Skip to content
Legiscope
Menu
Data Privacy

GDPR Supplementary Measures: Schrems II Catalog 2026

Schrems II supplementary measures catalog: technical, contractual, organisational. EDPB Recommendations 01/2020, use cases, cloud examples, TIA integration.

Key takeaways

  • Three categories: technical, contractual, organisational.
  • Technical measures (encryption, pseudonymisation) are the only ones that block direct access in most threat models.
  • EDPB Recommendations 01/2020 (final version June 2021) provide use cases 1-7.
  • Required for Article 46 transfers (SCCs, BCRs, codes, certifications) — not for Article 45 adequacy.
  • Cloud “remote access” by US engineers counts as a transfer requiring assessment.
  • Failure: Meta Ireland €1.2B (DPC + EDPB, May 2023).

1. Origin: Schrems II + EDPB Recommendations 01/2020

CJEU C-311/18 (16 July 2020) invalidated Privacy Shield and conditioned SCC validity on “additional measures” where local law undermines protection. The EDPB Recommendations 01/2020 (final version adopted 18 June 2021) translated this into a six-step methodology and a catalog of measures.

2. The six-step methodology

  1. Know your transfers (map every cross-border data flow)
  2. Verify the transfer tool (Article 46 instrument)
  3. Assess the law and practice of the third country
  4. Identify and adopt supplementary measures
  5. Take procedural steps (consult DPA if needed)
  6. Re-evaluate at appropriate intervals

3. Technical measures (most robust)

EDPB Annex 2 — technical measures:

Measure Effect Use case
Strong encryption with keys held only in EU Blocks access by importer and authorities Storage-only transfer (use case 3)
Pseudonymisation without re-id keys at importer Reduces re-identification Research data export
Split processing (multi-party computation) No single party sees full data Cross-border analytics
End-to-end encryption Importer cannot decrypt Messaging

Technical measures are the only ones EDPB considers effective against bulk surveillance.

4. Contractual measures (supplementary, not sufficient alone)

EDPB Annex 2 — contractual:

  • Importer obligation to challenge access requests
  • Obligation to use legal remedies
  • Transparency reporting on access requests
  • Notice to controller upon receipt of request
  • Audit rights specific to local law
  • Warranty regarding absence of backdoors

These deter or document but do not block access. Always required, never sufficient alone for US/China-type regimes.

5. Organisational measures

  • Internal access policies restricting US-located staff
  • Documented procedures for handling government requests
  • Training on Schrems II
  • Strict need-to-know on cross-border data flows
  • Selection of EU-based subprocessors where possible

6. EDPB use cases (Annex 2)

Use case Scenario Conclusion
1 Data hosted in EU only Effective measures possible (split processing)
2 Pseudonymised data transferred for research Effective if re-id keys held in EU
3 Encrypted data hosted/backup in third country Effective if EU-held keys
4 Transfer to FISA 702 importer for clear data No effective measures
5 Remote access from third country to EU data Generally no effective measures for clear data
6 Cloud SaaS with importer clear-data access No effective measures under FISA 702
7 Joint controller research with FISA risk Case by case

Use cases 4-6 are the practical blockers — they apply to most US cloud SaaS configurations.

7. Cloud-specific application

For US hyperscalers (AWS, Azure, GCP), supplementary measures typically include:

  • EU regions only
  • Customer-managed keys held in EU (BYOK / HYOK)
  • Confidential computing where available
  • Contractual transparency on US government requests
  • EU sovereign cloud variants (T-Systems / SAP / OVHcloud)
  • For DPF-certified recipients: rely on adequacy, supplementary measures not required

8. Government access — third-country profile

EDPB’s law-and-practice assessment requires examining:

  • US: FISA 702, Executive Order 12333, CLOUD Act, Patriot Act
  • China: National Intelligence Law, Cybersecurity Law, DSL
  • Russia: SORM, Yarovaya law (essentially no transfers)
  • India: Telegraph Act, IT Act 69
  • UK: Investigatory Powers Act (despite adequacy)

9. Documentation requirements

Per the Article 5(2) accountability principle, a TIA + supplementary measures document must include:

  • Data flow description
  • Law and practice assessment
  • Measures adopted (with proof: KMS configuration, contractual clauses signed)
  • Re-evaluation schedule

DPAs (CNIL, Garante, AEPD) request this file during inspections — it belongs in the evidence pack described in our GDPR audit guide.

