Menu
← All articles

Schrems II explained: what the ruling means for your practice

Schrems II explained: what the ruling means for your practice

Hands typing on a laptop, with a smartphone and a plant beside them

In short: Schrems II invalidated the Privacy Shield and placed the responsibility for assessment on the organisation sending the data. Since 11 July 2023 the Data Privacy Framework (DPF) has been in place, allowing transfers to participating American companies without additional measures. If your supplier is not in that register, you need standard contractual clauses (SCCs), plus a Transfer Impact Assessment (DTIA) and possibly additional security.

Three things to check today:

  • Is your American software supplier listed in the official DPF register?
  • Does that participation also cover the specific product you use, not just the parent company?
  • If the DPF does not apply, do you have SCCs and a DTIA on paper?

Key insights

Schrems II requires organisations to assess for themselves whether transfers to the US are safe, and the Data Privacy Framework only eases that burden for certified suppliers.

Point Details
Privacy Shield is invalid Since 2020 you can no longer rely on that framework for transfers to the US.
DPF since 2023 Check the register and whether your specific product falls under the certification.
SCCs require a DTIA Without DPF coverage, you must assess for yourself whether the level of protection is adequate.
A data processing agreement remains mandatory Always conclude one, regardless of which transfer route you choose.
Exantur operates from within the EU No transfer to the US needed; includes a ready-made data processing agreement.

Table of contents

What did the Court of Justice rule in Schrems II?

On 16 July 2020 the Court of Justice of the EU declared the Privacy Shield invalid, in the case known as C-311/18. The heart of the ruling comes down to three points.

  1. American surveillance laws give security services overly broad access to the data of European citizens, without sufficient legal protection in return.
  2. As a result, the Privacy Shield did not provide a level of protection that is “essentially equivalent” to the GDPR, despite the self-certification of participating companies.
  3. Standard contractual clauses remain valid, but the exporting organisation must assess for itself, for each transfer, whether the level of protection actually holds up in practice.

That last point is where many coaches and small businesses trip up. Signing a contract is not enough. You also have to check whether the laws of the receiving country undermine that protection, and take additional measures if necessary. That obligation still applies, even now that there is once again an adequacy decision.

What is the Data Privacy Framework and what do the AP and EDPB do?

The Data Privacy Framework is the European Commission's new adequacy decision for the United States, in force since 11 July 2023. It replaces the invalidated Privacy Shield and is built around stricter safeguards against uncontrolled access by American government agencies.

Here's how it works in practice:

  • An American company must voluntarily register and certify with the US Department of Commerce.
  • If the supplier is in the register, you may transfer data without separate contracts or assessments.
  • If the supplier is not in it, nothing changes: you will still need SCCs and a DTIA.

Since when has this applied? The decision came into force in mid-2023. The European Commission and the EDPB subsequently published explanatory notes on how organisations should apply it.

The Dutch Data Protection Authority (AP) continues to supervise transfers in the Netherlands and handles complaints from data subjects. The European Data Protection Board (EDPB), the cooperative body of all European privacy supervisors, provides additional guidance and warns organisations that the DPF is not a licence for blind trust. Both authorities can still investigate a transfer if there is reason to.

How do you legally transfer personal data to the US?

The route you choose depends entirely on who receives your data. Follow this order.

  1. Map out what you share. Which personal data goes to which American party, and why? Think of email marketing, accounting software, video calling or cloud services.
  2. Check the DPF register. Look up the supplier in the participant search and see whether the specific product you use falls under the certification. A large supplier may have ten products with only three covered.
  3. No DPF coverage? Conclude SCCs and carry out a Transfer Impact Assessment. This is an assessment of whether the level of protection is adequate in practice, given the laws of the receiving country. The Dutch Data Protection Authority recommends that assessment for every transfer without an adequacy decision.
  4. Determine additional measures where needed: encryption, pseudonymisation or limiting the data you actually share.
  5. Always conclude a data processing agreement, regardless of which route you choose. This is a mandatory contract between you and the supplier about how they handle personal data, and that obligation is separate from the DPF.

