Blog · GDPR & EU compliance

    Schrems II for course creators: what to actually do about it.

    If you've heard the term "Schrems II" without ever sitting down to understand it, this post is for you. No law degree required.


    The one-paragraph summary

    In July 2020 the Court of Justice of the European Union ruled (in Case C-311/18, brought by Austrian lawyer Max Schrems) that the EU-US Privacy Shield framework — the legal basis most US companies relied on to handle European personal data — was invalid. The court found that US surveillance law (FISA 702, Executive Order 12333) gave US authorities access to that data in ways incompatible with the GDPR. The result: every EU-to-US transfer of personal data now requires Standard Contractual Clauses (SCCs) plus a Transfer Impact Assessment proving the transfer is actually safe in context.

    That's the legal version. Here's what it actually means.


    Why this is your problem

    You probably don't think of yourself as someone who handles personal data. You teach a course on copywriting, or community management, or selling on Amazon. The students are the point; the data is incidental.

    The GDPR doesn't see it that way. The moment one of your students is an EU resident, you are processing their personal data — name, email, IP address, payment information, learning activity, sometimes faces and voices in your video case studies.

    If your course platform is US-hosted, that data is being transferred to the US the moment it leaves the student's browser. Schrems II made that transfer harder to defend legally.

    For most creators this never becomes a regulator-at-the-door problem. It becomes slower problems:

    • A B2B buyer asks "where is our employees' data hosted?" and you don't have a clean answer.
    • A German student emails asking for everything you have on them, and you realise your platform's Subject Access Request workflow lives in another time zone with a multi-week SLA.
    • Your accountant flags during a tax review that your DPA with your course platform doesn't actually cover the data flows you're running.

    None of these will shut you down. All of them will slow you down at exactly the moment you can't afford it.


    The 2026 status: DPF, SCCs, and the cracks showing

    The political response to Schrems II was the EU-US Data Privacy Framework (DPF), which entered force in July 2023. US companies can self-certify under DPF and claim compliance with EU data transfer requirements again.

    Two problems with relying on this in 2026:

    First, DPF is under active legal challenge. The same advocacy group that brought Schrems I and Schrems II has filed Schrems III, arguing that DPF doesn't materially fix the US surveillance issues that invalidated Privacy Shield. Most EU data protection lawyers expect another invalidation within 18-36 months. Building your compliance posture on a framework that's expected to fall is risky.

    Second, DPF doesn't fix the underlying law. Even DPF-certified US companies still operate under the CLOUD Act, which lets US authorities compel disclosure of data held by US providers regardless of where it's stored. FISA 702 still authorises bulk surveillance of foreign communications. A DPF self-certification is a contract; it isn't a force field.

    The pragmatic reading: DPF is the current floor. It is not a ceiling, and it is not durable.


    What to ask your platform

    If you're on a US-hosted course platform today and want to understand your actual exposure, here are seven questions worth asking. The answers should be on a public trust page, not requiring a sales call.

    1. Where is the application database hosted? A single region answer ("us-east-1") is fine. Vague answers ("globally distributed") usually mean the answer is "wherever AWS happens to put it."
    2. Where is video stored and processed? Course platforms often outsource video to a separate provider. If your platform uses Wistia, Cloudflare Stream, or Mux, ask where those services keep your files.
    3. Where is live session content stored? Recordings, transcripts, attendee logs.
    4. Who are your subprocessors? A real subprocessor list is published, dated, and updated when it changes. If you have to email to receive one, that's a flag.
    5. How is the DPA structured, and does it apply to your current plan? GDPR-required Data Processing Agreements should be available to every customer, ideally embedded in standard Terms of Use (the modern-SaaS pattern — Vercel, Cloudflare, Stripe) rather than gated behind a paid tier or negotiated bilaterally. If you have to request the DPA from support or it's paywalled, the platform is signalling its priorities.
    6. What's the DSAR turnaround? Subject Access Requests must legally be fulfilled within 30 days. Ask what the actual median turnaround is. Anything over 5 business days suggests manual handling, which doesn't scale.
    7. Are you DPF-certified, and what's your stance if DPF is invalidated? A platform that has thought past DPF will have a clear answer. A platform that hasn't will not.

    What "EU-hosted" should actually mean

    When a platform says "EU-hosted," that should mean:

    The application database is in an EU region.

    The video processing pipeline runs on EU infrastructure.

    The CDN edge can be configured for EU-only routing.

    AI inference (for search, recommendations, transcription) runs on EU-resident models.

    Subprocessors are predominantly EU-resident; the few that aren't are documented with SCCs.

    Flag-waving — a `.eu` domain and a logo on the homepage — doesn't qualify. The substrate has to be EU, not just the marketing.


    Why we built lernaura the way we did

    lernaura runs on Scaleway for the application database and infrastructure (French-owned hardware), Scalingo for application hosting (French), Mistral for AI inference (French), Gladia for transcription (French), Brevo for transactional email (French), Mollie for payments (Netherlands, EU-regulated), and api.video and Whereby (both EU-resident) for video and live sessions. The DPA is embedded in our Terms of Use, accepted at signup, applying to every plan from the free tier. AI inference happens on EU-resident models with contractual no-training clauses, and every AI invocation is logged as a versioned skill — full audit trail for EU AI Act compliance, produced by design rather than reconstructed from logs.

    This was a deliberate architectural choice in 2024, not a marketing pivot in 2026. The argument that drove it: the next decade of EU data law will move further from US transfers, not closer. Building on EU infrastructure was the only design that didn't bet on Schrems II being the last word.

    If you're interested in the longer version, our European course platform page covers it.


    What to do this month

    Whether or not you switch platforms, three actions are worth taking this month:

    1. Read your current platform's DPA. Most creators have never opened it. Skim section 4 (transfers) and section 7 (subprocessors). Note what you don't understand.
    2. Document your data flows. Where do your student names, emails, video, payment details, and community posts go? Even a hand-drawn diagram is more than most creators have.
    3. Run a 30-day DSAR drill. Pretend a student has asked for everything you have on them. How long does it take you to assemble it? What can't you get?

    These aren't compliance theatre. They're the moments where you realise what you'd actually need to do if a regulator did call — and where the friction in your current setup actually lives.

    If you're thinking about moving to an EU-hosted course platform, sign up free at lernaura — the platform stays free until you monetize. Or read the longer version of how we built compliance in.


    Make it. Keep it.

    The whole back office of cross-border selling — tax, payments, collection, FX, disputes — handled by lernaura. One integration, one clean payout, EU-owned end to end. Creators: the free platform is waiting.
    For sellers based in the EU/EEA, selling to buyers across Europe and North America — more countries on both sides soon.