The honest answer for a DPO
Yes. Sending EU personal data to a US-incorporated provider still carries real legal risk in 2026, even though the EU-US Data Privacy Framework is valid law today. The 2023 adequacy decision stands and the General Court upheld it on 3 September 2025 — but an appeal is now pending at the Court of Justice, the US oversight body the deal leans on has lost its quorum, and a wider challenge is widely expected. Defensible today is not the same as settled.
What Schrems II actually decided
In July 2020 the CJEU struck down Privacy Shield, the framework that came before the DPF, in the case everyone calls Schrems II. The reasoning was narrow and it has aged well. US surveillance law — FISA Section 702 and Executive Order 12333 — lets intelligence agencies compel disclosure from US companies, with no EU-equivalent judicial redress for the people whose data gets caught. A contract between two companies cannot override a statute that sits above the contract.
The same ruling kept Standard Contractual Clauses alive, but bolted a condition onto them that rewired everyone's compliance work. SCCs are only valid if the exporter verifies the destination offers protection "essentially equivalent" to GDPR, and adds supplementary measures where it falls short. That verification is the Transfer Impact Assessment. Before Schrems II it was not a routine obligation. After it, every transfer to a US provider needed one.
The Data Privacy Framework is shakier than it looks
The European Commission adopted a fresh adequacy decision on 10 July 2023, creating the EU-US Data Privacy Framework. If your US provider is DPF-certified, you can transfer on that basis without writing your own SCCs. That is the easy path, and in 2026 it is still in force. Three cracks run through it.
First, the Latombe appeal. French MP Philippe Latombe challenged the DPF; the General Court dismissed him in September 2025, and he appealed to the CJEU on 31 October 2025 (Case C-703/25 P). No hearing date had been set as of May 2026. The CJEU has already invalidated both previous frameworks, and it tends to be far harder to convince than the lower court was.
Second, the oversight body isn't functioning. The Privacy and Civil Liberties Oversight Board — the watchdog the framework relies on to police US signals-intelligence safeguards under Executive Order 14086 — was cut to a single member after the firings in January 2025. It still lacks the quorum it needs to issue reports. The Commission itself named restoring the PCLOB as something the framework's continued functioning depends on.
Third, a broader challenge is coming. Max Schrems and NOYB have signalled a wider action against the DPF, arguing the Latombe case was pitched too narrowly. A "Schrems III" ruling that lands the way the first two did would invalidate the adequacy decision a third time.
None of this makes a DPF transfer illegal today. It means the legal basis you build on in 2026 can be pulled out from under you on a timeline you do not control — the exact surprise that hit every company standardised on Privacy Shield in 2020.
SCCs are not a safe fallback
The reflex after Schrems II was "fine, we'll fall back to SCCs." But SCCs don't escape the problem. They inherit it. If the importer is a US company subject to FISA 702, your Transfer Impact Assessment has to stare down the exact surveillance exposure that sank Privacy Shield. The EDPB's Recommendations 01/2020 set out a six-step method that ends in re-assessing the transfer periodically. A TIA that shrugs and concludes "US law is fine" for a 702-eligible importer is the kind of paperwork that does not survive an audit.
The measure regulators actually rate
Here is the part most "GDPR-compliant" marketing pages skip. The EDPB splits supplementary measures into technical, contractual, and organisational — and it is blunt that contractual and organisational measures on their own usually fail, because a clause cannot stop a lawful government order. The measures it rates as genuinely effective are technical.
The strongest one in the guidance is encryption where the keys stay with the exporter (or an entity in the EEA or an adequate country), the importer cannot decrypt, and the algorithm holds up against a state-level attacker. If the US provider only ever holds ciphertext and never the keys, a FISA 702 order produces encrypted blobs with no way to read them. The exposure that defines the whole Schrems II problem stops being a transfer problem, because nothing readable was transferred.
That is the posture of zero-knowledge storage. Files are sealed on your device before upload; the server stores ciphertext only. We use AES-256-GCM for file data, keys derived with Argon2id from a passphrase that never leaves the device, and BIP39 recovery so you — not the provider — hold the means of access. The full mechanism is on our security page. The honest framing matters: zero-knowledge does not exempt you from GDPR. You still owe a DPA, sub-processor transparency, and a lawful basis for processing. What it does is make the TIA's hardest question — "can the importer be compelled to hand over readable data?" — answerable with "no, by construction."
The cleanest TIA is no transfer at all
Every option above is a way to manage a transfer into US jurisdiction. The simpler move is to not make the transfer. Data stored with a European-incorporated provider on European infrastructure is not a third-country transfer, so Chapter V — DPF, SCCs, TIAs, supplementary measures — does not apply to it at all.
That is how we're built. Beebeeb is operated by Initlabs B.V., a Dutch company (KvK 95157565), with all data stored on dedicated servers in Falkenstein, Germany. No US parent, no US region, no CLOUD Act reach over the operating entity. If you're scoping a replacement for a US tool, our honest EU alternatives breakdown walks through who each option fits and where we're still building — native mobile and desktop apps and cloud import are on the way, not shipped.
A US provider may stay legally usable through 2026. It may not. A Transfer Impact Assessment is only worth writing if it is honest about which risks you've removed and which you're hoping won't fire. Removing the transfer removes the biggest one outright.