White Paper
Securing GDPR-compliant Data Post Schrems II
The Schrems II ruling invalidated Privacy Shield and exposed GDPR’s gaps in protecting EU personal data once transferred to non-EU countries. Pages 3 and 6 explain that companies now face liability, stricter EDPB expectations and potential disruption of global data flows if safeguards are not strengthened. The white paper recommends adopting technical supplementary measures, especially encryption with full customer control of keys through BYOK, HYOK or preferably BYOE. Thales supports this with discovery, tokenization, centralized key management, HSMs and strong access controls to maintain sovereignty and ensure compliant cross-border data transfers.
