The Divergence Is Real
Since December 31, 2020, the United Kingdom is no longer part of the EU legal framework. The General Data Protection Regulation no longer applies there directly. The UK has codified its own rules in the UK Data Protection Act 2018 and the UK GDPR. The EU initially granted the UK an adequacy decision — a declaration that the British data protection standard is equivalent to the European one. This decision expires in 2025 and must be renewed. In parallel, the UK has issued its own adequacy decisions for third countries, which partially diverge from EU decisions.
The practical consequence: A German company that transfers personal data to both the USA and the United Kingdom must examine two separate legal bases. For the transfer to the USA, the EU adequacy decision for the EU-US Data Privacy Framework applies, or alternatively Standard Contractual Clauses with a Transfer Impact Assessment under Schrems II. For the transfer to the UK, the EU adequacy decision for the UK initially applies — but only if the data stays there. If the data is transferred onward from the UK to third countries, UK-specific adequacy lists apply, which are not identical to the EU list. The UK has, for example, issued its own Adequacy Regulations for countries like Israel or South Korea, which may differ from EU decisions in timing and substance.
An example: A German software company uses a cloud service provider with data centers in London and Virginia. Data flows from Germany to the UK, and from there partially onward to the USA. The company must examine: Does the EU adequacy decision for the UK still apply? Does the UK adequacy decision for the USA apply? Which Standard Contractual Clauses are to be used — those of the EU Commission or those of the UK Information Commissioner's Office? Which risk assessment must be conducted — according to EU standards or UK standards? The answer: both. In parallel. With different documentation obligations.
The Structural Core: Fragmentation Without a Translation Layer
The cause of this double burden lies not in the complexity of the rules themselves, but in the absence of a state-provided translation layer. Every German company must analyze, assess, and document the divergence between UK and EU law on its own. There is no central authority that examines once whether a specific data transfer path — say, Germany → UK → USA via a specific cloud provider — is legally compliant, and makes the result available to all companies.
In Denmark, NemID and its successor MitID constitute a national digital identity infrastructure provided by the state. Every citizen, every company uses the same technical and legal foundation for digital transactions. The risk assessment of whether a particular authentication path meets data protection requirements is conducted once, centrally. The results are binding for all. The system is state-operated but open to private providers who can obtain certification. The architecture clearly separates: The state delivers the infrastructure and the compliance foundation, companies use it.
In Germany, no comparable infrastructure exists for data transfer compliance. The Conference of Data Protection Authorities of the federal states issues general guidance. The Federal Office for Information Security publishes technical guidelines. But the concrete risk assessment for a specific data transfer — for instance: Is the transfer of customer data via AWS data centers in London and Frankfurt permissible under Schrems II when AWS is also subject to US government access? — must be conducted by each company individually. Or purchased externally. The result: thousands of parallel assessments of the same question, no reusability, no scaling, no learning effect for the overall market.
The allocation of responsibilities aggravates the problem. Data protection supervision is a state matter. There are 16 state data protection authorities and the Federal Commissioner for Data Protection and Freedom of Information. Their assessments of one and the same data transfer scenario may diverge from one another. A company with offices in several federal states may need to consult multiple supervisory authorities. Coordination between authorities takes place via the Conference of Data Protection Authorities — a coordination body without enforcement power. The result: no uniform, binding assessment, no central knowledge base, no infrastructure that relieves companies.
The Cost of Fragmentation
The economic consequences are measurable. A 2023 study by the digital industry association Bitkom estimates the annual compliance costs for German companies under GDPR at an average of 1.2 million euros per company with more than 250 employees. A substantial portion of these costs is attributable to the assessment of international data transfers. Since Brexit and the CJEU's Schrems II decision in July 2020, this share has increased. Every company must conduct a Transfer Impact Assessment for every third-country transfer — an individual risk analysis that evaluates legal, technical, and organizational measures. This analysis must be documented and regularly updated. The divergence between UK and EU doubles the burden for all companies active in both legal frameworks.
Fragmentation also creates a competitive disadvantage. Large corporations can afford specialized compliance teams that continuously monitor and assess the divergence between UK and EU law. Medium-sized companies must purchase external consultants or fall back on generic solutions that are overly restrictive in case of doubt — and thus block business opportunities. Small companies often forgo international data transfers entirely or knowingly accept legal risks because compliance costs are prohibitive. The result: regulation acts as a market entry barrier, not as a protective standard.
The cause does not lie in the existence of different legal systems — this is unavoidable after Brexit. The cause lies in the absence of a state response to this divergence. Other countries have recognized that regulation is only effective when it can be enforced — and that enforcement requires infrastructure. Germany has the regulation, but not the infrastructure.
Bauplan
The next step is building a national data transfer platform. The goal: conduct risk assessments for international data transfers once, centrally, make the results available to all companies, update the assessments regularly. The platform would not replace the decision of the individual company — responsibility remains with the data controller — but it would provide the foundation: a standardized, legally vetted assessment of common data transfer scenarios.
Concretely, the platform could function as follows: A company enters what type of data it wants to transfer, to which country, via which service provider, with which technical safeguards. The platform checks whether an assessment already exists for this scenario. If yes, it delivers the legal classification, the list of required measures, and a template for documentation. If no, the scenario is forwarded to the responsible data protection authority, which creates an assessment and feeds it into the platform. All subsequent companies with the same scenario benefit from this assessment.
Technical feasibility is established. Denmark has demonstrated with MitID that a national digital infrastructure works when it follows three principles: First, state operation of core infrastructure, but openness to private providers. Second, clear separation between infrastructure and application — the platform delivers the compliance foundation, companies decide on usage. Third, continuous updating — assessments must keep pace with legal developments.
The legal foundation can be created through a federal-state agreement. The Conference of Data Protection Authorities could operate the platform jointly, the federal government could provide the technical infrastructure. The assessments would not be binding on supervisory authorities, but they would create a common knowledge base and facilitate coordination. For companies, use would be voluntary, but the relief through standardized assessments would be substantial.
The pitfalls are known: federal jurisdictional conflicts, different assessment standards among states, the effort required for ongoing updates. But the alternative is today's situation — thousands of parallel assessments, no reusability, no scaling. The question is not whether a national data transfer platform would be perfect. The question is whether it would be better than the status quo. The answer is clear.
The state owes its citizens not just laws, but enforcement. Enforcement requires infrastructure. A national data transfer platform would be a concrete step from regulation to implementation. What this step can look like is described in Band 3 "Bauplan" of the Projekt Freistaat trilogy.