Pro tip: Record every decision in writing, even if you conclude that a tool poses no problem. Half a page with the date, supplier and conclusion is often enough to show, in the event of an inspection by the AP, that you have taken this seriously.

Binding corporate rules and the exceptions under Article 49 of the GDPR (such as explicit consent) also exist, but are rarely practical for a coaching practice. They are intended for large corporations or one-off, well-substantiated situations, not for structural transfers via software.

Checklist for coaches: which tools do you check first?

For a coaching practice, the theory comes down to a few concrete actions per software tool you use.

  • Make a list of all the tools that contain client data: accounting, video calling, email, scheduling tools, coaching software.
  • For each American supplier, look up whether it is in the DPF register, and whether your specific subscription or product is included in the certification.
  • No coverage? Ask the supplier for SCCs and carry out a short DTIA yourself: which data, which risk, which measure.
  • Conclude a data processing agreement with each supplier, even if that supplier is based in the Netherlands or the EU.
  • Where possible, choose tools with EU-hosted storage; that makes the entire assessment unnecessary for that specific service.

Anyone who wants to get started right away can link this overview to the advice on American cloud solutions, which shows how difficult it is in practice to break away entirely from American services, even for larger organisations.

Key insights

Point Details
Privacy Shield is dead Since 2020 that framework has been invalid; SCCs alone are not automatically sufficient.
DPF since 2023 Always check the register and the product coverage, not just the company name.

A brief perspective: priorities and common mistakes

Most coaches don't make the mistake of ignoring Schrems II. They make the mistake of looking at it once and then closing the file. Start with a simple inventory: which supplier has access to which client data. That overview is missing at a surprising number of small practices, even though it is the foundation for everything that follows.

Prioritise the DPF check above all else. It takes a few minutes per supplier and prevents unnecessary paperwork for tools that are already covered. What I more often see going wrong: a data processing agreement is signed and forgotten, whereas it is precisely that agreement and the reasoning behind it that a supervisor asks for first in an investigation. Document your choices, even the boring ones.

— Martijn

Why EU hosting makes the difference for coaches

The steps described above, the DPF check, SCCs, DTIA, take time that most coaches would rather spend on clients. Exantur is built around that problem: the software runs on servers within the EU, in Frankfurt, and organisations work separately from one another based on strict access rules. This means that for this specific tool the entire Schrems II assessment is simply unnecessary, because there is no transfer to the US.

A coach's hands placing a token in a bright coaching studio

Exantur also offers a data processing agreement that you can conclude directly and keep as evidence for the AP. That is exactly the kind of documentation supervisors ask for. Would you like to see what client management software for coaches with EU hosting looks like, and whether it suits your practice? Start the free 14-day trial and see for yourself whether it makes your GDPR file easier.

Sources

Frequently asked questions

What is an adequacy decision?

An adequacy decision is a declaration by the European Commission that a country outside the EU offers sufficient protection for personal data. For the US, the Data Privacy Framework has served as such a decision since 11 July 2023, but only for companies that have actually registered.

What are the main privacy rules in the Netherlands?

In the Netherlands, the GDPR applies as the basic data protection law, supplemented by the GDPR Implementation Act. The Dutch Data Protection Authority supervises compliance and can impose fines for violations, including improper transfers to countries outside the EU.

What are the GDPR rules around transfers to the US?

The GDPR permits transfers to the US via three routes: a valid adequacy decision (the DPF), standard contractual clauses with an additional assessment, or specific exceptions such as explicit consent. Without one of these routes, transfers are not permitted.

What does Schrems II mean for coaches who use American software?

Coaches must check for each American tool whether the supplier is listed in the DPF register. If not, standard contractual clauses and a brief risk assessment are required, along with a data processing agreement.

How do I carry out a Transfer Impact Assessment?

A Transfer Impact Assessment maps out which data you transfer, to which country, which laws pose a risk there and what measures you take to mitigate those risks. For a small practice, a short one-page document is often enough, provided you keep it as evidence.

Recommended