Skip to content

The simplest transfer impact assessment is no transfer

International transfers and Schrems II

Why EU-pinned CI removes the international transfer question rather than answering it, and where the EU-US Data Privacy Framework leaves you.

Frankfurt
Germany
Paris
France
Amsterdam
Netherlands
Stockholm
Sweden
Milan
Italy
Dublin
Ireland

In July 2020 the Court of Justice invalidated the Privacy Shield in the Schrems II ruling, and made clear that standard contractual clauses alone are not sufficient — a transfer impact assessment is required, considering whether the destination country's surveillance law undermines the safeguards.

The EU-US Data Privacy Framework, adopted in July 2023, restored a lawful route for transfers to certified US organisations. So transfers are possible again. The question for many European buyers is no longer strictly whether they may, but whether they want to depend on an adequacy decision that has now been struck down twice.

What EU pinning changes

If your build data never leaves the EU, there is no third-country transfer to assess. That removes an entire workstream rather than documenting it — no TIA for this processor, no supplementary measures analysis, no exposure to the next adequacy challenge.

US-operated CIrunnerhut EU-pinned
Third-country transferYesNone
Transfer impact assessmentRequiredNot applicable
Depends on adequacy decisionYesNo
Exposure if adequacy is struck downMaterialNone

Sources

  • CJEU judgment C-311/18 (Schrems II) — https://curia.europa.eu/juris/liste.jsf?num=C-311/18

Your next build could be twice as fast, at half the price

Start free. Migrating away is the same one line, and we publish that diff too.