Schrems II and AWS

EU data residency on AWS, done properly.

If your company is in the EU and your workload runs on AWS, Schrems II is the reason your lawyers care which region you picked and how your data is encrypted. This page explains, in plain English, what the ruling actually requires and the practical technical measures that back it up: EU-region architecture, encryption with keys you control, blocked egress, and the evidence a transfer assessment needs.

HAZERCLOUD provides technical implementation and evidence, not legal advice, and we do not guarantee compliance. Your counsel or Data Protection Officer owns the legal assessment; we build and document the measures that support it.

Transfer safeguardsEU-RESIDENT

Architected to stay in the EU.

EU regionsIreland, Frankfurt
Customer keysKMS you control
SCCsContractual basis
DPFCurrent mechanism
EgressBlocked outbound
TIAEvidence produced
The Ruling

What Schrems II is, in plain English.

Schrems II is the Court of Justice of the European Union (CJEU) case C-311/18, decided by judgment of 16 July 2020. Here is what it changed, stated plainly and without spin, because the technical decisions later on only make sense once the ruling does.

01 · THE CASE

A court ruling on data transfers

Schrems II is the Court of Justice of the European Union (CJEU) case C-311/18, decided by judgment of 16 July 2020. It set the rules that now govern when personal data can leave the EU for a country such as the United States, and it is the reason EU to US transfers get scrutinised.

CJEUC-311/1816 July 2020
02 · PRIVACY SHIELD

Why Privacy Shield ended

The judgment invalidated the EU-US Privacy Shield, the framework that many companies had relied on to move personal data to the United States. It stopped being a valid transfer mechanism, and every organisation using it had to fall back on other safeguards.

Privacy ShieldInvalidated
03 · SCCs

SCCs upheld, with conditions

The court upheld Standard Contractual Clauses but attached conditions. The data exporter must assess, case by case, whether the destination country gives adequate protection, and add supplementary measures where it does not. SCCs on their own are no longer a box to tick.

SCCs upheldCase by caseSupplementary measures
04 · WHAT IT MEANS

Using a US cloud from the EU

If you are an EU company using a US cloud provider, you are the data exporter the ruling talks about. You have to be able to show that the data is adequately protected, which is where technical measures such as EU-region hosting and strong encryption come in alongside the contracts.

Data exporterAdequate protectionTechnical measures
AWS Workloads

What it means for AWS workloads.

AWS is a US-headquartered provider, so an EU to AWS transfer of personal data falls squarely under these rules. The good news is that the safeguards are practical and mostly technical. The honest part is that the legal ground has shifted before, so it pays to build as if it could shift again.

The practical stack

Safeguards that actually hold

  • EU-region-only architecture so personal data is stored and processed inside the EU by design, not by default.
  • Encryption with keys the customer controls through AWS KMS, so the data is unreadable without keys you hold.
  • Contractual safeguards in the form of Standard Contractual Clauses, backed by the EU-US Data Privacy Framework as the current transfer mechanism.
  • Egress controls that stop data quietly flowing to regions or services outside the EU.
The honest position

Why we still over-engineer it

  • The EU-US Data Privacy Framework adequacy decision was adopted on 10 July 2023 and is the current mechanism for certified US companies.
  • It is a real, lawful basis today, and we do not pretend otherwise.
  • Two earlier frameworks, Safe Harbor and Privacy Shield, were struck down by the courts.
  • So cautious teams architect as if the framework could be struck down too, keeping the data in the EU and the keys in their own hands regardless.
The framework gives you a lawful basis today; the architecture gives you a position that survives if the basis changes tomorrow. We build both, so a future ruling is a paperwork update for your lawyers rather than a scramble to re-home your data.
Technical Measures

What we actually implement.

The measures below are the ones that make an EU to AWS transfer defensible. Each is concrete, each leaves evidence, and each is chosen to fit your workload rather than applied as a blanket checklist.

01 · REGIONS

EU region selection

We pin your workload to EU regions, for example eu-west-1 in Ireland and eu-central-1 in Frankfurt, and the other EU regions where they suit you better. Region choice is the foundation of data residency, so we make it explicit and enforce it rather than leaving it to a default.

eu-west-1eu-central-1Data residency
02 · EGRESS

Blocking data egress outside the EU

We use service control policies to deny non-EU regions across the whole AWS organisation, and VPC endpoints to keep traffic to AWS services on the private network. The aim is simple: data that should stay in the EU has no quiet path out.

Service control policiesVPC endpointsRegion deny
03 · KEYS

KMS with customer-managed keys

We encrypt with AWS KMS customer-managed keys so the keys, and therefore access to the plaintext, sit with you. Where a workload warrants it, we use external key stores so the key material lives outside AWS entirely, which raises the bar again on who could ever read the data.

