Schrems II
In shortSince 2020 you must check for yourself whether your data is really protected in the destination country.
On 16 July 2020 the Court of Justice of the European Union invalidated the EU–US Privacy Shield. That was the headline. The more important part of the judgment sits further down and still applies.
What the judgment actually requires
Standard contractual clauses remain valid — but they are not sufficient on their own. Anyone using them must assess, before transferring, whether the destination country's law permits the protection they promise at all. That assessment is called a transfer impact assessment, and it is the exporting company's job, not the vendor's.
Where the assessment finds a gap, supplementary measures are required. The European Data Protection Board added an uncomfortable finding here: encryption helps only where the provider itself cannot reach the key. Encryption at rest with provider-managed keys protects against theft, not against a government order. See Key control (BYOK and HYOK).
Why the judgment still bites
In 2023 the Commission adopted a new adequacy decision, the EU–US Data Privacy Framework. For companies transferring to participating US providers, the individual assessment falls away. See Adequacy decision.
The judgment stays relevant for three reasons. First, the decision covers certified recipients only. Second, it covers no transfers to other third countries. Third, the underlying US legal position is unchanged — what changed is the redress mechanism, not the power.
The practical residue
What remains for daily work is an unglamorous duty: know where data goes. A record of processing activities that genuinely reflects the sub-processors behind each service is the precondition for any statement about sovereignty. Without that record, even the best European provider is just a feeling.