The simplest transfer impact assessment is no transfer
International transfers and Schrems II
Why EU-pinned CI removes the international transfer question rather than answering it, and where the EU-US Data Privacy Framework leaves you.
In July 2020 the Court of Justice invalidated the Privacy Shield in the Schrems II ruling, and made clear that standard contractual clauses alone are not sufficient — a transfer impact assessment is required, considering whether the destination country's surveillance law undermines the safeguards.
The EU-US Data Privacy Framework, adopted in July 2023, restored a lawful route for transfers to certified US organisations. So transfers are possible again. The question for many European buyers is no longer strictly whether they may, but whether they want to depend on an adequacy decision that has now been struck down twice.
What EU pinning changes
If your build data never leaves the EU, there is no third-country transfer to assess. That removes an entire workstream rather than documenting it — no TIA for this processor, no supplementary measures analysis, no exposure to the next adequacy challenge.
| US-operated CI | runnerhut EU-pinned | |
|---|---|---|
| Third-country transfer | Yes | None |
| Transfer impact assessment | Required | Not applicable |
| Depends on adequacy decision | Yes | No |
| Exposure if adequacy is struck down | Material | None |
Sources
- CJEU judgment C-311/18 (Schrems II) — https://curia.europa.eu/juris/liste.jsf?num=C-311/18
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.