01. Transfers without an adequate basis
Continued reliance on Standard Contractual Clauses (SCCs) post-Schrems II without sufficient supplementary measures.
The largest GDPR fine on record: Meta was fined €1.2 billion by the Irish DPC for transferring EU user data to the US without an adequate legal basis after Schrems II — a structural reminder that international data transfers are still GDPR's hardest problem.
Last updated
Technical failure modes
Continued reliance on Standard Contractual Clauses (SCCs) post-Schrems II without sufficient supplementary measures.
The TIA — the document the EDPB expects every transfer to have — was either missing or insufficient for the volume of data involved.
The technical and organizational measures in place did not meaningfully limit US authorities' access to the transferred data.
Hundreds of millions of EU users meant the violation reached the upper bound of GDPR penalty exposure.
Remediation path
More enforcement analysis
Next step
The Meta decision is the marker case for international data transfers. SCCs alone are not enough; the Schrems II analysis requires real, documented assessments of US surveillance law and additional safeguards. The Data Privacy Framework changes the picture for some transfers, but not all of them — and not retroactively.
Get started in less than 5 min