Skip to main content
The state of ai impact assessment
ePrivacy Regulation Stalls: What Data Transfer Teams Need NowLaws and Regulations
4 min readFor Data Governance Teams

ePrivacy Regulation Stalls: What Data Transfer Teams Need Now

Scope

This guide addresses the compliance gap created by the ePrivacy Regulation's delay and the shifting legal landscape for international data transfers following Schrems II. If your team manages cross-border data flows, cookie consent infrastructure, or relies on standard contractual clauses, you're operating in a regulatory environment where promised clarity hasn't materialized.

We'll cover what's enforceable today, what remains uncertain, and how to structure your data transfer documentation when the rules keep changing.

Key Concepts and Definitions

ePrivacy Regulation: The EU's proposed update to electronic communications privacy rules, intended to harmonize with GDPR. Originally expected to pass alongside GDPR in 2018, it remains stalled. Until it passes, the 2002 ePrivacy Directive remains in force, creating inconsistent national implementations across member states.

Schrems II: The European Court of Justice case (Case C-311/18) that examined whether Privacy Shield and standard contractual clauses provide adequate safeguards for EU-to-US data transfers. The ruling invalidated Privacy Shield and imposed additional assessment requirements for standard contractual clauses.

Standard Contractual Clauses: Pre-approved contract terms issued by the European Commission that establish data protection obligations for international transfers. Post-Schrems II, these clauses alone aren't sufficient, you must conduct transfer impact assessments for each destination jurisdiction.

Privacy Shield: A framework that allowed certified US companies to receive personal data from the EU. Invalidated by the Schrems II ruling in July 2020, rendering thousands of existing data transfer arrangements non-compliant overnight.

Requirements Breakdown

What You Must Comply With Today

GDPR Article 44: All international transfers require an adequacy decision, appropriate safeguards (like standard contractual clauses), or a valid derogation. The "appropriate safeguards" bar has been raised.

GDPR Article 46: If you're using standard contractual clauses, you now need supplementary measures. The EDPB Guidelines on these measures weren't published until June 2021, but supervisory authorities expect you to have implemented them retroactively.

National ePrivacy Laws: Each EU member state has its own implementation of the 2002 ePrivacy Directive. France's Loi Informatique et Libertés, for instance, has specific cookie consent requirements that differ from Germany's Telemedia Act. You're bound by the law of each jurisdiction where you operate, not by the still-pending ePrivacy Regulation.

What Remains Undefined

The ePrivacy Regulation was supposed to resolve inconsistencies in Terminal Equipment Access rules, cookie consent requirements, and electronic marketing practices. Without it, you're navigating 27 different national interpretations. The CNIL Recommendation provides one model, but it's not binding on other member states.

Implementation Guidance

Audit Your Current Transfer Mechanisms

Start with an inventory. For each data flow leaving the EU:

  1. Document the Legal Basis for Processing (Article 6) and the transfer mechanism (Article 46 or 49).
  2. If you relied on Privacy Shield, that mechanism is void, identify replacement safeguards.
  3. For standard contractual clauses, conduct a transfer impact assessment examining the destination country's surveillance laws, data access procedures, and available legal remedies.

Structure Your Transfer Impact Assessments

Your assessment should address:

  • What categories of data you're transferring and why.
  • The legal regime in the destination country, including government access powers.
  • Technical measures you've implemented (encryption in transit and at rest, pseudonymization, data minimization).
  • Contractual measures beyond the standard clauses (audit rights, breach notification timelines, data deletion guarantees).

If your assessment concludes that the destination country's laws undermine the clauses, you cannot proceed with that transfer. Suspending the transfer or implementing additional safeguards are your only compliant paths.

Prepare for ePrivacy Regulation (Whenever It Arrives)

The regulation's delay doesn't mean you should ignore its proposed requirements. Draft versions have included:

  • Consent requirements for cookies and similar technologies that align with GDPR's Unambiguous Consent standard.
  • Restrictions on processing electronic communications metadata.
  • Privacy-by-design obligations for software developers.

Configure your Consent Management Platform to support granularity at the vendor level, not just purpose categories. When the regulation passes, you'll need to demonstrate prior consent for each third-party service accessing Terminal Equipment.

Common Pitfalls

Assuming Privacy Shield alternatives are straightforward: Switching from Privacy Shield to standard contractual clauses isn't a simple contract swap. You need the impact assessment, supplementary measures, and documentation proving you've evaluated whether the transfer is lawful.

Treating all EU jurisdictions identically: The CNIL Recommendation requires equal prominence for accept/reject buttons and prohibits pre-ticked boxes. Other member states have different standards. If you operate across multiple countries, your Consent Notice must satisfy the strictest national requirement or implement geo-specific variations.

Relying on "we're waiting for ePrivacy Regulation" as a compliance strategy: Supervisory authorities enforce the current law, the 2002 directive as implemented nationally, plus GDPR. The regulation's delay doesn't create a grace period.

Overlooking the consent-transfer connection: If you're using consent as your Legal Basis for Processing and then transferring that data internationally, both the initial processing and the transfer must meet their respective legal standards. Weak consent doesn't become lawful just because you've signed standard contractual clauses.

Quick Reference Table

Compliance Element Current Requirement Source Status
International transfers Adequacy decision, appropriate safeguards, or derogation GDPR Article 44 Enforceable
Standard contractual clauses Clauses + transfer impact assessment + supplementary measures GDPR Article 46, EDPB Guidelines Enforceable
Privacy Shield Invalidated Schrems II (2020) Not viable
Cookie consent Prior Consent, member state requirements vary National ePrivacy laws Enforceable
ePrivacy Regulation Harmonized Terminal Equipment Access rules Proposed regulation Not yet in force
Transfer impact assessment Required for each destination jurisdiction EDPB Guidelines 01/2020 Enforceable
Consent Management Platform configuration Granularity, Withdrawal of Consent, audit trail GDPR Articles 7, 12-14 Enforceable

The regulatory uncertainty isn't an excuse for inaction. Document your current transfer mechanisms, conduct the required assessments, and build consent infrastructure that can adapt when the ePrivacy Regulation finally passes. Your supervisory authority won't accept "we were waiting for clarity" as a defense when the rules were always clear, they just haven't finished changing yet.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like