Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 3 min read · Updated 16 August 2026

Schrems II

In shortSince 2020 you must assess yourself whether data is safe in the recipient country — the provider cannot do it for you.

At a glance

Decision
CJEU, judgment of 16 July 2020, Case C-311/18
What was annulled
The adequacy decision on the EU–US Privacy Shield, with immediate effect and no transition period
What survived
Standard contractual clauses — but only together with your own assessment of the recipient country
The reason
US surveillance powers, in particular FISA 702, without equivalent legal redress for EU citizens
Who must assess
The controller, meaning your company — not the provider and not the supervisory authority
Position today
The EU–US Data Privacy Framework has applied since July 2023; the duty to assess remains for every transfer outside its scope

On 16 July 2020 the Court of Justice of the European Union declared the adequacy decision on the EU–US Privacy Shield invalid — with no transition period. Overnight, thousands of European companies lost the legal basis for transfers they had been running for years.

The case arose from a complaint by the Austrian lawyer Maximilian Schrems against Facebook Ireland. It was the second decision of its kind: in 2015 the same complainant had brought down the predecessor arrangement, Safe Harbor.

Oct 2015 Safe Harbor falls Schrems I: the first adequacy decision is annulled Jul 2016 Privacy Shield arrives successor arrangement with an ombudsperson and assurances Jul 2020 Schrems II Privacy Shield is invalid too; standard clauses survive, but with a duty to assess Jul 2023 Data Privacy Framework third attempt, resting on a US executive order
Two annulled decisions in eight years. Treating the third as permanent plans against your own experience.

What the Court objected to

The core is not data protection bureaucracy but legal redress. The surveillance programmes resting on FISA 702 and Executive Order 12333 give US authorities access to data about people outside the United States. Those people have no route to redress equivalent to the European one: they do not learn of the access and cannot have it reviewed effectively by an independent court.

The Court does not demand an identical level of protection, but one that is essentially equivalent. That is where the Privacy Shield failed.

What survived — and what follows from it

The Court expressly did not strike down the standard contractual clauses. It did clarify what they can and cannot achieve: a contract between two companies binds no authority. Where the law of the recipient country permits access that conflicts with the European level of protection, the best contract changes nothing.

From that follows the duty to assess that has shaped practice ever since. Before every transfer to a third country without an adequacy decision, the controller must judge for themselves whether the level of protection holds, and document that judgment. The duty sits with you, not with the provider.

What belongs in such an assessment

You describe the categories of data transferred, the recipient and its legal form, the relevant access powers in the recipient country, and the measures with which you compensate for any shortfall in protection.

The last point decides it. The European Data Protection Board considers two measures effective above all: encryption whose keys sit beyond the reach of the recipient and its authorities, and pseudonymisation where the re-identification data stays in Europe. What that means technically is set out under Key control.

Contractual assurances and transparency reports are useful, but they are not supplementary measures within the meaning of the recommendations — they do not change the law in the recipient country.

Where things stand today

Since July 2023 the EU–US Data Privacy Framework has applied, resting on a US executive order that establishes a redress mechanism. For certified US recipients there is an adequacy basis again; the details are under Adequacy decision.

For practice this means two things. First, transfers to non-certified recipients and to other third countries still need their own assessment. Second, the third framework rests on a legal instrument a future US administration can change, and it is already being challenged. Building an architecture that would survive its loss is not pessimism; it is planning from experience.

What this means for procurement

Schrems II shifted the burden of proof. Before 2020 a reference to an arrangement sufficed; since then a company has to show it examined the question.

That is inconvenient, but it has a practical side effect: doing the assessment properly once for your five most important processing activities also gives you the list of providers where a change would have the greatest effect — and the basis for a workable Exit strategy.

Common questions

Has the Data Privacy Framework made Schrems II obsolete?
Only in part. For certified US recipients under the 2023 framework there is an adequacy basis again. For all other transfers the duty to assess from Schrems II applies unchanged — and the framework itself is already being challenged in court, as both its predecessors were.
What is a transfer impact assessment?
The assessment Schrems II requires: you describe the transfer, the law in the recipient country, the access powers of authorities there, and the supplementary measures with which you compensate. It must be documented and produced to the supervisory authority on request.
Are standard contractual clauses enough on their own?
No. The Court expressly upheld them but found that a contract between two companies binds no authority in the recipient country. Where local law permits access that conflicts with the European level of protection, supplementary measures are needed — technical, organisational, or abandoning the transfer.
Which supplementary measures actually work?
The European Data Protection Board points above all to encryption with keys beyond the recipient's reach, and to pseudonymisation where the re-identification data stays in Europe. Contractual and organisational measures alone do not suffice where authorities have a statutory right of access anyway.

Sources

See also

Related terms