The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative assessment. It also outlines potential GDPR fines of €20 million or 4% of global turnover for non‑compliant transfers.
Why it matters: It helps EU controllers avoid hefty GDPR penalties by complying with the CJEU’s Schrems II ruling on trans‑Atlantic data transfers.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.