Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations update EU-US data transfer controls…
Governance, Ownership & Risk

How should organisations update EU-US data transfer controls after the Schrems II ruling?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

Organisations should review every EU personal data transfer that relied on Privacy Shield or Standard Contractual Clauses and confirm the destination country can support an equivalent level of protection. Where that cannot be demonstrated, the transfer needs a different lawful mechanism or redesign. The key is case-by-case assessment, documented due diligence, and rapid remediation of affected transfers.

How Schrems II changes the transfer-control model

Schrems II did not remove the possibility of EU-US transfers, but it changed the operating assumption behind them. Transfer controls now need to be evidence-based rather than template-based: each transfer path must be evaluated for local law, access conditions, and the actual technical and organisational protections in place at the destination or with the recipient.

The practical consequence is that controls cannot stop at contract signatures. Organisations need a transfer inventory, a documented assessment of the legal and technical transfer mechanism, and a clear decision on whether the destination can maintain protection that is effectively equivalent in context.

For organisations that depend on third-party processing chains, this often means reviewing downstream access paths as well as the direct recipient, because transfer risk is shaped by who can actually reach the data and under what authority.

What organisations need to update in practice

The first step is to classify transfers by business purpose, data category, recipient, and mechanism. That includes transfers that relied on Privacy Shield historically and transfers that still use Standard Contractual Clauses, because both need a fresh legal and technical review after Schrems II. Where a transfer cannot be supported by the destination environment and safeguards, the organisation needs a different lawful basis, a redesign that avoids the transfer, or stronger supplementary measures.

Those supplementary measures may include encryption with keys controlled in the EEA, strict minimisation, pseudonymisation where it actually reduces exposure, access restriction, and tighter vendor governance. The important point is that the control must reduce the recipient’s ability to disclose or misuse the data in the real operating environment, not just in policy language.

This is also where contract language needs to be paired with operational evidence. A clause is useful, but the organisation still needs proof that the recipient can meet the expected protection level, can challenge unlawful access where appropriate, and can support timely remediation if the transfer model changes.

For security teams, the right analogue is disciplined control over long-lived access material: unrevoked credentials and stale access paths create the same kind of lingering exposure that poorly governed transfers do. In both cases, the issue is not only initial approval, but ongoing validity.

Risk and Threat Considerations

Schrems II makes transfer oversight a control problem as much as a legal one. The main risk is that an approved transfer mechanism looks compliant on paper while the recipient, infrastructure, or legal environment still permits access that weakens the protection expected for EU personal data.

Failure mechanism: Organisations rely on static contractual terms, incomplete due diligence, or outdated transfer records, then fail to reassess whether supplementary measures actually survive the destination country’s access conditions and operational realities.

Impact: EU personal data can be exposed through lawful or unlawful access, transfer chains can remain in place without a valid protection basis, and remediation becomes slower because no one owns the full inventory of affected flows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyCross-border transfers require ongoing risk decisions and documented acceptance.
PR.DS-02 — Data-in-Transit ProtectionSupplementary measures often depend on protecting personal data during transfer.
GV.SC-04 — Supply Chain Risk ManagementVendor and processor chains materially affect where EU personal data can flow.
Recommendation — Define transfer risk ownership and reassess each flow when legal or technical conditions change. Apply strong transit protections and limit what data is exposed in each transfer path. Map third-party transfer chains and require evidence for downstream control effectiveness.
CIS Controls v83.1 — Data Protection Process and ProceduresTransfer controls depend on governance for sensitive data handling and movement.
6.3 — Data RecoveryTransfer redesign often requires recovery or replacement of affected data flows.
Recommendation — Classify transfer paths and enforce handling rules for regulated personal data. Maintain tested recovery paths so transfer changes do not disrupt business operations.
NIST Zero Trust (SP 800-207)SC-1 — Policy EnforcementCross-border transfer decisions need explicit policy enforcement at each access path.
AL-1 — Continuous Diagnostics and MitigationTransfer assurances must be continuously validated, not assumed after contract signing.
Recommendation — Enforce transfer policies at the point where data is shared or accessed. Continuously verify that transfer conditions still match the approved control model.
NIST SP 800-63IAL1 — Identity ProofingRecipient assurance depends on knowing who can access transferred data and why.
AAL2 — Authenticator Assurance Level 2Destination protections depend on strong authentication for administrative access.
Recommendation — Use strong identity assurance for personnel who can reach transferred personal data. Require phishing-resistant or otherwise strong authentication for privileged access to transfer systems.

Practitioner Guidance

What to prioritise: Start with the highest-volume and highest-sensitivity transfers, especially those involving vendor chains, support access, or duplicated data stores. Those are the flows where a single weak assumption can affect the most records.

What to verify: Confirm that each transfer has a current owner, a current legal mechanism, an assessment of supplementary measures, and a documented decision for what happens if the recipient or jurisdiction can no longer meet the required protection level.

Decision rule: If you cannot show that the destination can sustain equivalent protection in practice, treat the transfer as needing redesign rather than as a paperwork issue. The right fix is usually to reduce the transfer, not to argue the old one more aggressively.

Practitioner takeaway: Schrems II turns cross-border transfer governance into continuous control validation, so the mature response is not a one-time legal review but a living inventory with evidence, ownership, and fast remediation for any flow that loses its protection basis.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org