News
Insight

Personal data transfers to the US: no grace period for a Plan B

In 2025, it has become harder to scrutinise how the US uses personal data from the EU. For those transferring data to the US, having an exit strategy could prove valuable if the EU is left without a contingency plan.

The European Commission has stayed silent on the fact that the oversight body, the Privacy and Civil Liberties Oversight Board (PCLOB), is no longer able to make decisions, after the White House in January emailed several members asking them to resign or informing them they were dismissed. PCLOB was established for independence and separation of powers, principles intended to rein in mass surveillance after the 2001 terrorist attacks in the US.

Members of the European Parliament asked in February and March whether the Commission intends to reconsider the EU-U.S. Data Privacy Framework (DPF) agreement, and whether it can even remain valid without PCLOB. In its October report, the Commission said it intended to ”closely follow developments regarding vacancies and nominations” to PCLOB, but has not responded to Parliament.

In the US, the Department of Justice — itself subject to change — has not commented on the departure of a judge appointed by PCLOB to the Data Protection Review Court (DPRC), reportedly also under pressure. The DPRC was established as a condition of the agreement with the EU. The court is meant to review complaints from EU citizens about how their personal data is processed.

Every statement can shift the course of events within and between the US and the EU. But silence and inaction also carry consequences.

Transferring personal data to the US is lawful to participating providers, following the European Commission's 2023 decision that the level of protection is adequate — a so-called adequacy decision. The Commission and the Court of Justice of the EU can revoke that decision — unless the US has already terminated the agreement itself, for example by revoking an earlier executive order.

In that situation, companies transferring personal data from the EU to the US need other legal grounds under Chapter V of the GDPR. Standard contractual clauses (SCCs) under Article 46 have not previously held up before the Court of Justice of the EU. Binding corporate rules (BCRs) under Article 47 are mainly relevant within large corporate groups. Derogations under Article 49 rest on weaker legal grounds: consent, contract, public interest and legal claims, as well as, for example, emergency medical care abroad. Anyone who cannot find a sustainable basis needs to ask how it might be possible to simply avoid transferring personal data to the US at all.

Microsoft and Google Cloud went live in 2025 with the “EU Data Boundary” project and co-location via the “Stockholm (europe-north2)” region, respectively. Beyond geographic options, there are technical ones such as Bring Your Own Key (BYOK), where the cloud provider can still be compelled to decrypt data if it has access to the key via a key management system (KMS) such as AWS KMS, Microsoft Azure Key Vault or Google Cloud KMS. Or Hold Your Own Key (HYOK), where the cloud provider does not hold the encryption key, which can limit search functionality.

All of this assumes that cloud providers governed by the US remain available and commercially viable in the EU — regardless of where and how data is encrypted, stored and processed — in the event of new executive orders. Authorities in Sweden, Denmark, Norway and the Netherlands are urging affected organisations to think through their options now. The window for reflection closes if the DPF is terminated.

  • EU-U.S. Data Privacy Framework (DPF) (2023–) The European Commission issued an adequacy decision in 2023.
  • Privacy Shield (2016–2020) The Court of Justice of the EU invalidated the agreement in 2020 in the Schrems II ruling, citing continued concerns over US surveillance programmes.
  • Safe Harbor (2000–2015) The Court of Justice of the EU invalidated the agreement in 2015 in the Schrems I ruling, on the grounds that it did not provide sufficient protection against US mass surveillance.

Read more: NYT 22 January, Euractiv 3 March, TT 9 March


Seclight — the right security, in the right order.

Contact: David Hässler, phone 08-94 55 99 david.hassler@seclight.com