Skip to main content
Should You Bet on SCCs or Wait for the Next Shoe to Drop?Lawful Basis for Processing
4 min readFor Legal & Compliance Teams

Should You Bet on SCCs or Wait for the Next Shoe to Drop?

The question at hand

You've built your international data transfer strategy on standard contractual clauses (SCCs). You've mapped your processors, documented your transfers, and filed the paperwork your supervisory authority requires. But the European Court of Justice heard the Schrems II case earlier this month, and the outcome could fundamentally reshape whether SCCs remain a viable transfer mechanism. Meanwhile, the ePrivacy Regulation, promised as GDPR's companion framework, has been delayed for years with no passage in sight.

This puts you in a tough position. Do you invest heavily in reinforcing your existing SCC framework, knowing the Court might invalidate it? Or do you start building alternative transfer mechanisms now, even though you don't know what the regulatory landscape will look like in six months?

The answer isn't obvious, and the stakes are high. Your transfer mechanisms underpin everything from payroll processing to customer support to analytics pipelines.

The case for doubling down on SCCs

The practical argument is simple: SCCs are what you have. They're the only scalable mechanism available right now for most organizations that don't qualify for adequacy decisions or binding corporate rules. Walking away from them before the Court rules is premature.

Reinforcing your SCC framework means conducting transfer impact assessments for each third country where you send personal data. You document the supplementary measures you've implemented, like encryption in transit and at rest, pseudonymization where feasible, and contractual restrictions on government access. You maintain records that demonstrate you've assessed the legal regime in each destination country and concluded your transfers meet Article 46 requirements.

This effort isn't wasted even if Schrems II goes badly. The Court might narrow the circumstances where SCCs work rather than invalidating them entirely. Your impact assessments and supplementary measures become the foundation for whatever comes next. You're building institutional knowledge about your data flows that you'll need regardless of the legal framework.

There's also a compliance reality: your supervisory authority expects you to use available mechanisms until they're formally invalidated. Abandoning SCCs preemptively raises questions about why you're not using the tools Article 46 provides.

The case for building alternatives now

The counterargument is equally compelling: SCCs have been on shaky ground since the Court invalidated Privacy Shield's predecessor, Safe Harbor. Schrems II isn't asking whether SCCs need minor adjustments. It's asking whether they can function at all when the receiving country's surveillance regime conflicts with EU fundamental rights.

If you wait for the Court's ruling to start building alternatives, you'll be scrambling. Implementing binding corporate rules takes 18-24 months under the best circumstances. Relocating data processing to the EEA requires processor negotiations, system migrations, and often significant cost increases. You can't spin these up in a quarter.

The delays in the ePrivacy Regulation should tell you something about EU legislative timelines. When the political will exists, regulations move forward. When it doesn't, they stall indefinitely. If the Court invalidates SCCs, don't expect a swift legislative fix. You'll be operating in uncertainty for years, not months.

There's also a risk management perspective. Your board doesn't want to hear that your entire customer data infrastructure depends on a legal mechanism that might disappear overnight. Building redundancy now, even if it's expensive, is defensible. Explaining why you didn't prepare isn't.

Where practitioners actually land

Most organizations aren't choosing one approach or the other. They're doing both, but with different levels of investment based on their risk tolerance and resources.

High-risk data flows get immediate attention. If you're transferring special categories of data, data about children, or data that could enable surveillance or discrimination, you're already looking at alternatives. You're having conversations with vendors about EEA hosting. You're evaluating which transfers you actually need versus which ones are convenient.

Lower-risk flows get documented and monitored. You're completing transfer impact assessments because they're required now and they'll be required under any future framework. You're implementing encryption and access controls that make sense regardless of where the law lands. But you're not rearchitecting your entire tech stack until you know what you're architecting toward.

The ePrivacy Regulation's ongoing delays have taught practitioners to distinguish between "the law as written" and "the law as enforced." Supervisory authorities have limited resources. They focus on high-risk processing and egregious violations. If you're making good-faith efforts to comply with existing frameworks, you're not at the top of their enforcement list.

Our take

Don't wait for clarity that isn't coming. The ePrivacy Regulation has been delayed for years, and there's no indication that timeline will accelerate. The Schrems II ruling will answer specific questions about SCCs and Privacy Shield, but it won't resolve the underlying tension between EU data protection law and third-country surveillance regimes.

Your job isn't to predict the Court's ruling or the Council's legislative priorities. It's to maintain compliant data transfers under current law while building resilience for multiple possible futures.

That means completing transfer impact assessments now, not because they'll save your SCCs if the Court rules against them, but because they force you to understand your data flows and identify your highest-risk transfers. It means implementing supplementary measures that make sense from a security perspective regardless of legal requirements. And it means having honest conversations with your leadership about the cost and timeline of relocating critical processing to the EEA, even if you don't pull that trigger immediately.

The organizations that weather regulatory uncertainty best aren't the ones who guess right about which way the law will go. They're the ones who build systems flexible enough to adapt when it does.

You Might Also Like