Schrems II is the shorthand for the Court of Justice of the European Union (CJEU) judgment in case C-311/18, delivered on 16 July 2020. It invalidated the EU-US Privacy Shield with immediate effect and made every organization that moves personal data out of the European Economic Area (EEA) responsible, under the General Data Protection Regulation (GDPR), for assessing whether that data is actually protected where it lands. For small and mid-sized enterprises (SMEs), the judgment is not an abstraction: most of the transfers it governs happen quietly, through the everyday software-as-a-service (SaaS) stack.
Several years on, the practical picture has settled into something manageable. This article covers what the court actually decided, what replaced Privacy Shield, the transfer toolbox as it now stands, what an SME should concretely do, the UK position, and the duties that continue after the paperwork is signed.
What the court decided
Two holdings matter. First, the court invalidated the adequacy decision underlying the EU-US Privacy Shield, without any transition period, because it found that United States law on government access to data did not provide protection essentially equivalent to EU law and that individuals in the EU lacked effective redress. Transfers relying on Privacy Shield lost their legal basis on the day of the judgment.
Second, the court upheld Standard Contractual Clauses (SCCs) as a transfer tool, but attached a condition that reshaped practice: an exporter relying on SCCs must verify, case by case, whether the law and practice of the destination country allow the clauses to be honored in fact, adopt supplementary measures where they do not, and suspend the transfer where nothing helps. Supervisory authorities are required to intervene where protection cannot be ensured. That verification is what became known as the Transfer Impact Assessment (TIA); a practical TIA walkthrough is available separately.
What replaced Privacy Shield
In Implementing Decision (EU) 2023/1795, adopted on 10 July 2023, the European Commission granted adequacy to the EU-US Data Privacy Framework (DPF), following changes to United States law on the necessity and proportionality of intelligence access and the creation of a new redress mechanism for people in the EU. Transfers to United States organizations certified under the DPF can rely on that adequacy decision, without SCCs and without a TIA.
Three checks come before relying on it. The importing entity must actually hold a certification, which is verifiable on the public list maintained by the United States Department of Commerce. The certification must be current, since organizations can lapse or withdraw. And its scope must cover the data concerned, since human-resources data is covered only where the certification extends to it. The DPF covers nothing else: transfers to non-certified United States importers, and to every other third country, still need a tool from the toolbox below. The adequacy decision is also subject to periodic review and to the possibility of legal challenge, so its current status is worth re-verifying rather than assuming.
Schrems II itself is the argument for treating that status as something to monitor rather than settled fact. As of July 2026 the DPF adequacy decision remains in force and is also under active challenge: the EU General Court dismissed an annulment action against it in September 2025, and an appeal against that ruling is pending before the Court of Justice. An adequacy arrangement has been struck down before, with immediate effect, and organizations without a fallback had to renegotiate their transfer arrangements at speed. Many Data Processing Agreements (DPAs) now layer SCCs beneath the DPF as a fallback mechanism. Knowing which of your vendors rely on the DPF today, and which would fall back to SCCs and therefore need an assessment ready, turns a possible future ruling into a manageable task list instead of a scramble.
The transfer toolbox today
- Adequacy decisions: the European Commission has found a set of countries adequate, and transfers to them need no additional tool. Check the current list rather than folklore, and remember that adequacy can be reviewed or invalidated, as Schrems II itself demonstrated.
- SCCs plus a TIA: the workhorse for everything else. The 2021 clauses come in four modules covering the controller and processor combinations, and their Clause 14 builds the assessment duty into the contract itself.
- Binding Corporate Rules (BCRs): approved intra-group transfer frameworks, realistic mainly for larger corporate groups given the approval effort involved.
- Derogations under Article 49: narrow exceptions, such as explicit consent or contractual necessity, designed for occasional, specific situations rather than the systematic flows of a SaaS relationship.
What this means for an SME running on SaaS
An SME rarely negotiates transfers; it inherits them. The email platform, the customer relationship management system, the support desk, the analytics tool, and the payroll service each come with their own processing locations and subprocessor chains, and the analysis has to follow the chain, not just the vendor: an EEA-based vendor with United States subprocessors still puts you in transfer territory. What to do when a subprocessor moves data outside the EEA is its own topic; the sequence below is the vendor-by-vendor baseline.
- Inventory your transfers, including subprocessor chains, using DPA annexes and vendor subprocessor lists as the sources.
