Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >Schrems II remediation: Where are we a year on?
    Technology

    Schrems Ii Remediation: Where Are We a Year On?

    Published by Jessica Weisman-Pitts

    Posted on September 27, 2021

    5 min read

    Last updated: February 1, 2026

    Add as preferred source on Google
    An informative image illustrating the complexities of data transfer compliance following the Schrems II ruling, highlighting key actions organizations must take to ensure legal and regulatory adherence.
    Visual representation of data transfer compliance post-Schrems II - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Quick Summary

    A year after Schrems II, organizations face new SCC deadlines and must conduct Transfer Impact Assessments for compliance.

    Schrems II Remediation: Progress One Year Later

    By Ana Fernandes, digital trust expert at PA Consulting

    Since the Schrems II decision invalidated the EU-US privacy shield, organisations have known they need to take a good look at their data transfers and ensure they’re safe. It’s now been a year since we initially explored what the ECJ ruling meant, so what’s changed and how can businesses move forward?

    What’s changed?

    The European Commission (EC) published updated Standard Contractual Clauses (SCCs) in June. And they’ve created real urgency to act, giving organisations just three months (up to 27 September 2021) before the legacy SCCs cease to be valid for new contracts, and 18 months (up to 27 December 2022) to review and fully migrate all existing arrangements to the new SCCs. The EC has also reiterated that organisations will need to conduct Transfer Impact Assessments (TIAs) by the end of 2022, as per Schrems II.​

    At the same time, the UK’s Information Commissioner’s Office (ICO) announced it was working on its own International Data Transfer Agreement (IDTA), rather than endorsing the new EU SCCs. While the ICO documents released for consultation are a promising indication of what’s to come, there’s no certainty about what the IDTA will look like and what deadlines the ICO will impose.

    This has left organisations with the tough task of figuring out how to manage both, without quite knowing how they’ll differ. And that becomes significantly more challenging in complex contexts, such as intra-group transfer agreements that involve both EU and UK transfers. ​

    Amid the uncertainty, organisations need to decide how to set up their Schrems II programmes from both a legal and compliance perspective. To gather executive sponsorship and get themselves to a position where they can meet existing and upcoming deadlines, organisations should focus on three key actions:

    1. Tackle immediate challenges

    The initial deadlines to create and implement new SCCs seemed reasonable. But we’re seeing third parties already reaching out with new SCCs, so it’s crucial for your compliance and data protection teams to provide interim guidance about how to respond coherently.

    Organisations also can’t wait for the final UK IDTA to act. The September 2021 deadline is already upon us. So, they must set their new SCCs now, ready for any new contracts. ​

    Such activities require resources, but data protection teams are likely already swamped with BAU activities, so will struggle to tackle a strategic programme of this size. Creating a business case for focusing on new SCCs and guidance will be critical to securing stakeholder involvement and resources, and, therefore, long-term success.

    1. Start with what you’ve got and build on it

    Your Schrems II programme can only be successful and sustainable if your ‘privacy foundations’ are solid, namely your third party and transfers governance framework. You must answer difficult questions around your risk appetite, approach to third party assurance and governance model. Do you have senior stakeholder buy-in? Have you determined what to tackle first? Based on what criteria? Have you provided clear guidance to the business?​ What information do you need to be gathering to fulfil TIAs? How can you create efficiencies (such as with a library of countries)?

    The Record of Processing Activities (RoPAs) you keep as part of GDPR compliance is likely to be the best place to understand your data transfer landscape and start identifying restricted transfers. And this is a great opportunity to tackle two (or more) birds with one stone – you can use the SSCs as an excuse to revisit your RoPAs to ensure they’re up-to-date, complete and actionable.​ Start by reviewing your RoPA template to test if you’re collecting all the information you need.

    To perform TIAs effectively, as well as to comply with pre-contractual obligations,[1] link them to your vendor assessment (VA), using automated tools where possible. You can enhance your VA by including the information required to assess the transfer, decide whether the SCCs/IDTA are likely to be enforceable and check there are appropriate protections in place from third-party access.

