The status of legality of personal data transfer with the US

Although tonnes of data flow between the United States (US) and Europe every day, the legal foundation for these transfers has been under pressure for some time. Recent case law from the US has prompted questions from various quarters to the European Commission (EC): does this foundation still hold? This blog takes a brief look.

A quick recap of the rules

The General Data Protection Regulation (GDPR) sets out conditions for sharing personal data outside the European Economic Area (EEA). These appear in Chapter V (for those who like detail) and essentially require that the destination country or region offers roughly the same level of protection for individuals as we provide here in the EEA. Transfers can be lawful if the EC has decided the country is adequate (an adequacy decision), or if, for example, pre-approved standard agreements have been concluded between your organisation and the third party (known as Standard Contractual Clauses, or SCCs).

Much of our digital infrastructure here in the Netherlands, and across Europe, runs on US-based software. Personal data travels back and forth constantly, and this transfer happens commonly on the basis of an adequacy decision. The EC previously determined that protection in the US was sufficient, following additional safeguards introduced under the Biden administration.

The current situation

Right now (as on several occasions before), that decision is once again on shaky ground. A recent US ruling (Trump v Slaughter) has raised doubts about the independence of supervisory authorities. It was precisely that supervisory authority which formed one of the safeguards that led the EC to conclude that US protection was adequate. This adequacy decision is referred to as the Data Privacy Framework (DPF; read more here). At the end of August, the EDPB (European Data Protection Board, the collective of European privacy supervisors) asked the EC to examine whether this ruling affects the adequacy decision. In the Netherlands, parliamentary questions on the consequences have since been answered as well.

The EDPB and other parties are right to flag this, but bear in mind that the EC must continuously assess the validity of adequacy decisions in light of current events and developments. The EC has already indicated that it is studying the impact of the ruling on the adequacy decision.

If the EC concludes that the adequacy decision is no longer sustainable, there would suddenly be no legal basis for the tonnes of data crossing the ocean. Ironically, this theoretical scenario would not mean that, in practice, nothing could be shared any more or that plugs would be pulled at internet exchange points (at least, we have not seen such a measure coming and it seems fairly problematic). What you do need to do, as State Secretary Van Bruggen rightly notes in response to the parliamentary questions, is put an alternative legal basis in place (from that same Chapter V of the GDPR) to safeguard the lawfulness of those data transfers.

"If the Commission were to (partially) withdraw or suspend the decision, transfers could no longer be based on the DPF. Transfers would then need to take place on the basis of other GDPR instruments, such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs)[1] ,or, by way of exception, the derogations in Article 49 GDPR." (freely translated from Dutch original).

In conclusion

There is plenty of news at the moment, but not necessarily information we did not already know. The DPF has been on shaky ground for some time (several years, in fact), and it is advisable to factor this into your operations.

What does that look like in practice? Take precautionary measures. SCCs are the most commonly used option alongside adequacy decisions for justifying data transfers. Make sure you are prepared to conclude SCCs and, if you have not done so already, identify which third parties you would need to sign them with. Ensure you have the right information to specify the details of the transfer in the SCCs. Some organisations have already concluded SCCs as a Plan B. One caveat: if you sign SCCs, you also need to carry out a TIA, a Transfer Impact Assessment. This is an analysis of the laws, regulations and practices in the third country, and the extent to which they enable you to meet the requirements of both the GDPR and the SCCs. Input from the third party is essential here.

Before you start thinking your organisation is now (or could be) the one and only in serious trouble: as I mentioned at the outset, you are not alone. While digital sovereignty is an objective of the European Union, we are not there yet.

Have questions about this process? Do not hesitate to get in touch.

Contact us


[1] Standard Contractual Clauses (SCC), Binding Corporate Rules (BCR)

Back to overview