If your company is in the EU and your workload runs on AWS, Schrems II is the reason your lawyers care which region you picked and how your data is encrypted. This page explains, in plain English, what the ruling actually requires and the practical technical measures that back it up: EU-region architecture, encryption with keys you control, blocked egress, and the evidence a transfer assessment needs.
HAZERCLOUD provides technical implementation and evidence, not legal advice, and we do not guarantee compliance. Your counsel or Data Protection Officer owns the legal assessment; we build and document the measures that support it.
Architected to stay in the EU.
Schrems II is the Court of Justice of the European Union (CJEU) case C-311/18, decided by judgment of 16 July 2020. Here is what it changed, stated plainly and without spin, because the technical decisions later on only make sense once the ruling does.
Schrems II is the Court of Justice of the European Union (CJEU) case C-311/18, decided by judgment of 16 July 2020. It set the rules that now govern when personal data can leave the EU for a country such as the United States, and it is the reason EU to US transfers get scrutinised.
The judgment invalidated the EU-US Privacy Shield, the framework that many companies had relied on to move personal data to the United States. It stopped being a valid transfer mechanism, and every organisation using it had to fall back on other safeguards.
The court upheld Standard Contractual Clauses but attached conditions. The data exporter must assess, case by case, whether the destination country gives adequate protection, and add supplementary measures where it does not. SCCs on their own are no longer a box to tick.
If you are an EU company using a US cloud provider, you are the data exporter the ruling talks about. You have to be able to show that the data is adequately protected, which is where technical measures such as EU-region hosting and strong encryption come in alongside the contracts.
AWS is a US-headquartered provider, so an EU to AWS transfer of personal data falls squarely under these rules. The good news is that the safeguards are practical and mostly technical. The honest part is that the legal ground has shifted before, so it pays to build as if it could shift again.
The measures below are the ones that make an EU to AWS transfer defensible. Each is concrete, each leaves evidence, and each is chosen to fit your workload rather than applied as a blanket checklist.
We pin your workload to EU regions, for example eu-west-1 in Ireland and eu-central-1 in Frankfurt, and the other EU regions where they suit you better. Region choice is the foundation of data residency, so we make it explicit and enforce it rather than leaving it to a default.
We use service control policies to deny non-EU regions across the whole AWS organisation, and VPC endpoints to keep traffic to AWS services on the private network. The aim is simple: data that should stay in the EU has no quiet path out.
We encrypt with AWS KMS customer-managed keys so the keys, and therefore access to the plaintext, sit with you. Where a workload warrants it, we use external key stores so the key material lives outside AWS entirely, which raises the bar again on who could ever read the data.
We turn on the logging that shows who touched what and when, so access to personal data is recorded and reviewable rather than invisible. That record is both an operational control and part of the evidence a transfer assessment relies on.
Where the workload allows, we separate directly identifying fields from the rest of the data so that what sits in the cloud is harder to tie back to a person on its own. Pseudonymization is a recognised supplementary measure, and it lowers the stakes of any single exposure.
A transfer impact assessment, or TIA, is the documented analysis Schrems II expects before personal data leaves the EU. It is a legal exercise, but it leans heavily on technical facts, and that is exactly what we supply.
A TIA looks at what data is transferred, where it goes, the laws of the destination country, the risk of government access, and the safeguards in place to reduce that risk. It has to conclude, on the specifics, whether protection is adequate and what extra measures are needed.
We produce the technical evidence the assessment needs: which EU regions hold the data, how egress is blocked, how encryption and customer-managed keys are configured, and what the access logs show. Instead of asserting that the data is protected, you can point to how.
We provide the technical evidence; your counsel or Data Protection Officer owns the legal assessment and its conclusion. We are careful about that line, because the value of the evidence depends on the right people drawing the legal conclusion from it.
Plain answers to the questions EU teams actually ask about AWS. The legal calls belong to your counsel or DPO; we handle the technical side and say so wherever the line matters.
Bring your AWS setup and your data residency requirement, and we will walk through the regions, encryption, egress controls, and evidence with you. It is a free scoping call, and you leave with a clear technical picture your counsel or DPO can build the legal assessment on.
★ EU-region architecture · Customer-managed keys · Technical evidence, not legal advice