On 31 March 2022, the School of Law of UCLan Cyprus held its second Continuing Professional Development webinar on the Fundamentals of Data Protection, organised in association with the Larnaca Bar Association and Famagusta Bar Association.
The webinar formed part of the collaboration between UCLan Cyprus and the two Bar Associations following the signing of their respective Memoranda of Understanding.
The session focused on recent developments in data-protection regulation in Cyprus, the European Union and internationally.
Maria Raphael participated as a speaker representing the Larnaca and Famagusta Bar Associations and delivered the keynote presentation:
“International Data Transfers: Compliance and Challenges.”
At the time, international data transfers were undergoing a period of significant change.
The Court of Justice’s Schrems II judgment had invalidated the EU-US Privacy Shield.
The European Commission had adopted new Standard Contractual Clauses.
The European Data Protection Board was developing detailed guidance on Transfer Impact Assessments, supplementary measures and the meaning of an international transfer.
And only days before the webinar, the European Union and United States had announced an agreement in principle on a new transatlantic data-transfer framework.
The presentation therefore examined both the legal framework already in force and several important developments that were still taking shape.
Fundamentals on Data Protection at UCLan Cyprus
The webinar was organised by the School of Law of UCLan Cyprus in association with the Larnaca Bar Association and Famagusta Bar Association.
UCLan Cyprus is an accredited provider of Continuing Professional Development programmes under the Cyprus Bar Association scheme.
The webinar addressed developments in data protection relevant to legal practitioners and other professionals, including:
- regulatory enforcement;
- court decisions;
- international data transfers;
- practical GDPR compliance;
- and the continuing effect of the COVID-19 period on organisations and data-protection obligations.
Maria Raphael’s contribution focused specifically on cross-border personal-data transfers.
The transfer landscape in March 2022
When the webinar took place, organisations transferring personal data outside the European Economic Area were still working through the practical consequences of Schrems II.
The Court’s judgment had invalidated the EU-US Privacy Shield while confirming that Standard Contractual Clauses could remain a valid transfer mechanism.
But SCCs could not be treated as a purely contractual formality.
Exporters needed to consider whether the law and practice of the recipient country could prevent the transfer mechanism from providing an essentially equivalent level of protection.
Where necessary, organisations had to identify supplementary measures capable of addressing those risks.
This placed significantly greater emphasis on practical transfer governance.
The new Standard Contractual Clauses
The European Commission had adopted a new generation of Standard Contractual Clauses in June 2021.
The clauses introduced a modular structure designed to address different transfer relationships, including:
- controller to controller;
- controller to processor;
- processor to processor; and
- processor to controller.
The 2021 SCCs also expressly reflected the implications of Schrems II.
Parties were required to consider the laws and practices of the third country relevant to the transfer and document their assessment.
For organisations operating internationally, implementation therefore required more than replacing an old contractual template.
It required mapping:
- the data exporter;
- the importer;
- the roles of the parties;
- the data being transferred;
- the purpose of the transfer;
- the destination country;
- and the safeguards required in practice.
Transfer Impact Assessments and supplementary measures
Maria Raphael’s presentation addressed the European Data Protection Board’s recommendations on supplementary measures and the practical use of Transfer Impact Assessments.
A Transfer Impact Assessment requires organisations to examine whether the legal and practical environment in the destination country may affect the effectiveness of the transfer mechanism being used.
Relevant considerations can include:
- public-authority access to personal data;
- surveillance legislation;
- available legal remedies;
- the type and sensitivity of the data;
- the nature of the recipient;
- technical safeguards;
- and the circumstances of the transfer.
Where the transfer tool alone does not provide sufficient protection, organisations may need supplementary safeguards.
Those measures can be:
- technical;
- contractual; or
- organisational.
The presentation also considered practical problems organisations were encountering when trying to translate these regulatory expectations into workable transfer processes.
The EDPB was also clarifying what counts as a transfer
Another issue discussed during the presentation was the EDPB’s draft Guidelines 05/2021 concerning the relationship between Article 3 GDPR and Chapter V.
Those Guidelines addressed a question that had become increasingly important as the GDPR’s territorial scope expanded:
When does disclosure or access involving an organisation outside the EEA actually constitute an international transfer under Chapter V?
At the time of the webinar, the Guidelines were still in draft form.
Maria Raphael had also participated in the EDPB’s public consultation on the draft Guidelines.
The final version was subsequently adopted in February 2023.
The final Guidelines identify three cumulative criteria for a Chapter V transfer:
-
a controller or processor is subject to the GDPR for the relevant processing;
-
that exporter discloses or otherwise makes personal data available to another controller, joint controller or processor; and
-
the recipient is located in a third country or is an international organisation, regardless of whether that recipient is itself subject to the GDPR under Article 3.
Could a new EU-US framework solve the Schrems II problem?
The final part of the presentation examined transatlantic transfers.
Only days before the webinar, on 25 March 2022, the European Union and United States had announced an agreement in principle on a new framework for transatlantic personal-data transfers.
At that stage, there was no adequacy decision.
The presentation therefore considered whether a future framework could address the concerns identified by the Court of Justice when it invalidated the Privacy Shield.
Those concerns related particularly to:
- access by US intelligence authorities;
- proportionality;
- necessity;
- and effective judicial or independent redress for individuals in the European Union.
