Scope
This guide addresses the compliance gap created by the ePrivacy Regulation's delay and the shifting legal landscape for international data transfers following Schrems II. If your team manages cross-border data flows, cookie consent infrastructure, or relies on standard contractual clauses, you're operating in a regulatory environment where promised clarity hasn't materialized.
We'll cover what's enforceable today, what remains uncertain, and how to structure your data transfer documentation when the rules keep changing.
Key Concepts and Definitions
ePrivacy Regulation: The EU's proposed update to electronic communications privacy rules, intended to harmonize with GDPR. Originally expected to pass alongside GDPR in 2018, it remains stalled. Until it passes, the 2002 ePrivacy Directive remains in force, creating inconsistent national implementations across member states.
Schrems II: The European Court of Justice case (Case C-311/18) that examined whether Privacy Shield and standard contractual clauses provide adequate safeguards for EU-to-US data transfers. The ruling invalidated Privacy Shield and imposed additional assessment requirements for standard contractual clauses.
Standard Contractual Clauses: Pre-approved contract terms issued by the European Commission that establish data protection obligations for international transfers. Post-Schrems II, these clauses alone aren't sufficient, you must conduct transfer impact assessments for each destination jurisdiction.
Privacy Shield: A framework that allowed certified US companies to receive personal data from the EU. Invalidated by the Schrems II ruling in July 2020, rendering thousands of existing data transfer arrangements non-compliant overnight.
Requirements Breakdown
What You Must Comply With Today
GDPR Article 44: All international transfers require an adequacy decision, appropriate safeguards (like standard contractual clauses), or a valid derogation. The "appropriate safeguards" bar has been raised.
GDPR Article 46: If you're using standard contractual clauses, you now need supplementary measures. The EDPB Guidelines on these measures weren't published until June 2021, but supervisory authorities expect you to have implemented them retroactively.
National ePrivacy Laws: Each EU member state has its own implementation of the 2002 ePrivacy Directive. France's Loi Informatique et Libertés, for instance, has specific cookie consent requirements that differ from Germany's Telemedia Act. You're bound by the law of each jurisdiction where you operate, not by the still-pending ePrivacy Regulation.
What Remains Undefined
The ePrivacy Regulation was supposed to resolve inconsistencies in Terminal Equipment Access rules, cookie consent requirements, and electronic marketing practices. Without it, you're navigating 27 different national interpretations. The CNIL Recommendation provides one model, but it's not binding on other member states.
Implementation Guidance
Audit Your Current Transfer Mechanisms
Start with an inventory. For each data flow leaving the EU:
- Document the Legal Basis for Processing (Article 6) and the transfer mechanism (Article 46 or 49).
- If you relied on Privacy Shield, that mechanism is void, identify replacement safeguards.
- For standard contractual clauses, conduct a transfer impact assessment examining the destination country's surveillance laws, data access procedures, and available legal remedies.
Structure Your Transfer Impact Assessments
Your assessment should address:
- What categories of data you're transferring and why.
- The legal regime in the destination country, including government access powers.
- Technical measures you've implemented (encryption in transit and at rest, pseudonymization, data minimization).
- Contractual measures beyond the standard clauses (audit rights, breach notification timelines, data deletion guarantees).
If your assessment concludes that the destination country's laws undermine the clauses, you cannot proceed with that transfer. Suspending the transfer or implementing additional safeguards are your only compliant paths.
Prepare for ePrivacy Regulation (Whenever It Arrives)
The regulation's delay doesn't mean you should ignore its proposed requirements. Draft versions have included:
- Consent requirements for cookies and similar technologies that align with GDPR's Unambiguous Consent standard.
- Restrictions on processing electronic communications metadata.
- Privacy-by-design obligations for software developers.
Configure your Consent Management Platform to support granularity at the vendor level, not just purpose categories. When the regulation passes, you'll need to demonstrate prior consent for each third-party service accessing Terminal Equipment.
Common Pitfalls
Assuming Privacy Shield alternatives are straightforward: Switching from Privacy Shield to standard contractual clauses isn't a simple contract swap. You need the impact assessment, supplementary measures, and documentation proving you've evaluated whether the transfer is lawful.
Treating all EU jurisdictions identically: The CNIL Recommendation requires equal prominence for accept/reject buttons and prohibits pre-ticked boxes. Other member states have different standards. If you operate across multiple countries, your Consent Notice must satisfy the strictest national requirement or implement geo-specific variations.
Relying on "we're waiting for ePrivacy Regulation" as a compliance strategy: Supervisory authorities enforce the current law, the 2002 directive as implemented nationally, plus GDPR. The regulation's delay doesn't create a grace period.
Overlooking the consent-transfer connection: If you're using consent as your Legal Basis for Processing and then transferring that data internationally, both the initial processing and the transfer must meet their respective legal standards. Weak consent doesn't become lawful just because you've signed standard contractual clauses.
Quick Reference Table
| Compliance Element | Current Requirement | Source | Status |
|---|---|---|---|
| International transfers | Adequacy decision, appropriate safeguards, or derogation | GDPR Article 44 | Enforceable |
| Standard contractual clauses | Clauses + transfer impact assessment + supplementary measures | GDPR Article 46, EDPB Guidelines | Enforceable |
| Privacy Shield | Invalidated | Schrems II (2020) | Not viable |
| Cookie consent | Prior Consent, member state requirements vary | National ePrivacy laws | Enforceable |
| ePrivacy Regulation | Harmonized Terminal Equipment Access rules | Proposed regulation | Not yet in force |
| Transfer impact assessment | Required for each destination jurisdiction | EDPB Guidelines 01/2020 | Enforceable |
| Consent Management Platform configuration | Granularity, Withdrawal of Consent, audit trail | GDPR Articles 7, 12-14 | Enforceable |
The regulatory uncertainty isn't an excuse for inaction. Document your current transfer mechanisms, conduct the required assessments, and build consent infrastructure that can adapt when the ePrivacy Regulation finally passes. Your supervisory authority won't accept "we were waiting for clarity" as a defense when the rules were always clear, they just haven't finished changing yet.





