Introduction
The Schrems II ruling, issued by the Court of Justice of the European Union in July 2020, fundamentally reshaped how organizations handle international data transfers under the GDPR. For website owners, this decision means that relying solely on standard contractual clauses (SCCs) or the Privacy Shield is no longer sufficient. You must now conduct a transfer impact assessment (TIA) and implement supplementary measures to ensure an equivalent level of protection for personal data transferred to third countries. This guide provides specific, actionable steps to align your website’s data processing with the Schrems II requirements, focusing on consent defaults, pre-consent network requests, tag manager triggers, policy disclosures, reject-flow testing, and post-change scans.
Understanding the Schrems II Ruling and Its Core Requirements
The Schrems II case arose from a complaint by Austrian privacy activist Max Schrems against Facebook Ireland, challenging the legality of transferring personal data to the United States. The CJEU invalidated the EU-US Privacy Shield and clarified that SCCs alone cannot guarantee adequate protection if the recipient country’s laws allow public authorities to access data without equivalent safeguards. For GDPR compliance, this means you must assess the legal environment of each third country where data is transferred and, if necessary, implement supplementary measures—such as encryption, pseudonymization, or contractual clauses that limit access by foreign governments.
Assessing Your Data Transfers: A Transfer Impact Assessment (TIA)
A TIA is not optional; it is a direct consequence of Schrems II. Start by mapping all data flows from your website to third countries, including cloud services, analytics tools, marketing platforms, and content delivery networks. For each transfer, document the type of data, the recipient, the legal basis (e.g., SCCs, binding corporate rules, or derogations), and the third country’s legal framework. Use resources like the European Data Protection Board’s (EDPB) recommendations to evaluate whether the recipient country provides essentially equivalent protection. If gaps exist, you must implement supplementary measures—for example, end-to-end encryption that prevents the recipient from accessing plaintext data, or pseudonymization that makes re-identification impossible without keys held in the EU.
Consent Defaults: Setting the Right Baseline
Under Schrems II, consent for data transfers must be specific, informed, and unambiguous. Your website’s consent defaults should be set to “no consent” for any processing that involves international transfers unless the user actively opts in. Avoid pre-ticked boxes or implied consent. For example, if you use Google Analytics with US-based servers, the default should be that analytics cookies are blocked until the user clicks “Accept.” This aligns with the GDPR’s requirement that consent must be freely given and revocable. Test your consent banner to ensure that users who reject all cookies do not inadvertently trigger data transfers to third countries.
Tag Manager Triggers: Configuring for Compliance
Tag managers are powerful tools for managing third-party scripts, but they can also be a source of non-compliance if not configured correctly. After Schrems II, you must ensure that tags that trigger data transfers to third countries are only activated after the user has given explicit consent. Create separate tags for each service that involves international transfers, and set their triggers to fire only when the corresponding consent category is granted. For instance, if you use a marketing automation tool hosted in the US, the tag should fire only after the user has accepted “Marketing” cookies. Additionally, implement a “reject all” flow that stops all non-essential tags from firing, and test this flow to confirm that no data is sent inadvertently.
Policy Disclosures: Updating Your Privacy Policy
Your privacy policy must clearly disclose all international data transfers, the legal basis for each transfer, and the safeguards in place. Under Schrems II, you should also describe the supplementary measures you have implemented, such as encryption or contractual clauses. Avoid vague statements like “we may transfer data to third countries”; instead, list the specific recipients, their locations, and the mechanisms used. For example: “We transfer personal data to Google LLC in the United States under standard contractual clauses, supplemented by technical measures including encryption at rest and in transit.” This transparency helps users make informed decisions and demonstrates accountability to supervisory authorities.
Reject-Flow Testing: Ensuring User Choices Are Honored
Testing the reject flow is critical to verify that your website respects user choices. After a user rejects all non-essential cookies, check that no third-party scripts load, no network requests are made to third-country servers, and no data is collected for analytics or marketing. Use browser developer tools or network monitoring tools to inspect outgoing requests. For example, if you use Google Analytics, confirm that the analytics script does not load after rejection. Also, test that the consent banner reappears if the user clears cookies or after a reasonable period (e.g., six months). Document these tests as part of your compliance records.
