EU Privacy Law EU/EEA

GDPR Cross-Border Transfers: SCCs, Transfer Impact Assessments, and Supplementary Measures

GDPR Chapter V transfer rules after Schrems II: adequacy decisions, the 2021 SCCs, transfer impact assessments, and the EU-US Data Privacy Framework.

Regulation

GDPR, Chapter V (Articles 44 to 50)

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Personal data may leave the EEA only through a Chapter V mechanism: an adequacy decision, appropriate safeguards such as SCCs or BCRs, or a narrow Article 49 derogation.
  • The CJEU's Schrems II judgment (C-311/18, July 2020) invalidated Privacy Shield and required transfer impact assessments alongside SCCs.
  • The current SCCs were adopted in June 2021 (Commission Decision 2021/914) in four modules; old-form SCCs have been invalid since December 27, 2022.
  • The EU-US Data Privacy Framework adequacy decision (July 10, 2023) covers transfers to self-certified US companies.
  • Transfer violations sit in the top fine tier and produced the largest GDPR fine ever: EUR 1.2 billion against Meta in May 2023.

Chapter V of the GDPR restricts moving personal data outside the EEA. A transfer is lawful only through one of three routes: the destination benefits from an adequacy decision, the parties put appropriate safeguards in place (most often standard contractual clauses), or a narrow Article 49 derogation applies. Since the Schrems II judgment, safeguards alone are not enough; you must also assess whether the destination’s laws undermine them.

RegulationGDPR, Chapter V (Arts. 44 to 50)
Max penaltyEUR 20M or 4% of global annual turnover
Key caseSchrems II, CJEU C-311/18 (July 16, 2020)
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The three lawful routes

Adequacy (Art. 45). The European Commission has decided the destination provides essentially equivalent protection. Transfers flow freely, no extra paperwork. The US is partially covered: only recipients self-certified under the EU-US Data Privacy Framework since the July 10, 2023 decision.

Appropriate safeguards (Art. 46). Standard contractual clauses are the workhorse. The current set, Commission Decision 2021/914 of June 2021, comes in four modules covering each controller-processor permutation. Binding corporate rules serve intra-group transfers but take years to approve. Since Schrems II, every safeguard-based transfer needs a documented transfer impact assessment covering the destination’s government access laws, plus supplementary measures where needed.

Derogations (Art. 49). Explicit consent, contractual necessity, and a few other grounds, all interpreted narrowly and unsuitable for systematic transfers.

What Schrems II changed

The CJEU invalidated the EU-US Privacy Shield because US surveillance law (FISA 702, EO 12333) did not meet EU standards, and it held that SCC users must verify protection in practice, not just on paper. The enforcement consequences arrived quickly: decisions against the use of Google Analytics by the Austrian DSB and France’s CNIL in 2022, and the Irish DPC’s EUR 1.2 billion fine against Meta in May 2023 for continuing EU-US Facebook transfers, the largest GDPR fine to date. Uber followed in 2024 with a EUR 290 million fine from the Dutch DPA for transfers made without valid safeguards.

The practical checklist

  1. Map your transfers, including every SaaS vendor and every remote-access arrangement. Most organizations undercount by half.
  2. Check adequacy first, including DPF certification status for US vendors on the official DPF list.
  3. Execute the correct SCC module where adequacy does not apply, and complete a transfer impact assessment.
  4. Apply supplementary measures where the assessment finds risk: encryption with EEA-held keys is the strongest.
  5. Reflect all of it in your privacy notice, which Articles 13 and 14 require to disclose transfers and safeguards.

Your website is often the first undisclosed transfer: analytics, fonts, and ad tags routinely send visitor data to US servers. A free scan identifies which third-country recipients your site contacts, the same starting point a regulator would use.

Frequently Asked Questions

What counts as a transfer under GDPR?

Making personal data available to a recipient in a third country, including remote access from outside the EEA. A US support team viewing EU customer records is a transfer even if the data never physically moves.

Are SCCs alone enough after Schrems II?

No. Schrems II requires a transfer impact assessment: evaluate the destination country's surveillance laws, and add supplementary measures such as strong encryption or pseudonymization where the SCCs alone cannot guarantee protection.

Do I still need SCCs for transfers to the US?

Not for recipients self-certified under the EU-US Data Privacy Framework, which benefits from the July 2023 adequacy decision. For US recipients that are not certified, SCCs plus a transfer impact assessment remain necessary.

Which countries have EU adequacy decisions?

The list includes the UK, Switzerland, Japan, South Korea, Canada (commercial organizations), Israel, New Zealand, Argentina, Uruguay, Andorra, the Faroe Islands, Guernsey, Jersey, the Isle of Man, and the US under the DPF. Check the European Commission's current list before relying on it.

What are the four SCC modules?

Module 1: controller to controller. Module 2: controller to processor. Module 3: processor to processor. Module 4: processor back to controller. Pick the module matching the actual relationship; mixing them up is a common audit finding.

Regulatory Crosswalk

EU-US Data Privacy FrameworkUK IDTASwiss FADP

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.