Abstract
The enactment of the General Data Protection Regulation (GDPR) and subsequent seminal jurisprudence from the Court of Justice of the European Union (CJEU), notably the Schrems II ruling, have fundamentally altered the landscape of international personal data transfers. This qualitative empirical study examines the multifaceted operational, legal, and institutional compliance challenges confronted by European Union-based banking institutions engaged in routine cross-border data flows. Drawing upon semi-structured in-depth interviews with thirty-two Chief Compliance Officers, Data Protection Officers (DPOs), and specialized financial legal counsels across six EU member states (Germany, France, Ireland, Luxembourg, the Netherlands, and Italy), this paper investigates how institutions navigate the dual pressures of rigid data sovereignty mandates and inherently globalized financial infrastructures. Our findings indicate that post-Schrems II requirements, particularly the implementation of Transfer Impact Assessments (TIAs) and supplementary measures for Standard Contractual Clauses (SCCs), have triggered significant legal uncertainty, disproportionate cost burdens, and technical frictions in correspondent banking and transnational fraud detection mechanisms. Furthermore, the structural incompatibility between third-country surveillance regimes—predominantly in the United States—and European fundamental rights under the Charter creates systemic compliance impasses. The article concludes by evaluating emerging policy responses, such as the EU-US Data Privacy Framework, and posits doctrinal and regulatory reforms to harmonize the imperative of fundamental privacy protections with the functional realities of international digital banking.