Showing posts with label CJEU. Show all posts
Showing posts with label CJEU. Show all posts

Thursday, December 4, 2025

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

“If EU citizens’ data goes to the United States, will it still receive GDPR-level protection?” Schrems II rewrote the balance between global data flows and fundamental rights.


Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Hello! Today we look at Schrems II (2020). Brought by Austrian privacy activist Max Schrems, the case centered on concerns that personal data transferred from the EU to the U.S. could be exposed to large-scale surveillance by U.S. intelligence agencies. In particular, the constitutionality—better, the validity—of the Privacy Shield framework (adopted after Safe Harbor was invalidated) was back under scrutiny. Studying this judgment made me realize that the idea of “data borders” is anything but abstract.

Background and Facts

The case began with Austrian privacy advocate Max Schrems suing Facebook Ireland. Schrems argued that when EU citizens’ data is transferred to the United States, it may be subject to extensive surveillance by U.S. intelligence agencies (notably the NSA). In his view, this fails to meet the GDPR’s requirement of an “essentially equivalent” level of protection. After the 2015 Schrems I ruling had already invalidated Safe Harbor, this case targeted its successor, the EU-U.S. Privacy Shield.

The question was whether the Privacy Shield framework meets the level of protection required by the GDPR. The breadth of U.S. surveillance programs and the lack of adequate judicial redress for EU citizens were central concerns.

Issue Problems with Privacy Shield GDPR Requirements
Scope of surveillance Allows large-scale collection by U.S. government Only necessary and proportionate surveillance allowed
Judicial redress EU citizens lack effective remedies in U.S. courts Remedies must be effective and accessible
Level of protection Not equivalent to the EU level Protection essentially equivalent to (or exceeding) GDPR

The Judgment and Reasoning

The CJEU held that Privacy Shield is invalid. However, it deemed Standard Contractual Clauses (SCCs) valid in principle, while emphasizing that national supervisory authorities must assess the level of protection in each particular case. The reasoning:

  • U.S. surveillance programs do not satisfy necessity and proportionality.
  • EU citizens lack effective judicial redress in the United States.
  • SCCs remain valid, but controllers/processors and supervisory authorities must verify case-by-case whether equivalent protection is ensured.

Impact on the EU Legal System

Schrems II brought sweeping changes to EU-U.S. data transfers. Privacy Shield was invalidated immediately, confronting thousands of companies with legal uncertainty. In response, the EU and the U.S. negotiated a new framework—the EU-U.S. Data Privacy Framework—and supervisory authorities took on stricter oversight of SCCs. The ruling strengthened the global effect of the GDPR and amplified worldwide debates on data sovereignty.

Criticism and Academic Debate

While hailed for strengthening privacy, Schrems II has also been criticized for imposing heavy practical burdens on companies and regulators.

Perspective Main Argument
Critical Greater uncertainty for data transfers; potential chill on global business
Supportive Firmly protects EU citizens’ fundamental data rights and elevates the GDPR’s global standing

Contemporary Significance and Takeaways

Schrems II remains a reference point for governing international data flows—not only for the EU-U.S. relationship but also for legislation in India, Brazil, Korea, and beyond. Key takeaways:

  • Exposes the fragility of transfer frameworks (e.g., Privacy Shield) and calls for new models of international cooperation
  • Reinforces the GDPR’s global standard-setting effect, influencing foreign legislation
  • Emphasizes the shared responsibility of companies and regulators to verify “concrete protective measures”

Frequently Asked Questions (FAQ)

Q What is the core of Schrems II?

The validity of the EU-U.S. Privacy Shield, the applicability of SCCs, and the role of supervisory authorities (DPAs) in overseeing transfers.

Q How did the CJEU rule on Privacy Shield?

It invalidated Privacy Shield due to the breadth of U.S. surveillance and insufficient redress mechanisms.

Q What happened to SCCs?

They remain valid in principle, but DPAs must verify in each transfer whether an equivalent level of protection is ensured.

Q What should companies do after the ruling?

Use SCCs together with a Transfer Impact Assessment (TIA), implement supplementary measures (encryption, pseudonymization), and review local surveillance laws.

Q What is its significance today?

Schrems II strengthened the GDPR’s international influence and spurred debates on data sovereignty and surveillance reform.

In Closing

Schrems II (2020) makes clear that data flows are not merely technical—they are tied directly to fundamental rights. For exams and practice, structure your analysis around ① Privacy Shield invalid, ② SCCs valid with conditional verification, and ③ surveillance programs and redress gaps. Emphasizing the Transfer Impact Assessment (TIA) and supplementary measures will align you with current GDPR enforcement trends. This case convinced me that “data is the new border.” The topic will only heat up—so keep a close eye on cases and controversies. 🙂

Wednesday, December 3, 2025

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

“Does the EU’s right to be forgotten apply to Google Search worldwide?” Google v. CNIL shows how data protection and freedom of expression can clash across borders.

Google v. CNIL (2019): The Geographic Limits of the Right to Be Forgotten

Hello! Today we summarize the Google v. CNIL (2019) judgment. The dispute concerned how the EU’s Right to be Forgotten applies to Google’s global search engine. The French regulator CNIL argued that Google must apply delisting (de-referencing) not only to EU domains but to search results worldwide, while Google pushed back, citing freedom of expression and the risk of international conflicts. Studying this case made me rethink how digital rights collide with the very concept of borders.

Background and Facts

Following the Google Spain (2014) ruling, the EU recognized the right of data subjects to request search-result removal—i.e., the right to be forgotten. France’s data protection authority, CNIL, ordered Google to apply delisting not only on EU domains (.fr, .de, etc.) but also on all global search results (such as google.com). Google argued this demand was excessive and could conflict with freedom of expression and other jurisdictions’ laws. The case reached the CJEU, raising a new question about the right to be forgotten’s geographic scope.

