Why Words Alone Cannot Comply With Schrems II*

Although “words are the lawyer’s tools of the trade”2, trying to address Schrems II requirements using words alone will always fail, regardless of whether the words come in the form of revised contracts, new treaties, policies, or digital terms of use.
Organisations focused on updating Standard Contractual Clauses (SCCs) miss the point that words alone cannot make data transfers lawful under Schrems II. It is critical to understand that new technical controls are required in addition to updating SCCs.
Attempting to avoid massive Schrems II-related disruptions to international data flows3 using words alone will be unsuccessful. This is because:
  • The fundamental rights of European Union data subjects are not available to barter for commercial or surveillance benefits;4 and
  • GDPR-compliant technical safeguards must supplement SCCs to reduce the risk of violating data subjects' fundamental rights for international data transfers to be lawful.5
There is no political solution to Schrems II that removes the obligation to implement new technology controls. The EU Parliament’s Committee on Civil Liberties, Justice and Home Affairs (LIBE) states that even the promise of a US federal privacy law is insufficient to remove that obligation because of ongoing surveillance concerns. In addition, Schrems II impacts the evaluation of adequacy decisions for countries around the globe.6

Also, despite reports to the contrary7, there is no certainty of a post-Brexit adequacy decision for the United Kingdom. This uncertainty is highlighted by:
  • The recommendation by the Information Commissioner's Office (ICO) for UK "businesses working with EU and EEA organisations who transfer personal data to them, to put in place alternative transfer mechanisms, to safeguard against any interruption to the free flow of EU to UK personal data"8 (emphasis added); and
  • The European Data Protection Supervisor (EDPS) Opinion 3/2021 on the Conclusion of the EU and UK Trade Agreement and the EU and UK Exchange of Classified Information Agreement, raising concerns about whether UK data transfers comply with Schrems II.9
Relying on “Words Alone” by updating contracts and hoping for treaties produces unsustainable operations because no contract or treaty will remove the need for new technology controls to protect data when in use.
Why New Technology Controls Are Required to Comply with Schrems II
Anonos technology solves international cross-border legal challenges, enabling the highest data protection levels, accuracy, and utility on a global scale.10
Schrems II fundamentally changes how data-driven global business must be conducted to be lawful. Hundreds of companies attended Anonos’ Schrems II webinars, including regulators, industry experts, and leading nongovernmental organisations (NGOs). Numerous stakeholders asked Anonos to answer the following two questions:
  • Can Anonos help me to legally process data using US-based cloud (and other) technology companies and still comply with Schrems II?
  • Can Anonos technology help my organisation reduce risk exposure and ensure predictable business operations now that the UK is no longer part of the EU and is subject to the UK GDPR?11
The answer to both questions is yes. Anonos’ patented12 Variant Twin technology enables Lawful Borderless Data for international cross-border transfers and processing using SCCs in compliance with Schrems II.

It’s important to remember that the remedy for violating Schrems II requirements is injunctive termination of processing, rather than the assessment of penalties.13 This highlights the risk of immediate disruption to business operations that comes from non-compliance. The imposition of injunctions shifts the burden of proof onto organisations to regain the right to process data and get the injunction removed. This is a significant change from the fines-based penalties resulting from GDPR violations levied in the past.

In addition, waiting to establish a defensible position for using US-based and other non-EEA cloud, SaaS, and outsourcing solutions (including UK providers) creates the risk of personal exposure for Board members and officers.14 Auditors are obligated to report non-compliance to authorities, and are also becoming increasingly aware of Schrems II data protection audit requirements.15 Contracts, policies, and treaties do not provide the technical controls required for Schrems II compliance, and this issue is time-critical. Organisations should implement European Data Protection Board (EDPB) recommended technical controls to comply with Schrems II, such as GDPR-compliant Pseudonymisation.
