Schrems II and your email list — what a transfer outside the EU really requires
The Court of Justice annulled Privacy Shield on 16 July 2020 and left the standard clauses in force with conditions. In 2023 a new adequacy decision took its place, covering only the companies that have joined the list. Here is what each means for a small business choosing an email tool.
An email list is a register of personal data, and the tool that sends to it is a processor of personal data. If the tool moves the list outside the EU, the transfer needs a basis — and around that basis two things have happened that are worth knowing before you choose a tool.
The short answer
A transfer outside the EU is not prohibited. It requires a transfer basis under Chapter V of the GDPR, and the bases come in order of priority: first a Commission adequacy decision, and in its absence, for example, the standard clauses with their supplementary assessment.
The simplest solution is not to transfer. Five of the seven email tools we compare store the list data in the EU, in which case this whole chapter drops out of your own documentation.
What the Schrems II judgment decided
The Court of Justice gave judgment in case C-311/18 on 16 July 2020. Two things were settled at once, and they point in different directions.
- Privacy Shield was annulled. Point five of the operative part is unambiguous: “Commission Implementing Decision (EU) 2016/1250 … is invalid.”
- The standard clauses remained in force. According to point four, the examination of Decision 2010/87 “has disclosed nothing to affect the validity of that decision”.
The practical change, though, was not that one decision was replaced by another. It was the condition the Court set on the use of the standard clauses: the exporter has to ensure that data subjects receive in the destination country “a level of protection essentially equivalent to that guaranteed within the European Union”, and the assessment must also take into account access to the data by the destination country’s authorities. Responsibility thus moved from the Commission’s decision to the exporter itself. The same operative part obliges the supervisory authority to suspend or prohibit a transfer if protection cannot be ensured.
What replaced Privacy Shield
On 10 July 2023 the Commission adopted Implementing Decision (EU) 2023/1795 on the EU–US Data Privacy Framework. One detail decides what the decision means for you: it does not cover the United States as a country.
Article 1 of the decision limits adequacy to transfers “to organisations in the United States that are included in the ‘Data Privacy Framework List’, maintained and made publicly available by the U.S. Department of Commerce”. Adequacy is therefore organisation-specific. In practice this means one work step: when you consider a US service, check whether that specific organisation is on the list — and search by the company’s official name, because the service may be listed under its parent company.
The decision also contains its own unwinding clause. Under Article 3(5) the Commission may “suspend, amend or repeal this Decision, or limit its scope” if an adequate level of protection is no longer ensured.
Is the new decision permanent
There is an honest answer to this: it has already been challenged, and once before a corresponding decision fell. The General Court dismissed the action for annulment on 3 September 2025 in case T-553/23 (Latombe v Commission). According to the Court’s press release, it “confirms that, on the date of adoption of the contested decision, the United States of America ensured an adequate level of protection”.
An appeal to the Court of Justice has been registered (case C-703/25 P, lodged 31 October 2025). We have not checked the state of the proceedings since, and we do not predict the outcome.
For the reader this leads to one practical instruction, not a prediction: do not build anything on the adequacy decision that you cannot unwind. For an email tool that means the list’s portability out of the service is part of risk management — and it is a good requirement anyway.
If the adequacy decision does not cover the service
Then the transfer needs an appropriate safeguard under Article 46 of the GDPR. The most common is the standard contractual clauses approved by the Commission, found in Article 46(2)(c). Paragraph 1 of the article also sets a condition: in addition to the safeguards, data subjects must have “enforceable data subject rights and effective legal remedies”.
Merely signing the clauses is not enough. The European Data Protection Board’s Recommendations 01/2020 (version 2.0, adopted 18 June 2021) describe six steps. Four of them are real work for the exporter, and the fifth is the formal procedures a supplementary measure may require:
- Know your transfers. Map what personal data moves where — the recommendations call this the first step and note that it is often a difficult exercise.
- Check the transfer tool. If a Commission adequacy decision covers the recipient, nothing more is needed than monitoring that the decision remains in force — and for the United States that means the organisation, not the country.
- Assess the destination country’s law and practice. This is the transfer impact assessment: does the legal situation in the destination country undermine the effectiveness of the safeguards in your specific transfer.
- Adopt supplementary measures if the assessment requires them, and re-evaluate at appropriate intervals.
Two points in the recommendations are worth reading verbatim. On documentation: “You should conduct this assessment with due diligence and document it thoroughly. Your competent supervisory and/or judicial authorities may request it and hold you accountable for any decision you take on that basis.” And on the situation where nothing suffices: “In those cases where no supplementary measure is suitable, you must avoid, suspend or terminate the transfer.”
What this means when choosing an email tool
This is where the law turns into a buying decision, and the outcome is simpler than the text above suggests.
Five of the seven tools we compare store the list data in the EU: Brevo, GetResponse, Systeme.io, MailerLite and EmailOctopus. For them no Chapter V transfer basis is needed at all, because there is no transfer. The remaining two, Mailchimp and ActiveCampaign, transfer data outside the EU — lawfully, but with a transfer basis and a record. The situation service by service: email marketing and GDPR; all seven policies side by side and dated: where email tools store their data.
This does not mean a non-EU tool is the wrong choice. It means its price includes a work step that an EU provider’s price does not — and in a one-person business that work step costs more than a few euros’ monthly difference.
Four things a small business should do
- Find out where your list is. The answer is in the service’s own privacy policy, not on the marketing page. Ask for both the contracting party and the location of the data centre — they can be in different countries.
- Record the processor in your own privacy policy. If there is a transfer outside the EU, Article 13(1)(f) requires you to state the transfer and whether an adequacy decision exists or not.
- Put a processing agreement in place. It is a different thing from the transfer basis and is needed in any case, with an EU provider too. What the agreement has to contain.
- If you transfer under the standard clauses, document the assessment. The EDPB’s recommendations say directly that the authority may ask to see it.
The EDPB’s recommendations sum up the same thing briefly: every transfer needs a Chapter V transfer basis, and the effectiveness of that basis and the need for supplementary measures have to be assessed case by case. Recommendations read 6 September 2026.
What this page is not
This is not legal advice. We say what the original sources say, and every one of them is linked in the text: the text of the judgment, the Commission decision, the articles of the regulation and the EDPB’s recommendations. Applying them to your own situation is your job or your lawyer’s.
Nor do we publish individual services’ Data Privacy Framework status. The reason is methodological: the status can change without notice, and our 90-day checking cycle would not guarantee it is current. The list is public, and checking it is faster than reading it from us. The method in full: how we compare.