Data to the United States: where things stand after three attempts
Twice the Court of Justice struck down an arrangement; since 2023 the third one applies. What that means for embedded services, which assessment is still required – and why a tick box does not settle the question.
The GDPR permits transfers outside the EU only under conditions. The simplest route is an adequacy decision: the Commission finds that a country offers a comparable level of protection, and transfers there are treated like transfers within the EU. For the United States that route has an eventful history.
Three arrangements in ten years
- 2000Safe Harbor takes effect – a self-certification by US companies.
- 2015The Court of Justice strikes it down (Schrems I). Reason: disproportionate government access.
- 2016The successor, Privacy Shield, takes effect.
- 2020That one falls too (Schrems II) – for the same reason. Standard contractual clauses survive but require an additional assessment.
- 2023The Data Privacy Framework takes effect, resting on a US presidential order and a new redress court.
What applies concretely today
A transfer to a US company is permitted where that company is certified under the Data Privacy Framework. The certification is publicly visible and has to be renewed annually – it is therefore not a permanent state but a status that can lapse.
The scope matters too: a certification can be limited to particular kinds of data. A company certified only for human-resources data does not thereby cover website data.
Where no certification exists
The remaining routes, in order of practicality
- Standard contractual clauses plus assessmentThe usual route. Since Schrems II the clauses alone are not enough – a documented assessment of the legal situation in the destination country is added.
- Supplementary measuresEncryption where the key stays in the EU, or processing exclusively in pseudonymised form.
- Consent for the individual caseIntended only for occasional transfers and with a warning about the risks. Unsuitable for the continuous operation of a website.
- Changing providerThe route that dissolves the question rather than administering it. For most kinds of service there are providers processing within the EU.
For practice this yields a simple stocktaking recommendation: every embedded service is examined for where it processes and whether a valid certification exists. The result belongs in the privacy notice – and the certifications belong in a diary, because they lapse annually.
Two struck-down arrangements in fifteen years is a pattern, not an exception. Anyone wanting the question gone for good moves the processing – anyone administering it plans for the next review.