A More Stable Path for Cross-Border Data Transfers

The digital economy depends on the ability to move personal data across borders. The Internet's open architecture has enabled global trade and innovation, but recent years have seen a trend toward data localization and new barriers to international flows. These restrictions often stem from concerns about privacy protections in third countries, national security interests, or economic self-determination. Yet, as noted in our prior analysis, localizing data does not automatically make it more private—in some cases, it can reduce security and privacy by limiting access to better-protected services abroad.

Complications Under the GDPR

Since the 2020 Schrems II ruling by the European Court of Justice, EU data controllers transferring personal data to the US have faced a complicated compliance landscape. The court suspended the Privacy Shield framework, leaving EU standard contractual clauses (SCCs) and additional safeguards as the primary legal mechanisms. The European Data Protection Board has confirmed that EU personal data can still be processed in the US, but the practical burden is significant. With 45 data protection authorities across Europe, each interpreting the law in its own way, a case-by-case approach simply does not scale. Even within Germany, DPAs have reached differing conclusions on third-country transfers.

Litigation remains slow and resource-intensive, favoring organizations with deep pockets. For smaller companies, the mere threat of a large fine from a DPA may be enough to stop using services that involve cross-border transfers—even when those services offer better security and privacy than local alternatives. This outcome harms the European economy without delivering meaningful privacy gains, a result that was unlikely intended when the GDPR was adopted in 2016.

Two Steps Toward Certainty

Progress has been made at the international policy level. In December 2022, two significant milestones brought some relief.

First, on December 13, the European Commission published its preliminary adequacy assessment for the future EU-US Data Privacy Framework (DPF). The assessment follows US President Biden's signing of Executive Order 14086, which addresses the ECJ's Schrems II concerns. The order limits US authorities' use of bulk surveillance against non-US citizens and creates an independent redress mechanism for EU data subjects. The ratification process is expected to take four to six months, and experts are optimistic about its adoption.

Second, one day later, the US, the European Union, and 37 OECD countries adopted a first-of-its-kind agreement on government access to personal data. The declaration articulates joint principles for privacy safeguards when governments access data held by private entities for national security and law enforcement purposes. Where legal frameworks like the GDPR require safeguards for transborder flows, participants agreed to consider a destination country's implementation of these principles as a positive factor. The declaration also reaffirms a commitment to a "global, open, accessible, interconnected, interoperable, reliable and secure Internet."

The Limits of Current Frameworks

Both the DPF and the OECD Declaration are valuable, but each has limitations. The DPF applies only to EU-US transfers and remains vulnerable to legal challenge—privacy activists have already signaled plans to contest it. The OECD Declaration is global in scope, but only sets general principles for governments; how those principles operate in practice can vary widely.

What is needed is a stable multilateral framework with specific, binding privacy requirements that cannot be invalidated unilaterally. Such a framework should allow a single global certification to cover transfers between all participating countries. The emerging Global Cross Border Privacy Rules (CBPR) certification, supported by several governments in North America and Asia, is a promising candidate.

European policymakers face a choice. They can press on with the current fragmented approach, which risks leaving the EU isolated as a "data island." Or they could revise the GDPR to reduce the interpretive variability among national and regional DPAs, and make it interoperable with a global framework built on shared values and mutual trust. The latter path would better serve both privacy and the economy—something worth considering as Data Privacy Day prompts reflection on how regulations can meaningfully protect users, particularly through security and privacy-enhancing technologies rather than prohibitive measures that carry no tangible benefit.