    This approach reduces the number of assessments you’re performing and provides the information needed to implement SSCs and TIAs, and you’re more likely to spot gaps requiring remediation. It’s also easy to hide the new section of the VA if the transfer isn’t restricted.

    1. Think long term and holistically, making sure to build in flexibility 

    Schrems II programmes are likely to require considerable effort and resources, so it’s crucial to set up solid foundations to ensure long-term sustainability. Organisations will need to consider how to embed other privacy requirements alongside the new SCCs to avoid multiple contract updates running consecutively.​

    And, as TIAs are dynamic documents, organisations must review them both periodically as part of BAU and anytime something significant changes. Setting up the monitoring process now, as well as the KPIs to report against, will ensure all the effort and resources dedicated to the programme will deliver value.

    Last but not least, setting up your privacy management system for success by enabling centralised collaboration, tracking and documentation of work, is key to getting the data to track success and demonstrate accountability.

    Key Takeaways

    • •Updated SCCs require urgent action by organizations.
    • •Transfer Impact Assessments are mandatory by end of 2022.
    • •UK developing its own International Data Transfer Agreement.
    • •Organizations must align legal and compliance strategies.
    • •Review RoPAs to ensure data transfer compliance.

    Frequently Asked Questions about Schrems II remediation: Where are we a year on?

    1What is the main topic?

    The article discusses Schrems II remediation and data transfer compliance following the EU-US privacy shield invalidation.

    2What are Standard Contractual Clauses?

    SCCs are legal tools for data transfer compliance between EU and non-EU countries, updated post-Schrems II.

    3What is a Transfer Impact Assessment?

    A TIA evaluates the impact of data transfers on privacy and compliance, required by the end of 2022.

    More from Technology

    Explore more articles in the Technology category

    Image for Asprofin Bank Appoints RRP Electronics as Tier One Contractor for Multi-Billion Data Center Network
    Asprofin Bank Appoints Rrp Electronics as Tier One Contractor for Multi-Billion Data Center Network
    Image for Submit Your Nominations: Most Innovative Islamic Mobile Savings App 2026
    Submit Your Nominations: Most Innovative Islamic Mobile Savings App 2026
    Image for Entries Open: Most Innovative Islamic Bank Digital Branch Design 2026
    Entries Open: Most Innovative Islamic Bank Digital Branch Design 2026
    Image for Best New Islamic Open Banking APIs 2026 – Nominations Open
    Best New Islamic Open Banking APIs 2026 – Nominations Open
    Image for Submit Your Nominations Today for Best Digital Islamic Bank 2026
    Submit Your Nominations Today for Best Digital Islamic Bank 2026
    Image for Designing a Scalable Telecom Quoting Architecture: From Pricing Complexity to Quote-to-Order Automation
    Designing a Scalable Telecom Quoting Architecture: From Pricing Complexity to Quote-to-Order Automation
    Image for How Web3 Infrastructure Is Redefining Data Sovereignty and Operational Efficiency for Modern Financial Institutions
    How Web3 Infrastructure Is Redefining Data Sovereignty and Operational Efficiency for Modern Financial Institutions
    Image for Klippa Now Operates as Doxis as Part of a Unified Global Brand
    Klippa Now Operates as Doxis as Part of a Unified Global Brand
    Image for Nominations Open: Best New Digital Wallet 2026
    Nominations Open: Best New Digital Wallet 2026
    Image for Best Digital Wallet 2026: Nominations Now Open
    Best Digital Wallet 2026: Nominations Now Open
    Image for Bessemer Venture Partners Poured Millions Into Litify; Here's Why One of the World's Top VCs Thinks This Platform Will Dominate Legal Tech
    Bessemer Venture Partners Poured Millions Into Litify; Here's Why One of the World's Top VCs Thinks This Platform Will Dominate Legal Tech
    Image for HID Announces Converged Credentials Solution Bridging Physical and Logical Identity Across the Enterprise
    Hid Announces Converged Credentials Solution Bridging Physical and Logical Identity Across the Enterprise
    View All Technology Posts
    Previous Technology PostHow Workforce Management Technology Can Improve Business Performance
    Next Technology PostThe Importance of Managing Data Risk in the Finance Function