The agreement in principle was an important political development.
But in March 2022 the legal architecture had not yet been finalised.
WHAT HAPPENED AFTER THE 2022 WEBINAR?
Several issues discussed at the webinar were unresolved in March 2022. In the years that followed, some became established parts of the international-transfer framework.
The EDPB finalised Guidelines 05/2021
The EDPB adopted the final version of Guidelines 05/2021 in February 2023.
The final Guidelines confirmed the three-part test for identifying a transfer under Chapter V and clarified the relationship between:
- the GDPR’s territorial scope under Article 3; and
- the transfer restrictions in Chapter V.
The Guidelines also clarify that a situation may involve processing outside the EEA without constituting a Chapter V transfer where there is no disclosure to a separate controller or processor.
That distinction can matter significantly for multinational organisations, remote access arrangements and international group structures.
The agreement in principle became the EU-US Data Privacy Framework
The political agreement discussed at the webinar later developed into the EU-US Data Privacy Framework.
On 10 July 2023, the European Commission adopted an adequacy decision concluding that the United States provides an adequate level of protection for personal data transferred to US organisations participating in the Framework.
The adequacy decision introduced a new route for eligible EU-US transfers without requiring SCCs for transfers covered by the Framework.
The Data Privacy Framework does not, however, replace the wider Chapter V architecture.
Organisations still need other transfer mechanisms where:
- the recipient is not covered by the Framework;
- the transfer is to another non-adequate jurisdiction;
- or another transfer structure is required.
SCCs, Transfer Impact Assessments and supplementary measures therefore remain important parts of international data-transfer governance.
EU-US Data Privacy Framework adequacy decision →
The Commission reviewed the Framework after its first year
The Commission carried out the first periodic review of the EU-US Data Privacy Framework in 2024.
Its report, published in October 2024, examined whether the elements underlying the adequacy decision had been implemented and were functioning in practice.
The review covered matters including:
- compliance by participating organisations;
- enforcement;
- redress mechanisms;
- US intelligence safeguards;
- and the functioning of the Data Protection Review Court.
The periodic-review mechanism is important because adequacy is not treated as a one-time determination.
The Commission is required to continue monitoring developments capable of affecting the level of protection on which the decision is based.
The EU-US adequacy decision was challenged before the General Court
The EU-US Data Privacy Framework was subsequently challenged before the General Court of the European Union.
In Case T-553/23, Latombe v Commission, the applicant sought annulment of the Commission’s adequacy decision.
On 3 September 2025, the General Court dismissed the action.
The Court concluded that, on the date the adequacy decision was adopted, the United States ensured an adequate level of protection for personal data transferred under the Framework.
The judgment therefore left the adequacy decision in force.
Adequacy decisions remain subject to continuing review and may be affected by future legal or factual developments.
The General Court judgment has been appealed
On 31 October 2025, Philippe Latombe lodged an appeal before the Court of Justice against the General Court’s judgment.
The appeal is pending as Case C-703/25 P.
The EU-US Data Privacy Framework adequacy decision therefore remains in force, but the judicial challenge has not yet been finally concluded.
Schrems II still matters outside adequacy frameworks
The emergence of the Data Privacy Framework did not eliminate the compliance issues discussed during the 2022 webinar.
For transfers relying on mechanisms such as Standard Contractual Clauses to jurisdictions without an applicable adequacy decision, organisations still need to consider whether the transfer mechanism can operate effectively in the destination country.
That means transfer governance continues to involve:
- mapping international data flows;
- identifying the transfer mechanism;
- assessing destination-country risks where required;
- determining whether supplementary measures are necessary;
- documenting the analysis;
- and monitoring changes over time.
The central lesson from Schrems II therefore remains relevant:
a transfer mechanism needs to work in practice, not merely exist on paper.
From pending developments to an established framework
The international-transfer landscape discussed at UCLan Cyprus in March 2022 was unusually fluid.
At the time:
- the new SCCs were still being operationalised;
- organisations were developing Transfer Impact Assessment methodologies;
- the EDPB’s transfer-definition Guidelines remained in draft form;
- and the new EU-US framework existed only as an agreement in principle.
By September 2026:
- Guidelines 05/2021 have been finalised;
- the 2021 SCC architecture is established;
- the EU-US Data Privacy Framework is in force;
- its first periodic review has been completed;
- and the General Court has dismissed the first annulment challenge against the adequacy decision.
An appeal against that judgment is currently pending before the Court of Justice in Case C-703/25 P.
The practical work has therefore shifted.
The central question is no longer simply which transfer tool exists.
Organisations increasingly need to build governance capable of applying the correct tool consistently across complex international data flows.
International transfers remain a governance issue
The legal framework for international transfers has become more developed since the 2022 UCLan Cyprus webinar.
But the underlying compliance challenge remains familiar.
International organisations need to know:
- where personal data moves;
- which entities disclose and receive it;
- whether Chapter V applies;
- which transfer mechanism is available;
- whether the destination requires additional assessment;
- what supplementary measures are needed;
- and how those conclusions will remain current as law, technology and processing arrangements change.
The developments since 2022 have added new mechanisms and greater clarity.
They have not reduced international transfers to a simple contractual exercise.
Effective transfer compliance still depends on connecting legal analysis with the organisation’s actual data flows and operational environment.



