Schrems II: why EU data shouldn't sit on US servers
The CJEU struck down Privacy Shield and tightened the rules on standard contractual clauses. For AI workloads it means one thing: send personal data to a US-controlled provider and the risk is yours. What Schrems II means in practice - and the only clean way around it.
In July 2020 the Court of Justice of the EU, in the ruling known as Schrems II, invalidated the EU-US Privacy Shield - the framework thousands of companies relied on for transatlantic data transfers. Overnight, the simplest legal basis for sending EU data to the US was gone.
For AI teams this is not a footnote. Every prompt, every training example, every uploaded document can contain personal data. The moment that data reaches a US-controlled service, you are squarely inside the question Schrems II left open.
What Schrems II actually decided
The court found two things. First, US surveillance law (notably FISA 702) gives EU citizens no effective legal remedy, so US protection is not equivalent to the EU's. Second, standard contractual clauses remain valid - but only if the exporter assesses, case by case, whether the destination country really offers equivalent protection, and adds extra measures where it doesn't.
That puts the burden on you, the data exporter. Not the provider, not the regulator. You have to document why the transfer is lawful - and with a provider subject to the CLOUD Act and FISA 702, that case is very hard to make convincingly.
Why an EU region doesn't fix it
Many providers respond with an EU region and an EU subsidiary. That addresses data residency, not control. As long as the parent company is American, it remains compellable under US law regardless of where the servers sit. Schrems II is about that legal reach, not the physical location.
The transfer-impact assessment nobody wants to write
If you keep using a US service, regulators expect a documented risk assessment. They typically look at:
- Which categories of personal data are transferred and how sensitive they are.
- Which surveillance laws the recipient in the third country is subject to.
- Whether technical measures like encryption actually prevent access - which, for live cloud processing, they usually don't.
- Whether data subjects have an enforceable legal remedy.
Encryption at rest helps little when the provider holds the keys and must decrypt the data to process it - which is exactly what AI inference and training require. This is where most assessments fall apart.
The cleanest risk assessment is the one you never have to write, because the data never left EU jurisdiction.
The clean answer: don't transfer at all
Schrems II is complex because the transfer is complex. Remove the third-country transfer and the whole problem disappears - no Privacy Shield, no SCC acrobatics, no transfer-impact assessment. If your AI compute runs on hardware owned by an EU company and governed by EU law, there is no exporter and no third-country importer.
That is the VANAFTER model: servers built in the EU, run in the EU, controlled by an EU company. Your prompts and training data stay inside the jurisdiction your compliance already requires.
What to do now
- Inventory which AI services process personal data and who controls them.
- Flag every US-controlled provider as a transfer - regardless of region.
- Move sensitive workloads onto infrastructure owned and governed in the EU.
- Document the decision - here, the clean version is the short one.
Sovereignty is not a feature you bolt on. It is a property of who owns the machine and which law governs it. Schrems II simply made that visible to everyone else.
Ready to own your AI compute?
Browse servers →