Schrems II
In shortSince 2020 you must assess yourself whether data is safe in the recipient country — the provider cannot do it for you.
At a glance
- Decision
- CJEU, judgment of 16 July 2020, Case C-311/18
- What was annulled
- The adequacy decision on the EU–US Privacy Shield, with immediate effect and no transition period
- What survived
- Standard contractual clauses — but only together with your own assessment of the recipient country
- The reason
- US surveillance powers, in particular FISA 702, without equivalent legal redress for EU citizens
- Who must assess
- The controller, meaning your company — not the provider and not the supervisory authority
- Position today
- The EU–US Data Privacy Framework has applied since July 2023; the duty to assess remains for every transfer outside its scope
On 16 July 2020 the Court of Justice of the European Union declared the adequacy decision on the EU–US Privacy Shield invalid — with no transition period. Overnight, thousands of European companies lost the legal basis for transfers they had been running for years.
The case arose from a complaint by the Austrian lawyer Maximilian Schrems against Facebook Ireland. It was the second decision of its kind: in 2015 the same complainant had brought down the predecessor arrangement, Safe Harbor.
What the Court objected to
The core is not data protection bureaucracy but legal redress. The surveillance programmes resting on FISA 702 and Executive Order 12333 give US authorities access to data about people outside the United States. Those people have no route to redress equivalent to the European one: they do not learn of the access and cannot have it reviewed effectively by an independent court.
The Court does not demand an identical level of protection, but one that is essentially equivalent. That is where the Privacy Shield failed.
What survived — and what follows from it
The Court expressly did not strike down the standard contractual clauses. It did clarify what they can and cannot achieve: a contract between two companies binds no authority. Where the law of the recipient country permits access that conflicts with the European level of protection, the best contract changes nothing.
From that follows the duty to assess that has shaped practice ever since. Before every transfer to a third country without an adequacy decision, the controller must judge for themselves whether the level of protection holds, and document that judgment. The duty sits with you, not with the provider.
What belongs in such an assessment
You describe the categories of data transferred, the recipient and its legal form, the relevant access powers in the recipient country, and the measures with which you compensate for any shortfall in protection.
The last point decides it. The European Data Protection Board considers two measures effective above all: encryption whose keys sit beyond the reach of the recipient and its authorities, and pseudonymisation where the re-identification data stays in Europe. What that means technically is set out under Key control.
Contractual assurances and transparency reports are useful, but they are not supplementary measures within the meaning of the recommendations — they do not change the law in the recipient country.
Where things stand today
Since July 2023 the EU–US Data Privacy Framework has applied, resting on a US executive order that establishes a redress mechanism. For certified US recipients there is an adequacy basis again; the details are under Adequacy decision.
For practice this means two things. First, transfers to non-certified recipients and to other third countries still need their own assessment. Second, the third framework rests on a legal instrument a future US administration can change, and it is already being challenged. Building an architecture that would survive its loss is not pessimism; it is planning from experience.
What this means for procurement
Schrems II shifted the burden of proof. Before 2020 a reference to an arrangement sufficed; since then a company has to show it examined the question.
That is inconvenient, but it has a practical side effect: doing the assessment properly once for your five most important processing activities also gives you the list of providers where a change would have the greatest effect — and the basis for a workable Exit strategy.
Common questions
- Has the Data Privacy Framework made Schrems II obsolete?
- Only in part. For certified US recipients under the 2023 framework there is an adequacy basis again. For all other transfers the duty to assess from Schrems II applies unchanged — and the framework itself is already being challenged in court, as both its predecessors were.
- What is a transfer impact assessment?
- The assessment Schrems II requires: you describe the transfer, the law in the recipient country, the access powers of authorities there, and the supplementary measures with which you compensate. It must be documented and produced to the supervisory authority on request.
- Are standard contractual clauses enough on their own?
- No. The Court expressly upheld them but found that a contract between two companies binds no authority in the recipient country. Where local law permits access that conflicts with the European level of protection, supplementary measures are needed — technical, organisational, or abandoning the transfer.
- Which supplementary measures actually work?
- The European Data Protection Board points above all to encryption with keys beyond the recipient's reach, and to pseudonymisation where the re-identification data stays in Europe. Contractual and organisational measures alone do not suffice where authorities have a statutory right of access anyway.
Sources
See also
Related terms
- FISA 702US intelligence agencies may access Europeans' data held by American providers, and those affected are not told.
- Adequacy decisionAn adequacy decision permits transfers to a third country without extra safeguards — until it is struck down.
- US CLOUD ActUS providers must hand over data even when it sits in Frankfurt.