10. Sanctions

  • Meta Ireland (DPC, May 2023): €1.2 billion — no effective supplementary measures for EU-US Facebook transfers
  • Google Analytics decisions (CNIL, Garante, DSB 2022-2023): unlawful transfers
  • Clearview AI (multiple DPAs): €20M+ partly transfer-based

10a. The DPF changed the shape of the problem, not its substance

The EU-US Data Privacy Framework (adequacy decision in force since July 2023) removed the need for supplementary measures for transfers to DPF-certified US recipients — but only for those recipients, and only while the adequacy decision stands. Three things follow. First, you must verify certification per recipient, on the active DPF list, and re-verify it, because certification lapses. Second, the DPF does nothing for the very large population of US vendors that never certified, or for transfers to any other third country — those still require the full Schrems II analysis. Third, the adequacy decision itself is under legal challenge and subject to periodic Commission review; a controller that has torn out all its technical measures in reliance on the DPF is one court ruling away from the 2020 Privacy Shield situation repeating. The defensible posture in 2026 is belt-and-braces: rely on DPF where it applies, but keep the encryption and key-management architecture in place so that a withdrawal of adequacy does not leave transfers instantly unlawful.

10b. What “essentially equivalent” actually demands

The standard the CJEU set is not “reasonable” or “adequate” protection — it is protection essentially equivalent to that guaranteed within the EU. That phrasing is why contractual promises alone fail against a surveillance regime like FISA 702: a clause cannot bind an intelligence agency that is not a party to the contract. Only measures that make the data technically inaccessible to the foreign authority — strong encryption with keys never leaving the EEA, or effective pseudonymisation — meet the bar for clear-data transfers. This is the single most important sentence in the whole catalog, and the reason use cases 4 to 6 are marked “no effective measures”.

11. Tooling

FAQ

What are GDPR supplementary measures?

Additional technical, contractual or organisational safeguards required by Schrems II (CJEU C-311/18) and EDPB Recommendations 01/2020 to ensure essentially equivalent protection when transferring personal data to a country with deficient local law.

When are supplementary measures required?

Whenever a Transfer Impact Assessment under Article 46 (SCCs, BCRs, codes, certifications) shows that local law and practice in the destination country undermine protection — including most US, China, and Russia transfers.

What technical measures count as supplementary?

Strong encryption with EU-held keys, pseudonymisation without re-identification keys at the importer, split processing, end-to-end encryption.

Are contractual measures alone enough?

No. EDPB Recommendations 01/2020 are explicit: for FISA 702 / clear-data scenarios (use cases 4-6), no contractual measure is effective. Technical measures are required.

What’s the biggest sanction for missing supplementary measures?

Meta Ireland (Irish DPC + EDPB binding decision, May 2023): €1.2 billion — the largest GDPR fine ever — specifically for unlawful US transfers without effective supplementary measures.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

India-EU Data Transfers: Adequacy Status and SCCs

India holds no EU adequacy decision. There is no partial recognition, no sectoral carve-out, no pending framework to rely on in the meantime. Every transfer of personal data from the EEA to India…

July 30, 2026
03Data Privacy

Singapore–EU Data Transfers: Adequacy and SCCs

Singapore does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Singapore has never held one, and no adequacy…

July 30, 2026
04Data Privacy

Standard Contractual Clauses (SCCs): GDPR Guide for 2026

Standard Contractual Clauses (SCCs) are the most widely used mechanism for transferring personal data from the EU/EEA to third countries without an adequacy decision. The European Commission released…

April 30, 2026
05Data Privacy

Transfer Impact Assessment (TIA): Step-by-Step GDPR Guide

The Transfer Impact Assessment (TIA) is the most under-implemented requirement of the GDPR international transfer regime. Following the Schrems II judgment (CJEU C-311/18, 16 July 2020), the EDPB…

April 30, 2026
06Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
07Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
08Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026