TLDR: Your Google Analytics setup might be illegal in the EU—Austrian and French DPAs have already ruled against it. The EU-US Data Privacy Framework helps, but only if your vendors are DPF-certified. Check them all. Today.
Read full summary
Post-Schrems II guide to cross-border data transfers for CMP implementations. Covers the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs), Transfer Impact Assessments (TIAs), and vendor due diligence requirements. Essential reading for organizations using US-based analytics, advertising, or cloud providers.
*Summary by Claude AI*
## The 101 Websites That Became Instantly Illegal
In January 2022, the Austrian DPA ruled that a website's use of Google Analytics violated GDPR—not because of how they used it, but because data was being transferred to the US without adequate protection. The ruling triggered a cascade: the French CNIL followed weeks later, then Italy. NOYB had filed 101 identical complaints across EU member states.
The websites weren't doing anything unusual. They had cookie consent. They had privacy policies. They were using the same analytics setup as millions of other sites. But after Schrems II invalidated Privacy Shield, those routine data transfers became GDPR violations.
The EU-US Data Privacy Framework (adopted July 2023) provides a path forward—but only for vendors who self-certify. If your CMP integrates with US vendors who aren't DPF-certified, you're back to SCCs and Transfer Impact Assessments. Do you know which of your 47 tracking vendors are certified?
## Cross-Border Data Transfers post-Schrems II: Navigating the EU-U.S. Data Privacy Framework and SCCs for Your CMP
The landscape of cross-border data transfers, particularly from the EU/EEA, has been dramatically reshaped by the European Court of Justice (CJEU) "Schrems II" ruling in July 2020. This decision invalidated the EU-US Privacy Shield and imposed stricter requirements on organizations transferring personal data outside the EU/EEA.
However, as of **July 2023, the EU-U.S. Data Privacy Framework (DPF)** came into force, creating a new, primary mechanism for legally transferring personal data from the EU/EEA to certified U.S. organizations. For businesses relying on Consent Management Platforms (CMPs) that engage third-party vendors, understanding how the DPF interacts with existing mechanisms like Standard Contractual Clauses (SCCs) is paramount for compliance.
### The Impact of Schrems II and the Rise of the DPF
The **Schrems II** judgment affirmed that when data leaves the EU/EEA, it must continue to benefit from an essentially equivalent level of protection as guaranteed by the GDPR. The CJEU expressed concerns that U.S. surveillance laws (like FISA 702) could undermine the protection of EU data, even when transferred under legally binding mechanisms.
This led to a period of uncertainty, making Standard Contractual Clauses (SCCs) the default transfer tool, but with a new caveat: organizations had to conduct a **Transfer Impact Assessment (TIA)** to evaluate the recipient country's legal framework and implement supplementary measures if necessary.
The **EU-U.S. Data Privacy Framework (DPF)** emerged as the solution to this challenge. It addresses the CJEU's concerns by implementing new binding safeguards to protect personal data, such as limiting access by U.S. intelligence authorities and establishing a Data Protection Review Court (DPRC).
### What this Means for Your CMP and Third-Party Vendors in 2025
Your CMP is at the forefront of managing user consent for data processing, including transfers to third-party vendors. In 2025, due diligence for these vendors, especially those based outside the EU/EEA, is critical.
**Key considerations for your CMP and vendor management:**
1. **Prioritize the EU-U.S. Data Privacy Framework (DPF)**:
* For transfers to the U.S., check if your U.S.-based vendors (e.g., analytics, advertising, cloud providers) are **certified under the DPF**. You can verify their status on the official Data Privacy Framework Program website.
* If a vendor is DPF-certified, data transfers to them are now generally considered legal without requiring additional SCCs or TIAs for those transfers. This significantly simplifies the compliance burden.
2. **Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs)**:
* **SCCs remain crucial for other transfers**: For transfers to countries *without an adequacy decision* (and not covered by the DPF, like most other non-EU/EEA countries), SCCs remain the primary legal mechanism.
* **TIAs are still required with SCCs**: When relying on SCCs, organizations must still conduct a **Transfer Impact Assessment (TIA)**. This involves:
* **Assessing recipient country laws**: Evaluate if the laws in the data-importing country could undermine GDPR-equivalent protection (e.g., surveillance laws).
* **Implementing supplementary measures**: If risks are identified, implement additional safeguards (e.g., strong encryption, anonymization techniques, contractual clauses requiring legal challenges to government access requests).
* **SCCs as a DPF fallback**: Some organizations maintain SCCs alongside DPF certification as a redundant safeguard, ensuring transfers remain compliant even if DPF status changes.
3. **Vendor Due Diligence**:
* **Location of Data Processing**: Identify where each third-party vendor (and their sub-processors) processes and stores data.
* **Legal Basis for Transfer**: Confirm the legal mechanism used for international transfers (DPF, SCCs, Binding Corporate Rules (BCRs), adequacy decisions).
* **Recipient Country Laws**: For SCCs, critically assess the laws of the recipient country.
4. **Transparency via CMP**:
* Your CMP must inform users about cross-border data transfers to third countries. This includes specifying the countries involved and the transfer mechanisms used (DPF, SCCs).
* The cookie declaration provided by your CMP should clearly list all vendors and their data processing locations.
5. **Consent and Vendor Mapping**:
* Ensure your CMP accurately categorizes vendors and their purposes. Users should explicitly consent to the transfer of their data for specific purposes, especially if a vendor is not covered by DPF or an adequacy decision.
* If a TIA concludes that equivalent protection cannot be ensured (even with supplementary measures), you may need to reconsider using that vendor or implement alternative solutions.
### EDPB guidance and real-world controls
The European Data Protection Board (EDPB) continues to emphasize accountability and transparency. While the DPF provides a robust framework, the general principles of the Schrems II ruling (ensuring equivalent protection) still guide transfers outside the DPF scope. For U.S.-based ad-tech and analytics, DPF certification is now the preferred route. If relying on SCCs for other transfers, encryption in transit and at rest, paired with data minimization and pseudonymization before export, remain common supplementary measures. Keep a record of these controls so your CMP’s vendor listings align with what your security team has actually implemented.
## Where to focus now
The DPF has significantly streamlined EU-U.S. data transfers, but the general principles stemming from Schrems II still apply to global data flows. Your CMP is the visible layer that explains to users where data goes, but it must be backed by solid vendor due diligence. Prioritize DPF certification for U.S. vendors. For all other international transfers, conduct robust TIAs when relying on SCCs. That discipline prevents unpleasant surprises during audits and helps you keep marketing stacks running without breaching EU transfer rules.