Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > Schrems II remediation: Where are we a year on?
    Technology

    Schrems II remediation: Where are we a year on?

    Published by Jessica Weisman-Pitts

    Posted on September 27, 2021

    5 min read

    Last updated: February 1, 2026

    An informative image illustrating the complexities of data transfer compliance following the Schrems II ruling, highlighting key actions organizations must take to ensure legal and regulatory adherence.
    Visual representation of data transfer compliance post-Schrems II - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Quick Summary

    A year after Schrems II, organizations face new SCC deadlines and must conduct Transfer Impact Assessments for compliance.

    Schrems II Remediation: Progress One Year Later

    By Ana Fernandes, digital trust expert at PA Consulting

    Since the Schrems II decision invalidated the EU-US privacy shield, organisations have known they need to take a good look at their data transfers and ensure they’re safe. It’s now been a year since we initially explored what the ECJ ruling meant, so what’s changed and how can businesses move forward?

    What’s changed?

    The European Commission (EC) published updated Standard Contractual Clauses (SCCs) in June. And they’ve created real urgency to act, giving organisations just three months (up to 27 September 2021) before the legacy SCCs cease to be valid for new contracts, and 18 months (up to 27 December 2022) to review and fully migrate all existing arrangements to the new SCCs. The EC has also reiterated that organisations will need to conduct Transfer Impact Assessments (TIAs) by the end of 2022, as per Schrems II.​

    At the same time, the UK’s Information Commissioner’s Office (ICO) announced it was working on its own International Data Transfer Agreement (IDTA), rather than endorsing the new EU SCCs. While the ICO documents released for consultation are a promising indication of what’s to come, there’s no certainty about what the IDTA will look like and what deadlines the ICO will impose.

    This has left organisations with the tough task of figuring out how to manage both, without quite knowing how they’ll differ. And that becomes significantly more challenging in complex contexts, such as intra-group transfer agreements that involve both EU and UK transfers. ​

    Amid the uncertainty, organisations need to decide how to set up their Schrems II programmes from both a legal and compliance perspective. To gather executive sponsorship and get themselves to a position where they can meet existing and upcoming deadlines, organisations should focus on three key actions:

    1. Tackle immediate challenges

    The initial deadlines to create and implement new SCCs seemed reasonable. But we’re seeing third parties already reaching out with new SCCs, so it’s crucial for your compliance and data protection teams to provide interim guidance about how to respond coherently.

    Organisations also can’t wait for the final UK IDTA to act. The September 2021 deadline is already upon us. So, they must set their new SCCs now, ready for any new contracts. ​

    Such activities require resources, but data protection teams are likely already swamped with BAU activities, so will struggle to tackle a strategic programme of this size. Creating a business case for focusing on new SCCs and guidance will be critical to securing stakeholder involvement and resources, and, therefore, long-term success.

    1. Start with what you’ve got and build on it

    Your Schrems II programme can only be successful and sustainable if your ‘privacy foundations’ are solid, namely your third party and transfers governance framework. You must answer difficult questions around your risk appetite, approach to third party assurance and governance model. Do you have senior stakeholder buy-in? Have you determined what to tackle first? Based on what criteria? Have you provided clear guidance to the business?​ What information do you need to be gathering to fulfil TIAs? How can you create efficiencies (such as with a library of countries)?

    The Record of Processing Activities (RoPAs) you keep as part of GDPR compliance is likely to be the best place to understand your data transfer landscape and start identifying restricted transfers. And this is a great opportunity to tackle two (or more) birds with one stone – you can use the SSCs as an excuse to revisit your RoPAs to ensure they’re up-to-date, complete and actionable.​ Start by reviewing your RoPA template to test if you’re collecting all the information you need.

    To perform TIAs effectively, as well as to comply with pre-contractual obligations,[1] link them to your vendor assessment (VA), using automated tools where possible. You can enhance your VA by including the information required to assess the transfer, decide whether the SCCs/IDTA are likely to be enforceable and check there are appropriate protections in place from third-party access.

