When encryption is cited as a supplementary measure for cross-border data transfers, its protection depends entirely on who holds the encryption keys and whether they are accessible by parties in the destination jurisdiction.
Why This Matters Now
The post-Schrems II framework for cross-border data transfers introduced the concept of supplementary measures: additional technical, contractual, or organizational controls that organizations should implement when Standard Contractual Clauses alone cannot ensure adequate protection for transfers to third countries with problematic surveillance laws.
Encryption is frequently cited as the primary technical supplementary measure in transfer impact assessments. The logic is intuitive: if data is encrypted, unauthorized access is prevented, and the protection offered to EU data subjects is maintained regardless of the legal environment at the transfer destination. The logic is correct under specific conditions. It fails when those conditions are not met.
Encryption protects data from unauthorized access. It does not protect data from authorized access. When the entity that holds the keys or manages the infrastructure can be compelled to provide access, encryption does not protect against the jurisdictional exposure that supplementary measures are designed to address.
The Governance Problem Beneath the Surface
The governance problem is the conflation of two different security objectives. Encryption effectively addresses one: preventing unauthorized third parties from accessing data. It does not address the other: preventing authorized access by government authorities through legal compulsion of the data holder or processor.
The EDPB's guidance on supplementary measures specifically addresses this distinction. Encryption qualifies as an effective supplementary measure only when the keys are held exclusively by the data exporter or a party outside the jurisdiction of concern, and the importer cannot be compelled to provide access to the decrypted data. Where the importer holds the keys, encryption does not provide effective protection.
What This Actually Means in Enterprise Practice
Vendor-Held Keys Do Not Protect Against Vendor Compulsion
In standard cloud and SaaS deployments, encryption keys are managed by the vendor. The vendor can access the decrypted data as part of normal service delivery. A US government subpoena or FISA order directed at the vendor can compel production of decrypted data regardless of whether the data was encrypted at rest.
Vendor-managed encryption protects against unauthorized external access. It does not protect against authorized access through the vendor, whether by the vendor for service purposes or by government authorities through the vendor.
Customer-Managed Keys (BYOK) Are Partially Effective
Bring Your Own Key arrangements give customers control over encryption keys rather than relying on vendor-managed keys. This provides stronger protection: the vendor cannot access decrypted data without the customer's key.
BYOK is stronger than vendor-managed encryption for jurisdictional protection purposes. It is not a complete solution unless the key management infrastructure is outside the jurisdiction of concern and the customer is not subject to that jurisdiction's legal process.
Application-Layer Encryption Provides Different Protection
Application-layer encryption, where data is encrypted before it leaves the customer's environment and decrypted only within the customer's environment after retrieval, provides stronger jurisdictional protection. The vendor stores encrypted ciphertext and cannot access the plaintext. This approach limits the vendor's ability to provide value-added services that require access to plaintext data.
Transfer Impact Assessments Citing Encryption Must Specify the Conditions
A TIA that cites encryption as a supplementary measure without specifying who holds the keys, the architecture of the key management, and the jurisdictional reach of applicable legal process has not completed the analysis the EDPB recommends. The citation of encryption satisfies documentation requirements but does not assess whether the measure is effective against the specific jurisdictional risk identified.
How Different Teams See This: Where They All Miss
Effective encryption as a supplementary measure requires a joint assessment between legal, security, and cloud engineering that is rarely performed as part of TIA completion.
Framework Control Reference
The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.
These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.
The Enterprise Reality Gap
The enterprise encryption-as-supplementary-measure reality gap is between the protection organizations believe their encryption provides for cross-border transfers and the protection their specific key management architecture actually delivers against jurisdictional access risk.
Encryption cited as a supplementary measure in a TIA completed without assessing key management architecture and jurisdictional reach is documentation of a measure whose effectiveness has not been evaluated.
