Skip to main content
Should You Prepare for a Treaty or Bet on SCCs?Scope & Exemptions
5 min readFor Privacy Officers

Should You Prepare for a Treaty or Bet on SCCs?

You're facing a choice that shapes your international data transfer strategy. Since the Court of Justice of the European Union invalidated the EU-US Privacy Shield in Schrems II, you've likely defaulted to Standard Contractual Clauses (SCCs) with transfer impact assessments. But with the U.S. Department of Commerce and European Commission working on a new framework, and voices like Baker MacKenzie's Brian Hengesbaugh calling for a multilateral privacy treaty among democratic nations, you need to decide: do you invest in treaty-ready infrastructure, double down on SCC compliance, or maintain flexibility for both paths?

This isn't academic speculation. Your choice determines whether you redesign processor contracts, how you allocate compliance resources, and what you tell your board about trans-Atlantic data flow stability.

The Decision You're Facing

Your organization transfers personal data to the United States (or other third countries) and must decide how to structure your compliance posture over the next 18-36 months. Three paths exist:

Path A: Assume a new adequacy decision (potentially treaty-based) will restore simplified transfers.
Path B: Treat SCCs plus transfer impact assessments as the permanent baseline.
Path C: Build a hybrid approach that works under either scenario.

Each path requires different investments in legal review, technical controls, and processor management.

Key Factors That Affect Your Choice

Your data transfer volume and sensitivity. If you process high volumes of special category data or data subject to national security interest (financial records, health data, communications metadata), supervisory authorities will scrutinize your transfer mechanisms regardless of the political framework. A treaty won't eliminate your Article 46 obligations if your transfer impact assessment reveals problematic access laws.

Your processor ecosystem's flexibility. Can your processors implement supplementary measures like encryption with EU-held keys? If your U.S. cloud provider can't offer technical controls that address government access concerns, even a new adequacy decision might not cover your specific transfers. The Biden administration's appointment of Christopher Hoff in January 2021 signals serious engagement, but national security laws remain unchanged.

Your supervisory authority's enforcement posture. Some authorities have issued guidance requiring near-impossible standards for U.S. transfers (effectively demanding data localization). Others take a more pragmatic view. Check whether your lead authority has published transfer-specific guidance post-Schrems II.

Your organization's risk appetite for legal uncertainty. A treaty-based adequacy decision would face immediate legal challenges. If you build your entire compliance program around it, you're accepting the risk of another invalidation cycle.

Path A: Treaty-Ready Infrastructure

Choose this path if:

  • Your transfers are low-to-moderate risk (standard commercial data, limited special categories).
  • You have U.S. processors who can quickly certify under a new framework.
  • Your board prioritizes operational efficiency over legal defensibility.
  • You can pivot quickly if the framework fails.

What this means operationally: Maintain SCC compliance as a baseline but don't invest heavily in supplementary measures. Monitor the U.S. Department of Commerce and European Commission negotiations closely. Prepare processor contracts with clauses that automatically incorporate new certification requirements when an adequacy decision publishes.

The risk: A multilateral treaty faces the same fundamental challenge that killed Privacy Shield. Unless participating nations genuinely reform surveillance laws to include proportionality and individual redress mechanisms that satisfy EU standards, the Court will invalidate it. You're betting that shared democratic values translate into legally adequate protections. Hengesbaugh's proposal assumes alignment is possible; the Court's jurisprudence suggests alignment requires concrete legal reform, not diplomatic agreement.

Specific requirements you must still meet: Even with adequacy, Article 5(1)(a) requires you to identify a lawful basis for the original processing. Article 13/14 transparency obligations apply. You can't use adequacy as a substitute for fundamental compliance.

Path B: SCC-Plus as Permanent Baseline

Choose this path if:

  • You transfer sensitive data or large volumes to U.S. processors.
  • Your supervisory authority has published strict transfer guidance.
  • You operate in a sector with heightened regulatory scrutiny (health, finance, telecommunications).
  • You have technical capability to implement strong supplementary measures.

What this means operationally: Conduct thorough transfer impact assessments for each U.S. transfer. Implement supplementary measures: end-to-end encryption, pseudonymization, split processing arrangements, or EU-based processing where feasible. Document why each measure effectively addresses risks identified in your assessment. Negotiate contractual terms that give you audit rights and termination options if government access occurs.

The practical challenge: Many U.S. processors can't or won't implement supplementary measures that truly eliminate access risks under FISA 702 or Executive Order 12333. You may need to reduce your reliance on U.S. services or accept residual risk with documented business justification.

Specific requirements driving this path: Article 46 requires "appropriate safeguards." Post-Schrems II, supervisory authorities interpret this to mean SCCs alone are insufficient when the third country's laws enable access incompatible with EU standards. Your transfer impact assessment (required by EDPB Recommendations 01/2020) must evaluate both the legal framework and practical supplementary measures.

Path C: Adaptive Compliance Framework

Choose this path if:

  • You have diverse transfer types (some high-risk, some routine).
  • You need board-level defensibility but can't afford full data localization.
  • You're willing to invest in flexible infrastructure.

What this means operationally: Categorize your transfers by risk profile. For high-sensitivity data, implement Path B controls immediately. For routine commercial data, maintain SCC compliance with lighter supplementary measures, positioned to adopt treaty certification quickly if available.

Build modular processor contracts that support multiple compliance mechanisms. Establish a cross-functional working group that monitors both treaty negotiations and supervisory authority enforcement trends, with authority to shift resources between paths.

The investment required: This path demands the most sophisticated compliance infrastructure. You need data mapping granular enough to categorize transfers, technical architecture that supports varied controls, and legal resources to maintain multiple compliance frameworks simultaneously.

Summary Matrix

Factor Path A: Treaty-Ready Path B: SCC-Plus Permanent Path C: Adaptive
Best for Low-risk commercial data Sensitive/high-volume transfers Mixed transfer portfolio
Primary mechanism SCCs pending adequacy SCCs + supplementary measures Risk-tiered approach
Technical investment Minimal new controls Significant (encryption, localization) Moderate (flexible architecture)
Legal risk High (invalidation exposure) Low (defensible now) Moderate (managed exposure)
Operational complexity Low High Very high
Supervisory authority scrutiny Vulnerable to challenge Defensible in enforcement Defensible with documentation

Your choice isn't permanent. The landscape will shift as negotiations progress and enforcement patterns emerge. But you need a documented decision now, with clear triggers for reassessment. Whether a multilateral treaty among democratic nations can deliver legally adequate protections remains uncertain. What's certain: your compliance framework must work under current law, not hoped-for diplomacy.

European Data Protection Board Recommendations 01/2020

You Might Also Like