    This approach reduces the number of assessments you’re performing and provides the information needed to implement SSCs and TIAs, and you’re more likely to spot gaps requiring remediation. It’s also easy to hide the new section of the VA if the transfer isn’t restricted.

    1. Think long term and holistically, making sure to build in flexibility 

    Schrems II programmes are likely to require considerable effort and resources, so it’s crucial to set up solid foundations to ensure long-term sustainability. Organisations will need to consider how to embed other privacy requirements alongside the new SCCs to avoid multiple contract updates running consecutively.​

    And, as TIAs are dynamic documents, organisations must review them both periodically as part of BAU and anytime something significant changes. Setting up the monitoring process now, as well as the KPIs to report against, will ensure all the effort and resources dedicated to the programme will deliver value.

    Last but not least, setting up your privacy management system for success by enabling centralised collaboration, tracking and documentation of work, is key to getting the data to track success and demonstrate accountability.

    Key Takeaways

    • •Updated SCCs require urgent action by organizations.
    • •Transfer Impact Assessments are mandatory by end of 2022.
    • •UK developing its own International Data Transfer Agreement.
    • •Organizations must align legal and compliance strategies.
    • •Review RoPAs to ensure data transfer compliance.

    Frequently Asked Questions about Schrems II remediation: Where are we a year on?

    1What is the main topic?

    The article discusses Schrems II remediation and data transfer compliance following the EU-US privacy shield invalidation.

    2What are Standard Contractual Clauses?

    SCCs are legal tools for data transfer compliance between EU and non-EU countries, updated post-Schrems II.

    3What is a Transfer Impact Assessment?

    A TIA evaluates the impact of data transfers on privacy and compliance, required by the end of 2022.

    More from Technology

    Explore more articles in the Technology category

    Image for Infosecurity Europe launches new Cyber Startup Programme to champion the next generation of cybersecurity innovators
    Infosecurity Europe launches new Cyber Startup Programme to champion the next generation of cybersecurity innovators
    Image for BLOXX Launches ĀRIKI BLOXX at Web Summit Qatar
    BLOXX Launches ĀRIKI BLOXX at Web Summit Qatar
    Image for Engineering Trust in the Age of Data: A Blueprint for Global Resilience
    Engineering Trust in the Age of Data: A Blueprint for Global Resilience
    Image for Over half of organisations predict their OT environments will be targeted by cyber attacks
    Over half of organisations predict their OT environments will be targeted by cyber attacks
    Image for Engineering Financial Innovation in Renewable Energy and Climate Technology
    Engineering Financial Innovation in Renewable Energy and Climate Technology
    Image for Industry 4.0 in 2025: Trends Shaping the New Industrial Reality
    Industry 4.0 in 2025: Trends Shaping the New Industrial Reality
    Image for Engineering Tomorrow’s Cities: On a Mission to Build Smarter, Safer, and Greener Mobility
    Engineering Tomorrow’s Cities: On a Mission to Build Smarter, Safer, and Greener Mobility
    Image for In Conversation with Faiz Khan: Architecting Enterprise Solutions at Scale
    In Conversation with Faiz Khan: Architecting Enterprise Solutions at Scale
    Image for Ballerine Launches Trusted Agentic Commerce Governance Platform
    Ballerine Launches Trusted Agentic Commerce Governance Platform
    Image for Maximising Corporate Visibility in a Digitally Driven Investment Landscape
    Maximising Corporate Visibility in a Digitally Driven Investment Landscape
    Image for The Digital Transformation of Small Business Lending: How Technology is Reshaping Credit Access
    The Digital Transformation of Small Business Lending: How Technology is Reshaping Credit Access
    Image for Navigating Data and AI Challenges in Payments: Expert Analysis by Himanshu Shah
    Navigating Data and AI Challenges in Payments: Expert Analysis by Himanshu Shah
    View All Technology Posts
    Previous Technology PostHow workforce management technology can improve business performance
    Next Technology PostThe Importance of Managing Data Risk in the Finance Function