- For each United States vendor, check DPF certification, its currency, and its scope. Where it covers the transfer, adequacy applies and the analysis is short.
- Where it does not, rely on SCCs and run a TIA proportionate to the transfer.
- Adopt supplementary measures where the assessment identifies a gap, with technical measures such as encryption with keys held in the EEA doing the real work.
- Document each conclusion with a date and an owner, and revisit when the facts change.
Proportionality is legitimate throughout. Chapter V of the GDPR contains no SME exemption, but nothing requires a small controller to produce institutional-scale assessments for routine tools. Short, specific, dated records beat long generic ones, both for internal sanity and in front of a supervisory authority.
Sequence the work by exposure rather than alphabetically. Vendors processing employee data, customer records at scale, or anything touching the special categories of data deserve the first pass; a tool holding little more than business contact details can wait its turn. The inventory usually shrinks the problem as well: a small set of vendors typically accounts for most of the personal data actually leaving the EEA, and finishing those first covers most of the exposure while the long tail proceeds at a calmer pace.
The UK position in brief
The United Kingdom operates its own regime under the UK General Data Protection Regulation (UK GDPR). Transfers from the UK need a UK-recognized mechanism: the International Data Transfer Agreement (IDTA), or the EU SCCs combined with the UK Addendum, alongside the UK's own adequacy findings, which include an extension arrangement covering DPF-certified United States organizations. The Information Commissioner's Office (ICO) publishes guidance on international transfers, including its expectation of a transfer risk assessment where the IDTA or Addendum is used, along with a transfer risk assessment tool that smaller organizations can use as a working template. Organizations moving both EU and UK data through the same vendors should run the checks under both regimes; the facts are shared, the paperwork is not.
The duties that continue
Schrems II turned transfers from a signing exercise into a monitored state. Subprocessor locations change, vendors gain and lose DPF certifications, adequacy decisions come up for review, and each of those events can quietly invalidate yesterday's analysis. The continuing duties are concrete: watch vendor subprocessor lists and transfer disclosures for changes, re-run assessments at appropriate intervals and when events demand it, and keep the documentation current enough that you could hand it over this week without embarrassment. A vendor watchlist reviewed on a schedule, with subprocessor pages checked for changes and a diary entry for adequacy developments, is enough process for most SMEs; what does not work is treating the signature date of the SCCs as the end of the story.
Frequently asked questions
Is Privacy Shield still valid?
No. It was invalidated on 16 July 2020 with immediate effect. Its successor for transfers to the United States is the DPF adequacy decision of July 2023, which covers only United States organizations holding a current certification, and only for the data within the certification's scope.
Do we still need SCCs with United States vendors?
Not for transfers genuinely covered by a vendor's current DPF certification. SCCs remain necessary for non-certified vendors, for data outside a certification's scope, and for other third countries. Many contracts keep SCCs in place as a fallback; where you actually rely on them, the TIA duty applies.
Does Schrems II apply to small companies?
Yes. Chapter V of the GDPR contains no size threshold, and the judgment draws no distinction. What scales with size is the depth of the exercise: an SME can meet the duty with proportionate, specific, well-documented assessments rather than institutional ones.
Is an EEA-based vendor enough to avoid transfer rules?
Not necessarily. If the vendor's subprocessors process personal data outside the EEA, those onward legs are transfers too, and the chain needs a valid tool and an assessment behind it. The vendor's subprocessor list, and how it changes over time, is the fact that determines the answer.
What are supplementary measures?
Additional protections layered on top of a transfer tool where the destination country's law would otherwise undermine it. The effective ones are mostly technical, such as encryption with keys held in the EEA, or pseudonymization where the information needed to re-identify people stays in Europe; contractual and organizational measures can support them but rarely suffice on their own. The European Data Protection Board's recommendations on supplementary measures set out the reference scenarios.
Where DPAFlow fits in
The continuing duties are where tooling earns its keep. DPAFlow monitors vendor subprocessor lists, DPA pages, and trust-center pages on a scheduled, recurring basis, detects changes such as new subprocessor locations, records them with dated evidence, and alerts the team by email. Its Transfer Impact Assessment module helps create, maintain, and export structured TIA records, so a re-assessment starts from the current version instead of a search through inboxes. The legal calls stay with your counsel; the facts that should trigger them stop going unnoticed.