Schrems II for Swiss Companies, What It Still Means Today
Introduction
The Court of Justice of the European Union's Schrems II ruling of 16 July 2020 (Case C-311/18) fundamentally changed the world of data transfers between the EU/EEA and third countries, above all the United States. It invalidated the Privacy Shield decision, formally upheld the EU Standard Contractual Clauses (SCC) but required a case- and country-specific risk assessment (Transfer Impact Assessment, TIA). Six years later, in 2026, the picture is at once more complex and more stable: the EU-US DPF (10 July 2023) and the CH-US DPF (15 September 2024) are in force, and the scope for DPF-certified US recipients is clear. For all other transfers, Schrems II remains the guiding principle.
This article explains what Schrems II still means for Swiss companies today. What you will take away:
- the core findings of the Schrems II ruling and its direct consequences;
- the impact of the EU-US DPF and the CH-US DPF on US transfers;
- TIA practice under EDPB Recommendations 01/2020 and EDÖB guidance;
- residual risk for non-DPF US recipients and for other third countries;
- a pragmatic third-country strategy for Swiss SMEs.
The audience is data protection advisors, IT leaders, executives and procurement leads responsible for selecting and contracting with foreign service providers.
What Schrems II decided
In July 2020 the CJEU made two central findings that remain decisive today:
- The EU-US Privacy Shield is invalid. The Privacy Shield decision 2016/1250 breached Art. 45 GDPR and Art. 7, 8, 47 of the Charter of Fundamental Rights, because US surveillance programmes (FISA 702, EO 12333, PPD-28) did not provide EU citizens with essentially equivalent legal protection. Transfers based on Privacy Shield became unlawful overnight.
- EU SCC are valid, but with caveats. The Standard Contractual Clauses (now SCC 2021/914) remain in principle applicable, but the controller must check before every transfer whether the recipient country offers essentially equivalent protection. If not, supplementary measures (technical, contractual, organisational) must be put in place or the transfer must be discontinued.
EDPB Recommendations 01/2020 of 18 June 2021 operationalise this in six steps: map the transfers → identify the transfer tool → assess the recipient country's law → identify supplementary measures → take formal procedural steps → periodic review. This methodology is today the gold standard for any TIA.
For Switzerland, the EDÖB issued an opinion on 18 June 2021 applying the Schrems II logic by analogy to Art. 6 aDSG (now Art. 16–18 DSG), meaning it also applies to non-EU controllers with a Swiss nexus.
The EU-US DPF and the CH-US DPF
On 10 July 2023 the EU Commission adopted the adequacy decision for the EU-US Data Privacy Framework (DPF) (decision C(2023) 4745). On 15 September 2024 the Swiss Federal Council recognised the CH-US DPF (Swiss Extension). Both decisions make transfers to DPF-certified US recipients permissible without SCC.
What has changed compared with Privacy Shield? The US side implemented two key improvements through Executive Order 14086 (Biden, 7 October 2022):
- Necessity and proportionality: Signals Intelligence activities must now be necessary and proportionate, no longer merely «as tailored as feasible»;
- Data Protection Review Court (DPRC): EU and Swiss citizens can now turn to an independent complaints body with two-tier review.
DPF certification with the US Department of Commerce is a self-certification by US companies, costs around USD 250–3,250 per year and requires public publication of the privacy policy, a complaints mechanism and annual recertification. The list of certified companies is public at dataprivacyframework.gov. Anyone considering a US provider should first check whether they are DPF-certified, this resolves 80% of Schrems II concerns.
Important: the DPF only covers transfers to certified US recipients. Transfers to non-certified US recipients (e.g. smaller providers that have not certified) remain SCC-bound with a full TIA.
The Transfer Impact Assessment in practice
For non-DPF transfers or transfers to other third countries, a Transfer Impact Assessment (TIA) is required. The EDPB methodology calls for the following steps:
Step 1, Mapping: who transfers what to whom, in which country, with which transfer tool (SCC, BCR, Art. 49 GDPR derogations)?
Step 2, Assess the recipient country: do laws or practices in the recipient country undermine the protection offered by the SCC? Relevant factors: surveillance laws, government access rights, availability of effective legal protection for data subjects.
Step 3, Concrete assessment of the transfer: is this specific transfer likely to be subject to government access? Factors: data type (e.g. telecommunications metadata are particularly relevant for FISA 702), data volume, recipient industry (tech providers fall under FISA 702 per 50 U.S.C. § 1881a), storage location.
Step 4, Supplementary measures:
- Technical: end-to-end encryption with keys held in the EU/Switzerland; pseudonymisation with re-identification keys outside the recipient country; split processing; confidential computing.
