike final headshot

Mike Slipsky, editor of NC Privacy Law Blog, is a partner with Poyner Spruill LLP. He advises clients on a wide range of privacy, data security, and cyber liability issues, including risk management plans, regulatory compliance, cloud computing implications, and breach obligations. Mike may be reached at 919.783.2851 or mslipsky@poynerspruill.com.

Gul saad final headshot

Saad Gul, editor of NC Privacy Law Blog, is a partner with Poyner Spruill LLP. He advises clients on a wide range of privacy, data security, and cyber liability issues, including risk management plans, regulatory compliance, cloud computing implications, and breach obligations. Saad (@NC_Cyberlaw) may be reached at 919.783.1170 or sgul@poynerspruill.com. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Thought bubbles

    Lessons from the Security 500 Conference: The good, the bad, and the ugly

    See More
  • cyber email

    Digital Paper Trails: The Good, the Bad, and the Ugly

    See More
  • Wireless Video: the Good, the Bad and the Ugly

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

  • Risk Analysis and the Security Survey, 4th Edition

  • 150 things.jpg

    The Handbook for School Safety and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing