Module 38 of 52 · Privacy and protection

Data protection law

30 min 3 outcomes Interactive + terminal 10 references

By the end of this module you will be able to:

  • Identify the correct GDPR lawful basis for a given data processing activity
  • Explain Schrems II, adequacy, the EU-US Data Privacy Framework, the UK Extension, and transfer risk assessment
  • Apply the accountability principle to design a compliance-by-design data architecture

Meta fined €1.2 billion for transferring EU user data to the US without adequate safeguards

In May 2023, the Irish Data Protection Commission (DPC) issued the largest GDPR fine in history: €1.2 billion against Meta Platforms Ireland, plus an order to suspend data transfers from the EU to the US within 5 months. The root issue was Schrems II.

In July 2020, the Court of Justice of the European Union (CJEU) invalidated the EU-US Privacy Shield framework in the Schrems II ruling. The court found that US surveillance law (particularly FISA Section 702 and Executive Order 12333) did not provide EU citizens with equivalent protections to those guaranteed under EU law. Standard Contractual Clauses (SCCs) remained valid in principle, but a controller had to assess whether the recipient country's law and practice undermined the safeguards in the clauses.

Meta continued transferring data using SCCs and supplementary measures that the DPC found did not address the risks identified by the CJEU. The current decision path is different from a blanket SCC answer: check for adequacy first, use the EU-US Data Privacy Framework or UK Extension only where the US recipient is actively certified and eligible, and use SCCs, the UK Addendum or an IDTA with a transfer risk assessment where no adequacy route applies. Meta's €1.2 billion fine remains a landmark demonstration that international transfer compliance has direct financial consequences.

Meta processed EU user data on US servers under Standard Contractual Clauses. The Irish DPC ruled these clauses were insufficient because US surveillance law (FISA 702) meant EU data was not adequately protected. What current decision path should an organisation apply before transferring personal data across jurisdictions?

Privacy compliance begins before data is collected: the controller must know the purpose, lawful basis, data categories, recipients, retention rule, and risk controls.

25.1 UK GDPR: seven lawful bases for processing

UK GDPR Article 6 requires every personal-data processing activity to have a lawful basis. The controller must identify and document the basis before processing begins; switching bases after the fact is not permitted. ICO guidance now lists seven UK lawful bases after the Data (Use and Access) Act 2025 introduced recognised legitimate interests:

  • Consent (Article 6(1)(a)): The data subject has given freely given, specific, informed, and unambiguous consent. Consent must be as easy to withdraw as to give. Consent is appropriate for marketing emails, optional analytics, and personalisation. It is the weakest basis because it can be withdrawn at any time.
  • Contract (Article 6(1)(b)): Processing is necessary for the performance of a contract with the data subject, or to take pre-contractual steps. Delivering an order to the address provided is processing under contract. Behavioural advertising is not: Meta's €390M fine (January 2023) arose from claiming advertising was necessary for the social media service contract.
  • Legal obligation (Article 6(1)(c)): Processing is required by law. Tax reporting, anti-money laundering checks, and employment records are examples. Legal obligation overrides erasure requests.
  • Vital interests (Article 6(1)(d)): Processing is necessary to protect someone's life. Sharing a patient's blood type with emergency services. Intended as a last resort when the subject cannot consent.
  • Public task (Article 6(1)(e)): Processing is necessary for a public authority to perform a statutory function. NHS patient records for treatment, HMRC tax assessments, police investigations.
  • Recognised legitimate interests (Article 6(1)(ea)): Processing is necessary for a narrow public-interest purpose pre-approved in UK law, such as responding to emergencies or safeguarding vulnerable people. The controller does not carry out the ordinary legitimate-interests balancing test, but must still show the processing fits the recognised purpose and remains necessary and proportionate.
  • Legitimate interests (Article 6(1)(f)): The controller has a legitimate interest that is not overridden by the rights and interests of the data subject, after a documented balancing test. Available to private sector organisations; not available to public authorities acting in an official capacity. Fraud prevention, network security monitoring, and direct marketing to existing customers are common legitimate interest use cases.

The seven bases are not a ladder. ICO guidance says there is no hierarchy and no basis is always safer than another. The correct basis follows the purpose, the controller's role, the data subject's reasonable expectations, and the legal context.

A lawful basis allows processing, but international transfer rules decide whether personal data may cross legal boundaries and under what safeguards.

The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).

UK GDPR, Article 5(2) - Article 5(2) - the accountability principle

The accountability principle is the foundation of GDPR compliance. It is not enough to comply; the controller must be able to demonstrate compliance through records of processing activities, privacy impact assessments, data protection policies, staff training logs, and contractual evidence. In an enforcement investigation, the ICO or DPC will ask for documentation. Organisations without records cannot demonstrate compliance even if they are in fact compliant.

Loading interactive component...

25.2 International transfers: adequacy and the Schrems II transfer test

Transferring personal data from the EU to a country outside the European Economic Area (EEA) requires an adequacy decision or an alternative transfer mechanism. The European Commission adopted UK adequacy decisions in 2021 and renewed the UK GDPR and law-enforcement adequacy decisions on 19 December 2025. For countries, sectors, or recipients not covered by adequacy, controllers must use appropriate safeguards such as SCCs, BCRs, or a limited derogation.

Standard Contractual Clauses (SCCs) are pre-approved contract terms that impose GDPR-equivalent obligations on the data importer. Following Schrems II (July 2020), using SCCs alone is insufficient: the controller must conduct a Transfer Impact Assessment (TIA) analysing whether the recipient country's surveillance law allows the importing organisation to honour the SCC commitments. If the law does not, supplementary technical measures (such as end-to-end encryption where the importer holds no keys) may be required.

Knowing that a transfer needs a lawful route is not the same as picking one, so the next section walks through the routes on offer and when each of them fits.

25.3 Choosing a transfer route: the Data Privacy Framework, the UK Extension and BCRs

The EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023, created an adequacy route for US organisations that self-certify and maintain active status under the DPF. The UK Extension, also called the UK-US data bridge, allows UK and Gibraltar organisations to transfer personal data to eligible US businesses that participate in the DPF and have opted into the UK Extension. The ICO warns that organisations must check active status, data type coverage, and extra requirements for HR, special category, and criminal offence data.

Binding Corporate Rules (BCRs) provide a third mechanism for multinational organisations to transfer data internally across countries. BCRs require approval from a lead supervisory authority and apply to all entities within the corporate group. They are usually a strategic investment for large organisations with repeated intra-group transfers, not a quick fix for a single vendor integration.

Worked example: a UK analytics team wants to send customer events to a US vendor. If the vendor has active DPF status and opted into the UK Extension for the relevant data type, the team may rely on the UK Extension while still meeting UK GDPR principles. If not, the team needs an IDTA or UK Addendum to SCCs, a transfer risk assessment, encryption and access controls matched to the risk, and records showing why the transfer remains lawful.

Transfer rules are only one part of the control environment; operating across UK and EU markets also brings domestic data protection reform.

Common misconception

Encrypting data before transferring it to a US cloud provider fully resolves Schrems II compliance concerns.

Encryption reduces risk but does not automatically resolve the transfer concern. The key question is: who holds the encryption keys? If the US cloud provider holds the keys, US surveillance authorities can compel access to the decrypted data, which means the transfer may still undermine the SCC commitments. The only technical measure that fully addresses Schrems II is end-to-end encryption where the EU-based controller retains all encryption keys and the US processor cannot access plaintext. This rules out most standard cloud services in their default configurations.

25.4 UK GDPR divergence after Brexit and the Data (Use and Access) Act 2025

Following Brexit, the UK GDPR became part of domestic law as retained EU legislation under the European Union (Withdrawal) Act 2018, and it is published separately from the Data Protection Act 2018, which supplements it rather than containing it. The two regimes have since diverged: the Data (Use and Access) Act 2025 replaced Article 22 with Articles 22A to 22D, added a seventh lawful basis, rewrote the international transfer route, omitted Article 89 and inserted Articles 84A and 84B. UK organisations must therefore consider two separate and no longer interchangeable regimes: EU GDPR applies to processing related to EU residents, and UK GDPR to processing related to UK residents.

The Data (Use and Access) Act 2025 made targeted divergence from EU GDPR, all of it now in force. ICO guidance highlights recognised legitimate interests, changes to automated decision-making, cookie rule changes for specified low-risk purposes, and new research and reuse provisions. For significant automated decisions using personal information, the Act opens the full range of lawful bases where safeguards continue to apply, but special category data remains more protected. UK organisations should monitor ICO guidance rather than assuming UK GDPR and EU GDPR remain aligned.

Domestic reform is only half of the picture for an organisation working on both sides of the Channel; the next section turns to the EU cybersecurity duties that land on entities inside their scope.

25.5 NIS2 duties for in-scope essential and important entities

NIS2 is an EU directive, not a general UK statute. It matters to organisations established in EU Member States, entities that meet the directive's scope tests, and UK-headquartered groups with in-scope EU operations or services. Essential and important entities must implement proportionate security measures, manage supply-chain risk, and report significant incidents to the relevant national CSIRT or competent authority within 24 hours as an early warning and within 72 hours as a fuller incident notification. Management bodies have explicit governance duties and can face Member State enforcement where national transposition law applies.

25.6 Check your understanding

A retail company wants to send promotional emails about new products to customers who have previously purchased. The marketing team argues this is legitimate interests; the legal team argues consent is required. Under GDPR, which is correct?

Following the Schrems II ruling, a UK fintech transfers customer personal data to a US data analytics partner under updated SCCs. The DPO has not yet conducted a Transfer Impact Assessment. What risk does the organisation face?

A healthcare data platform operating in an EU Member State is in scope of NIS2 as an essential entity. It experiences a ransomware attack at 09:00 on Monday. By when must it make its early warning to the national competent authority or CSIRT, and what must that notification contain?

Loading interactive component...
Loading interactive component...

Core checks before moving on

  • Every UK GDPR processing activity needs a lawful basis documented before processing begins: consent, contract, legal obligation, vital interests, public task, recognised legitimate interests, or legitimate interests.
  • International transfers need adequacy or safeguards. The UK adequacy decisions were renewed on 19 December 2025, and the EU-US DPF and UK Extension work only for participating US organisations with active certification.
  • Schrems II means SCCs still require transfer risk analysis and, where necessary, supplementary technical measures that actually prevent access to plaintext data.
  • The accountability principle requires evidence: RoPA, DPIAs, lawful-basis records, transfer assessments, processor contracts, training logs, and review dates.
  • NIS2 should be scoped carefully. It is an EU directive for in-scope essential and important entities, including UK groups where their EU operations or services fall within Member State implementing law.

Standards and sources cited in this module

  1. GDPR Regulation (EU) 2016/679

    Full text of the regulation including Article 6 (lawful bases), Article 5(2) (accountability), Article 30 (RoPA), Article 35 (DPIA), and Article 46 (international transfer mechanisms).

  2. CJEU, Data Protection Commissioner v Facebook Ireland (Schrems II), Case C-311/18 (July 2020)

    Landmark ruling invalidating Privacy Shield and establishing the TIA requirement for SCCs-based transfers.

  3. European Commission adequacy decisions

    Current official source for EU adequacy decisions, including UK adequacy renewal on 19 December 2025 and the EU-US Data Privacy Framework adequacy decision.

  4. ICO: UK Extension to the EU-US Data Privacy Framework

    Practical UK guidance on active DPF status, eligible US businesses, HR data, special category data, and periodic checks.

  5. GOV.UK: UK-US data bridge supporting documents

    Official UK source for the UK Extension effective from 12 October 2023 and the data bridge mechanism.

  6. Irish DPC Decision on Meta Platforms Ireland (May 2023)

    Source for the EUR1.2 billion fine, the suspension order, and the finding that Meta's transfer safeguards did not address Schrems II risks.

  7. ICO: Data (Use and Access) Act 2025 guidance

    Current ICO guidance on recognised legitimate interests, automated decision-making, cookies, and research reuse under DUAA 2025.

  8. NIS2 Directive (EU) 2022/2555

    Full text of NIS2 including the notification timeline (Article 23) and the expanded scope of essential and important entities.

  9. ENISA: NIS2 incident reporting

    Official EU cybersecurity agency summary of the 24-hour early warning and 72-hour incident notification structure.

  10. UK ICO: Lawful basis for processing

    Practical guidance on choosing and documenting the lawful basis under UK GDPR, including the Legitimate Interests Assessment checklist.

Module 38 of 52 · Privacy and protection