Chapter V of the GDPR restricts moving personal data outside the EEA. A transfer is lawful only through one of three routes: the destination benefits from an adequacy decision, the parties put appropriate safeguards in place (most often standard contractual clauses), or a narrow Article 49 derogation applies. Since the Schrems II judgment, safeguards alone are not enough; you must also assess whether the destination’s laws undermine them.
| Regulation | GDPR, Chapter V (Arts. 44 to 50) |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Key case | Schrems II, CJEU C-311/18 (July 16, 2020) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The three lawful routes
Adequacy (Art. 45). The European Commission has decided the destination provides essentially equivalent protection. Transfers flow freely, no extra paperwork. The US is partially covered: only recipients self-certified under the EU-US Data Privacy Framework since the July 10, 2023 decision.
Appropriate safeguards (Art. 46). Standard contractual clauses are the workhorse. The current set, Commission Decision 2021/914 of June 2021, comes in four modules covering each controller-processor permutation. Binding corporate rules serve intra-group transfers but take years to approve. Since Schrems II, every safeguard-based transfer needs a documented transfer impact assessment covering the destination’s government access laws, plus supplementary measures where needed.
Derogations (Art. 49). Explicit consent, contractual necessity, and a few other grounds, all interpreted narrowly and unsuitable for systematic transfers.
What Schrems II changed
The CJEU invalidated the EU-US Privacy Shield because US surveillance law (FISA 702, EO 12333) did not meet EU standards, and it held that SCC users must verify protection in practice, not just on paper. The enforcement consequences arrived quickly: decisions against the use of Google Analytics by the Austrian DSB and France’s CNIL in 2022, and the Irish DPC’s EUR 1.2 billion fine against Meta in May 2023 for continuing EU-US Facebook transfers, the largest GDPR fine to date. Uber followed in 2024 with a EUR 290 million fine from the Dutch DPA for transfers made without valid safeguards.
The practical checklist
- Map your transfers, including every SaaS vendor and every remote-access arrangement. Most organizations undercount by half.
- Check adequacy first, including DPF certification status for US vendors on the official DPF list.
- Execute the correct SCC module where adequacy does not apply, and complete a transfer impact assessment.
- Apply supplementary measures where the assessment finds risk: encryption with EEA-held keys is the strongest.
- Reflect all of it in your privacy notice, which Articles 13 and 14 require to disclose transfers and safeguards.
Your website is often the first undisclosed transfer: analytics, fonts, and ad tags routinely send visitor data to US servers. A free scan identifies which third-country recipients your site contacts, the same starting point a regulator would use.