KMSCustomer-managed keysExternal key store
04 · LOGGING

Logging and access transparency

We turn on the logging that shows who touched what and when, so access to personal data is recorded and reviewable rather than invisible. That record is both an operational control and part of the evidence a transfer assessment relies on.

CloudTrailAccess logsAuditable
05 · PSEUDONYMIZATION

Pseudonymization where it fits

Where the workload allows, we separate directly identifying fields from the rest of the data so that what sits in the cloud is harder to tie back to a person on its own. Pseudonymization is a recognised supplementary measure, and it lowers the stakes of any single exposure.

Field separationTokenisationSupplementary measure
Transfer Impact Assessment

TIA support, the evidence side.

A transfer impact assessment, or TIA, is the documented analysis Schrems II expects before personal data leaves the EU. It is a legal exercise, but it leans heavily on technical facts, and that is exactly what we supply.

WHAT A TIA COVERS

The questions it has to answer

A TIA looks at what data is transferred, where it goes, the laws of the destination country, the risk of government access, and the safeguards in place to reduce that risk. It has to conclude, on the specifics, whether protection is adequate and what extra measures are needed.

HOW WE FEED IT

Architecture as evidence

We produce the technical evidence the assessment needs: which EU regions hold the data, how egress is blocked, how encryption and customer-managed keys are configured, and what the access logs show. Instead of asserting that the data is protected, you can point to how.

WHO OWNS WHAT

A clear line of ownership

We provide the technical evidence; your counsel or Data Protection Officer owns the legal assessment and its conclusion. We are careful about that line, because the value of the evidence depends on the right people drawing the legal conclusion from it.

Related

Where this connects.

Schrems II rarely sits on its own: it lives next to your wider GDPR on AWS obligations, and for financial services and critical sectors it overlaps with DORA and NIS2, while the data residency patterns on this page are the same ones we build for SaaS companies selling into the EU.
Common Questions

Schrems II, answered straight.

Plain answers to the questions EU teams actually ask about AWS. The legal calls belong to your counsel or DPO; we handle the technical side and say so wherever the line matters.

Does using EU AWS regions alone make us Schrems II compliant?+
No. Choosing an EU region is necessary but it is not sufficient on its own. AWS is a US-headquartered provider, so under Schrems II you also need contractual safeguards such as Standard Contractual Clauses backed by the current transfer mechanism, encryption with keys you control, controls that keep data from leaving the EU, and a documented transfer assessment. Region choice is the foundation, not the whole building. The legal adequacy of your setup is a question for your counsel or Data Protection Officer, and we build and document the technical measures that support it.
What are SCCs?+
SCCs are Standard Contractual Clauses, a set of pre-approved contract terms published by the European Commission that a data exporter in the EU and a data importer outside it sign to commit to EU-level protection for personal data. After the Schrems II judgment they cannot be relied on by themselves. The data exporter has to assess, case by case, whether the destination country gives adequate protection, and add supplementary measures, technical ones such as encryption included, where it does not.
Is the EU-US Data Privacy Framework enough?+
It depends who you ask. The EU-US Data Privacy Framework is the current adequacy mechanism, adopted on 10 July 2023, for US companies that certify under it, and on paper it provides a lawful basis for EU to US transfers. In practice, some legal teams still require technical measures on top, because two previous frameworks, Safe Harbor and Privacy Shield, were struck down by the courts. Building EU-region architecture with encryption you control means your position does not collapse if the framework is challenged again. Whether the framework alone is enough for your organisation is a legal call for your counsel or Data Protection Officer.
Can AWS staff in the US access our data?+
AWS states that customers own and control their content, that customers choose the region in which their content is stored, and that AWS does not access or use customer content except as necessary to provide the services the customer selected or to comply with the law or a binding order. On top of that, when you use AWS KMS with customer-managed keys, your data is encrypted with keys you control, which materially limits what any provider access could actually reveal. We attribute the access statements to AWS because they are AWS statements; the practical protection comes from the architecture and the keys sitting with you.
Do you provide legal advice?+
No. HAZERCLOUD provides technical implementation and evidence, not legal advice, and we do not guarantee compliance. We build the EU-region architecture, the encryption with customer-managed keys, the egress controls, and the documentation, and we hand you the architecture evidence. Your lawyers or Data Protection Officer assess whether that meets your legal obligations. We are engineers, not a law firm, and we will always point the legal question back to the people qualified to answer it.
Ready to keep it in the EU?

30 minutes. We will map the technical measures to your workload.

Bring your AWS setup and your data residency requirement, and we will walk through the regions, encryption, egress controls, and evidence with you. It is a free scoping call, and you leave with a clear technical picture your counsel or DPO can build the legal assessment on.

EU-region architecture · Customer-managed keys · Technical evidence, not legal advice

30 min Free Consultation →