Schrems II (Third-Country Transfers)
"Schrems II" is the common name for a 2020 decision of the Court of Justice of the European Union. It invalidated the EU-US data protection arrangement "Privacy Shield". Since then a stricter yardstick applies to transfers of personal data to third countries. Whoever transfers has to consider whether the destination country offers essentially equivalent protection, and otherwise put additional safeguards in place. The requirements are set out in Chapter V of the GDPR.
In practice
The companies affected are mainly those using US services: cloud storage, analytics tools, email marketing software. Before using one, it is worth checking whether the provider takes part in the EU-US Data Privacy Framework, the successor to Privacy Shield since 2023. If it does not, or if doubt remains, you need standard contractual clauses plus additional technical measures such as encryption. A framework that applies today may not apply in three years, which is the real reason a European service saves you the question altogether. Whether a particular transfer is lawful is for legal advice to assess.