Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do organisations get wrong about keeping cross-border…
Governance, Ownership & Risk

What do organisations get wrong about keeping cross-border transfers lawful after Schrems II?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

The most common mistake is assuming the signature of standard contractual clauses ends the analysis. In practice, teams also need to check whether the transfer mechanism still works in the destination country, whether supplementary measures are effective, and whether processor integrations create hidden onward transfers. Without those checks, compliance becomes paper based rather than defensible.

What teams miss after the SCC signature is in place

Schrems II did not turn cross-border transfer compliance into a one-time legal paperwork exercise. The real issue is whether the transfer arrangement still works in the destination environment, given local law, the service design, and the actual paths data can take. Teams often stop at contractual formality and never test operational reality, which is where lawful transfers succeed or fail.

That means the analysis has to move beyond the clause set itself. If the destination country creates access conditions that undermine the promised protections, or if the service architecture creates onward disclosure the team did not map, the transfer may be exposed even though the contract looks complete on paper.

Why supplementary measures have to be judged on effectiveness, not presence

Supplementary measures only matter if they change the practical exposure created by the transfer. Encryption, key handling, pseudonymisation, split processing, and access restrictions can all help, but only when they are deployed in a way that meaningfully limits intelligible access or reduces the transfer risk that the original legal mechanism leaves open.

In practice, the mistake is treating the existence of a measure as proof of adequacy. A measure that is easy to bypass, undone by the processor, or invalidated by the destination legal environment does not close the Schrems II gap. The relevant question is whether the measure remains effective throughout the full lifecycle of the transfer, including support access, troubleshooting, subprocessing, and recovery.

Teams also need to distinguish between protections that apply at rest and protections that survive the operational flow. A control that looks strong in a brochure can still fail if administrators, support personnel, or integrated services can reach the data in plain form when the business process runs.

Why hidden onward transfers and processor integrations change the answer

Many organisations assess the named transfer and ignore everything the processor connects to. That is a blind spot, because onward transfers can arise through embedded support tools, subprocessors, regional hosting, analytics pipelines, remote administration, and incident-response access paths. The legal question is not only where the first transfer lands, but where the data can be reached next.

The practical task is to map the full data path, including who can access it, under what authority, and through which services. If the processor can route data into another environment, or if a vendor chain creates a second transfer that was never reviewed, the original assessment is incomplete. A transfer can be lawful in form yet fragile in the way the service is actually run.

That is why processor due diligence cannot stop at the signed agreement. Organisations need evidence of subprocessor controls, access boundaries, and the technical measures that prevent casual repurposing of data across regions or service layers.

Risk and Threat Considerations

The main risk is compliance drift, where a transfer stays contractually documented but becomes unsupported by the operational and legal conditions that made it acceptable. The other risk is hidden exposure through onward transfers, support access, or weak supplementary measures that do not withstand the destination environment.

Failure mechanism: Teams rely on SCCs or similar clauses as if they were self-executing, then fail to validate destination-country access conditions, processor architecture, and actual control effectiveness. That leaves a gap between legal form and technical reality.

Impact: The organisation can end up with a transfer that is difficult to defend, especially if data access is broader than expected or if subcontracted processing creates additional cross-border movement that was never assessed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
GDPRArt. 44-49 — Transfers of personal data to third countries or international organisationsCross-border transfer legality is governed by GDPR transfer rules and safeguards.
Art. 32 — Security of processingSupplementary measures must materially reduce access and disclosure risk in the transfer chain.
Art. 28 — ProcessorProcessor and subprocessor arrangements determine hidden onward transfers and access paths.
Recommendation — Assess the destination transfer mechanism, supplementary measures, and onward recipients before relying on SCCs. Implement technical and organisational controls that preserve confidentiality and integrity during transfer and support access. Review processor contracts and subprocessor chains to ensure transfer safeguards remain effective end to end.

Practitioner Guidance

What to verify: Confirm the destination assessment is tied to the exact service path, not just the vendor name. Verify who can access the data, where support access originates, whether subprocessors are approved, and whether the supplementary measures still work when the processor operates the service.

Decision rule: If the transfer can only be justified by the contract text, treat it as incomplete until you have mapped onward transfers and tested whether the protective measures actually survive operational use.

What good looks like: The organisation can explain the transfer mechanism, the destination-country risk, the supplementary measures, and every material onward recipient in a way that would still make sense if a regulator asked how the service runs in practice.

Practitioner takeaway: Schrems II compliance is durable only when legal, technical, and vendor-chain review stay aligned; if any one of those three is assumed rather than checked, the transfer is probably paper compliant and operationally weak.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org