Enterprise Scenario
The encryption was implemented. The key management architecture meant the encryption provided strong protection against unauthorized external access and no effective protection against authorized access through the vendor. The EDPB's guidance on this scenario is explicit: vendor-managed encryption does not qualify as an effective supplementary measure.
Industry Signal
The European Commission's adequacy decision for the EU-US Data Privacy Framework has reduced but not eliminated the need for transfer mechanisms and supplementary measures for certain EU-US transfers. Organizations that rely on transfers to non-DPF-covered entities continue to need effective supplementary measures. The EDPB guidance on encryption effectiveness remains relevant, and enforcement has begun examining whether cited supplementary measures meet the effectiveness standard.
Adequacy frameworks reduce but do not eliminate supplementary measure requirements. Organizations that have documented vendor-managed encryption as their supplementary measure have a documentation gap that adequacy decisions do not close.
Enabling Capabilities
- Customer-managed key management: BYOK or HYOK arrangements that keep encryption key control with the customer or a trusted third party outside the jurisdiction of concern.
- Application-layer encryption: Encryption architecture where data is encrypted before leaving the customer environment and decrypted only after return, preventing vendor access to plaintext.
- Confidential computing: Processing of encrypted data within secure enclaves that prevent vendor access to plaintext even during processing.
- Data tokenization: Replacement of sensitive data elements with non-sensitive tokens, with the mapping table held in the exporter's jurisdiction.
A Practical Starting Point
Review your existing TIAs that cite encryption as a supplementary measure. For each, document who holds the encryption keys and whether the vendor can access decrypted data in normal operations. Where vendor-managed encryption is cited as a supplementary measure against jurisdictional access risk, the TIA's effectiveness assessment requires updating.
The effectiveness of encryption as a supplementary measure is determined by key management architecture, not by the presence of encryption. Assess the architecture, not just the feature.
Questions Leaders Should Be Asking
- For our TIAs that cite encryption as a supplementary measure, who holds the encryption keys and can the vendor access decrypted data in normal service delivery?
- Have we assessed our encryption implementations against the EDPB's conditions for encryption to qualify as an effective supplementary measure?
- For our highest-risk cross-border transfers, is application-layer encryption or BYOK technically feasible?
- Are any of our TIAs relying on encryption as a supplementary measure while using vendor-managed key architectures where the vendor can be compelled to provide decrypted access?
What to Require From Vendors
Ask directly:
"Can you provide documentation of your key management architecture for our data, confirm whether you can access our data in decrypted form in normal operations, and describe the options available for customer-managed key control?"
Expect as evidence:
- Key management architecture documentation with customer access control options
- BYOK or HYOK capability documentation with scope and limitations
- Documentation of what government access requests you have received and how key management affects your ability to comply
A vendor who confirms encryption implementation without addressing key management architecture and their ability to access decrypted data has confirmed a security feature and not assessed its effectiveness as a supplementary measure.
Demonstrating Diligence
- Documentation: TIA supplementary measure effectiveness assessment with key management architecture analysis; EDPB standard compliance assessment for encryption measures.
- Process: TIA review specifically for supplementary measure effectiveness; BYOK or application-layer encryption feasibility assessment for high-risk transfers.
- Technical evidence: Key management architecture documentation; BYOK implementation records where applicable; encryption effectiveness assessment against EDPB Use Case 1 criteria.
Supplementary measure diligence requires demonstrating that the measures are effective, not just that they are documented.
Closing Perspective
Encryption is a powerful security control and an important component of cross-border data protection architecture. It provides strong protection against the threats it was designed to address: unauthorized access by external actors.
Its limitation as a supplementary measure is specific and important: it does not protect against authorized access through the entity that holds the keys. Understanding this limitation and designing key management architectures that address it is the governance work that TIAs citing encryption as a supplementary measure must complete.
Encryption protects against unauthorized access. Jurisdictional exposure requires protecting against authorized access through the right key architecture. Build the architecture that provides the protection your TIA claims.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
