Skip to main content
Portugal Halts Census Transfers: When FBI Misconduct Met GDPRScope & Exemptions
5 min readFor Legal & Compliance Teams

Portugal Halts Census Transfers: When FBI Misconduct Met GDPR

What Happened

In April 2021, Portugal's supervisory authority suspended data transfers to the United States after complaints revealed census data were being sent across the Atlantic. That same week, the U.S. Foreign Intelligence Surveillance Court renewed a surveillance program despite finding that FBI employees had illegally accessed email data.

These events highlight the ongoing tension in transatlantic data flows since the Schrems II decision invalidated Privacy Shield. U.S. surveillance law doesn't meet the protections Article 45 requires for adequacy, and supplementary measures under Article 46 can't bridge that gap when government access is the issue.

Timeline

July 2020: The Court of Justice of the European Union invalidates Privacy Shield in Schrems II, citing U.S. surveillance practices incompatible with Articles 7 and 8 of the Charter of Fundamental Rights.

April 2021: Portugal's supervisory authority halts census data transfers following complaints. The authority determined that Standard Contractual Clauses alone couldn't protect the data from U.S. government access.

Same week, April 2021: A U.S. Foreign Intelligence Surveillance Court decision reveals the court renewed surveillance authority even after finding FBI employees illegally accessed email data.

Ongoing: U.S. and EU negotiators attempt to craft a replacement framework, facing the same structural obstacles that doomed Safe Harbor and Privacy Shield.

Which Controls Failed or Were Missing

The Portugal case exposes three control failures you might be replicating in your own transfer mechanisms:

Transfer impact assessment inadequacy: The controller relied on Standard Contractual Clauses without conducting the case-by-case assessment Article 46 requires. Your SCCs aren't a rubber stamp. You must evaluate whether the recipient country's laws allow authorities to access the data in ways incompatible with EU protections, and whether supplementary measures can address that risk.

No effective supplementary measures: appropriate technical and organisational measures like encryption can work when you're protecting data from commercial threats. They fail when the legal framework itself compels disclosure. If U.S. law requires your processor to hand over decryption keys or unencrypted data, your supplementary measures aren't supplementing anything.

Overlooked government access risk: Many privacy teams assess processor security practices but skip the jurisdiction analysis. You're checking whether your processor can resist a breach, not whether they can resist a lawful order. Those are different threat models requiring different controls.

The FBI misconduct documented by the Foreign Intelligence Surveillance Court makes this worse. When even illegal access goes unpunished and the program gets renewed anyway, your contractual provisions about lawful requests become meaningless.

What the Relevant Standard Requires

Article 44 establishes that transfers can only occur if the conditions in Chapter V are met and all other GDPR provisions are respected. That means your lawful basis, purpose limitation, and data minimization obligations don't disappear just because you signed SCCs.

Article 45 sets the bar for adequacy decisions: the third country must ensure a level of protection "essentially equivalent" to the GDPR. The Schrems II court found U.S. surveillance law fails this test because it doesn't provide data subjects with actionable rights against government access.

Article 46 allows transfers with appropriate safeguards, but only if those safeguards are "effective in practice." The European Data Protection Board's Recommendations 01/2020 spell this out: you must identify the laws in the recipient country that enable government access, assess whether they respect principles of necessity and proportionality, and determine whether supplementary measures can bridge the gap.

Recital 101 clarifies that onward transfers from your processor to sub-processors in third countries need the same level of protection. Your processor's U.S. parent company accessing the data for "support purposes" is a transfer you need to assess.

Lessons and Action Items for Your Team

Map your actual data flows, not your documented ones: Start with where personal data physically resides and which legal entities can access it. Remote access by a U.S. parent counts as a transfer even if the data stays on EU servers. Support tickets containing personal data that route through a U.S. system count. Backup systems accessible from the U.S. count.

Run jurisdiction-specific transfer impact assessments: The EDPB's recommendations require you to assess each transfer individually. Document which U.S. laws apply to your processor (FISA Section 702, Executive Order 12333, CLOUD Act), whether your data falls within their scope, and what legal remedies data subjects would have. If your processor is an "electronic communication service provider" under U.S. law, Section 702 likely applies.

Don't rely on contractual commitments your processor can't honor: Your SCC clause requiring the processor to challenge government requests is worthless if U.S. law prohibits disclosure of the request itself. Your audit rights don't help if National Security Letters come with gag orders. Document these gaps in your assessment.

Consider whether you need the transfer at all: Article 5(1)(c) requires data minimization. If you're sending census data to a U.S. processor for analysis, can you anonymize it first? Can you run the processing in the EU? The Portuguese authority's action suggests they found the transfer wasn't necessary for the stated purpose.

Prepare for enforcement: Portugal won't be the last supervisory authority to halt U.S. transfers. Identify which of your processing activities depend on U.S. transfers and what your fallback is. If your entire SaaS infrastructure runs on a U.S. provider, you need a migration plan, not a legal argument.

Document your assessment even if you proceed: Article 5(2) requires you to demonstrate compliance. When a supervisory authority questions your transfers, "we signed SCCs" isn't documentation. You need the transfer impact assessment showing what you evaluated, what risks you identified, and why you concluded your safeguards were effective. If you can't write that assessment honestly, you can't make the transfer lawfully.

The Portugal case isn't just about census data. It's about supervisory authorities finally enforcing what Schrems II required: that you can't contract around incompatible surveillance law. Your SCCs bought you time to fix your architecture, not permission to keep transferring.

You Might Also Like