- Contractual: transparency reports; obligation to challenge authority requests; notification duty; audit right.
- Organisational: internal policies, data classification, access restriction, periodic audits.
Steps 5–6, Documentation and periodic review: the TIA is part of accountability (Art. 5(2) GDPR / Art. 6 DSG) and must be updated whenever the legal situation in the recipient country changes.
Residual risk for non-DPF US providers
Even with the DPF, a substantial share of US providers remains outside the certification. For these, the full Schrems II framework with SCC plus TIA continues to apply. The residual risk depends on whether the US recipient is an «Electronic Communication Service Provider» under 50 U.S.C. § 1881a (FISA 702), which catches many cloud and telecommunications providers.
For such providers, EDPB Recommendations 01/2020 are clear: SCC alone are not enough. Additional technical measures are needed that effectively prevent access even in the face of a government request. The most prominent example is end-to-end encryption with keys outside the recipient country, but this is not feasible for every use case (e.g. for a cloud CRM that needs to work on the data, encryption at rest is not sufficient).
EDÖB practice and EDPB guidance increasingly differentiate by probabilistic assessment: where the likelihood of concrete government access, factoring in EO 14086, is very low (e.g. anonymised aggregate data without identifiable persons), the transfer may be defensible with purely contractual and organisational measures. But the burden of proof lies with the controller.
In doubtful cases, EU/CH data residency is the simpler answer: most large providers (Microsoft 365 with EU Data Boundary, AWS Frankfurt, Google Cloud Zurich) now offer genuine EU/CH data storage, which resolves the third-country issue structurally.
Schrems III risk and strategies
noyb and other civil rights organisations have challenged the EU-US DPF in court (Schrems III). The case is currently pending before the CJEU. A ruling is expected at earliest in late 2026, more likely 2027. The risk is real: the CJEU struck down Privacy Shield, and the structural concerns (FISA 702, EO 12333) persist in substance even if EO 14086 mitigates them.
Strategically, three options emerge for Swiss companies:
- Option A, bet on DPF, keep a migration path ready: for standard applications, choose DPF-certified US providers but draft contracts so that, on DPF invalidation, migration to SCC or to an EU provider is possible within 6 months.
- Option B, EU/CH first: in every new procurement, prioritise EU/CH providers with local data storage. Higher procurement cost, but more stable against Schrems III.
- Option C, hybrid: for non-critical data (marketing analytics, logs without personal nexus) use the DPF; for critical data (customer, patient, employee data) use EU/CH data residency with encryption.
In practice, most mature Swiss organisations choose Option C, with documented data classification and an explicit third-country policy as part of data protection governance.
Other third countries, not a country list, a case-by-case call
Schrems II is a US decision, but the TIA methodology applies to every third country. Anyone transferring data to India (e.g. to an outsourcing provider), China (e.g. to a cloud provider such as Alibaba) or the Middle East must perform the same assessment:
- India: the Digital Personal Data Protection Act 2023 (DPDPA) is in force, but supervision and legal protection are still being built up. Government access rights are broad. SCC with supplementary measures are required in practice.
- China: PIPL (Personal Information Protection Law) is substantively strict, but the Cybersecurity Law and Data Security Law provide government access rights. Transfers to China are typically only defensible with strong technical safeguards.
- UK: after Brexit, the EU adopted an adequacy decision for the UK on 28 June 2021, extended through 27 June 2025 with a subsequent reassessment. The Swiss Federal Council also recognises the UK as a safe third country. Transfers without SCC are permissible.
- UK representative: Swiss companies without a UK establishment with extensive UK processing must appoint a UK representative under the UK GDPR, see UK representative.
- Other adequate third countries: Israel, Japan, South Korea, New Zealand, Argentina, Uruguay, Canada (partial), SCC are not needed here.
A country-by-country map belongs in every data protection management system, ideally anchored directly in the records of processing activities.
How SIDD supports you
SIDD conducts Transfer Impact Assessments per EDPB 01/2020 methodology and EDÖB practice, identifies the necessary supplementary measures and develops a consistent third-country strategy for your company. We support the selection of DPF-compliant US providers, contract design with SCC and sub-SCC, and migration to EU/CH data residency where sensible.
Our Data Protection Advisors under Art. 10 DSG and GDPR DPOs work closely with our CISOs/ISBs to ensure that technical measures (encryption, pseudonymisation, confidential computing) are implemented correctly. For Swiss companies without an EU establishment we provide the EU representative under Art. 27 GDPR and for UK business the UK representative.
Want to know whether your third-country transfers still hold up today, and which strategy best secures you against a possible Schrems III ruling? Request a non-binding quote for a TIA or contact us via the contact form. A 30-minute initial call is enough to identify your most pressing risks.