Post-Change Scans: Monitoring for Compliance Drift
After implementing changes, conduct regular scans to ensure that your website remains compliant. Use automated tools to check for new third-party scripts, changes in data flows, or updates to third-party services that might affect transfer safeguards. For example, if you add a new analytics tool that stores data in the US, you must update your TIA and consent settings. Schedule monthly scans and after any website update. This proactive approach helps you catch issues before they lead to a data breach or regulatory action.
Common Mistakes and Trade-Offs
One common mistake is assuming that SCCs alone are sufficient. Schrems II explicitly states that SCCs must be supplemented with case-by-case assessments and additional measures. Another mistake is failing to update consent defaults after the ruling; many websites still use “accept all” as the default, which can lead to unlawful transfers. Trade-offs include balancing user experience with compliance: blocking all third-party scripts until consent may slow down page load times or break functionality. However, you can mitigate this by using local hosting for essential scripts (e.g., fonts) or implementing a lightweight CMP. Also, be aware that some third-party services may not offer contractual terms that meet Schrems II requirements, forcing you to switch providers.
Implementation Checklist for Website Owners
- **Map all data transfers** to third countries, including cloud services, analytics, and marketing tools.
- **Conduct a transfer impact assessment** for each transfer, documenting the legal basis and supplementary measures.
- **Set consent defaults to “no consent”** for all non-essential processing involving international transfers.
- **Block pre-consent network requests** by using a CMP that prevents third-party scripts from loading before user choice.
- **Configure tag manager triggers** to fire only after explicit consent for the relevant category.
- **Update your privacy policy** to list specific recipients, locations, and safeguards for each transfer.
- **Test the reject flow** to confirm that no data is sent to third countries after rejection.
- **Run post-change scans** monthly or after any website update to detect new data flows.
Frequently Asked Questions
**Q: Does Schrems II apply to all websites?** A: Yes, if your website transfers personal data to a third country (outside the EU/EEA) and you are subject to the GDPR, you must comply with Schrems II requirements. This includes using services like Google Analytics, Facebook Pixel, or cloud hosting in the US.
**Q: Can I still use standard contractual clauses (SCCs) after Schrems II?** A: Yes, but you must supplement them with a transfer impact assessment and, if necessary, additional measures such as encryption or pseudonymization. SCCs alone are not sufficient if the recipient country’s laws allow disproportionate access.
**Q: What are supplementary measures?** A: Supplementary measures are technical, contractual, or organizational safeguards that ensure an equivalent level of protection. Examples include end-to-end encryption, pseudonymization, data minimization, and contractual clauses that prohibit access by foreign authorities.
**Q: How often should I update my transfer impact assessment?** A: You should review your TIA whenever there is a change in the data flow, the recipient’s legal environment, or the safeguards in place. At a minimum, conduct an annual review.
**Q: What happens if I don’t comply with Schrems II?** A: Non-compliance can lead to regulatory fines under the GDPR (up to 4% of annual global turnover or €20 million, whichever is higher), as well as reputational damage and potential legal action from data subjects.
Conclusion
The Schrems II ruling has made international data transfers more complex, but with careful planning and implementation, you can achieve GDPR compliance. By conducting a transfer impact assessment, setting consent defaults to “no consent,” blocking pre-consent network requests, configuring tag manager triggers, updating your privacy policy, testing the reject flow, and running post-change scans, you can protect user data and avoid regulatory penalties. For a comprehensive audit of your website’s data flows and compliance status, use the GDPRChecker scanner to identify potential issues and get actionable recommendations. Remember, this guide provides practical steps but does not constitute legal advice; consult with a data protection professional for your specific situation.
Copyright and editorial notice
© GDPRChecker
This original AI-assisted editorial draft was selected, reviewed, and published by GDPRChecker. All rights are reserved where protected by applicable law. Do not reproduce the article without permission.