At stake was whether EU delisting requests can bind Google’s search results worldwide. A global effect would extend EU regulation into other countries’ free-expression domains, while an EU-only effect could weaken the practical effectiveness of the right to be forgotten in the digital space.

Issue Global Application Application within the EU
Data protection Ensures the highest level of protection Protection confined to the EU; access from outside may remain
Freedom of expression Risk of infringing other countries’ free-speech regimes Minimizes international conflicts
International-law legitimacy Concern over encroaching on other States’ sovereignty Rationalizable as a regional measure

The Judgment and Reasoning

The CJEU held that Google is not required to ensure delisting on search results worldwide. However, it must ensure delisting within the EU. The reasoning:

  • EU law has direct effect only within the EU’s territory.
  • Worldwide application could clash with other countries’ free-speech protections and regulatory frameworks.
  • Nevertheless, effective delisting measures must operate within the EU.

Impact on the EU Legal System

Google v. CNIL clarified the geographic limits of the right to be forgotten in the EU. It shows how data protection and freedom of expression may conflict in an international setting. After the ruling, the EU maintained strong delisting obligations within its territory while refraining from asserting universal extraterritorial reach—an approach seen as measured restraint regarding the external scope of EU law.

Criticism and Academic Debate

The ruling drew mixed reactions: some argued it was not strong enough to protect EU citizens’ data, while others praised it as a sensible way to avoid overextending EU regulation globally.

Perspective Main Argument
Critical Limiting the effect to the EU weakens real protection; personal data may still be reachable via non-EU searches
Supportive Balances strong protection within the EU with restraint to avoid conflicts with other countries’ free-speech regimes

Contemporary Significance and Takeaways

Today, Google v. CNIL is a leading case on how internet regulation meets borders. Key takeaways:

  • A precedent illustrating the international balancing of data protection and freedom of expression
  • Strong EU-only delisting obligations paired with international-law restraint
  • Underscores the importance of the “inside–outside the EU” distinction in global internet regulation debates

Frequently Asked Questions (FAQ)

Q What is Google v. CNIL?

A case about whether the EU’s right to be forgotten requires Google to delist search results worldwide.

Q Who brought the case?

France’s data protection authority, CNIL, demanded that Google delist results across all global domains, triggering the dispute.

Q What was the legal issue?

Whether the EU right to be forgotten has worldwide effect or is confined to the EU.

Q How did the CJEU decide?

Google is not required to delist results worldwide, but it must delist within the EU.

Q What does the ruling mean?

EU law applies robustly within the EU but shows restraint to avoid conflicts with other legal orders abroad.

Q Is it still important today?

Yes. It is a staple precedent when discussing the scope of the EU’s right to be forgotten in global internet regulation.

In Closing

Google v. CNIL (2019) reminds us that even on a “borderless internet,” legal boundaries still matter. For application tips, frame proportionality around ① the data subject’s rights, ② freedom of expression and the right to know, and ③ inside–outside EU effects. On exams, the geographic scope is a common pitfall—state clearly the “mandatory in-EU + restraint outside the EU” conclusion. In practice, the implementation details—geoblocking, EU IP–based delisting, and management of public-interest exceptions—are key. If you have a scenario in mind, let’s build a checklist together. 🙂

Saturday, November 29, 2025

Digital Rights Ireland (2014): Balancing Data Protection and Security

Digital Rights Ireland (2014): Balancing Data Protection and Security

“Can we retain everyone’s communications data—or does that violate fundamental rights?” The Digital Rights Ireland ruling is a symbolic case showing how security and privacy collide within the EU legal order.


Digital Rights Ireland (2014): Balancing Data Protection and Security

Hello! Today we’re looking at Digital Rights Ireland (2014). This landmark judgment annulled the EU’s Data Retention Directive and made me ask, “Security or privacy?” The Court emphasised the right to private life and the confidentiality of communications under the EU Charter and subjected mass data retention to strict review. It became a key moment for re-articulating constitutional principles in the digital age.

Background and Facts

In 2006, the EU adopted the Data Retention Directive to combat terrorism and serious crime. It required all electronic communications providers to store users’ traffic data (call logs, email metadata, location information, etc.) for between six months and two years. The Irish NGO Digital Rights Ireland challenged the regime, arguing it treated the entire population as potential suspects and violated Articles 7 (respect for private life) and 8 (protection of personal data) of the Charter of Fundamental Rights. The case ultimately reached the CJEU.

At the heart of the case was the clash between the public interest in security and public safety and the fundamental rights to private life and data protection.

Issue Security and Public Safety Data Protection
Legal basis Treaty provisions on security and crime prevention EU Charter of Fundamental Rights, Arts. 7 & 8
Argument Prevent terrorism and enhance investigative effectiveness Generalised, indiscriminate data collection violates fundamental rights
Concern Security could become a pretext for pervasive surveillance People without any suspicion are swept into tracking regimes

The Court’s Judgment and Reasoning

The CJEU annulled the Data Retention Directive for disproportionately interfering with fundamental rights. While accepting the legitimacy of security objectives, the Court found that general and indiscriminate retention breached the principle of proportionality. Key points:

  • Security aims are legitimate, but blanket retention exceeds what is strictly necessary.
  • Retention periods, scope, and access procedures were set too broadly without concrete limits.
  • Any restriction on fundamental rights must satisfy necessity and proportionality—this directive did not.

Impact on the EU Legal Order

This was the first time in EU history that legislation aimed at security was struck down in its entirety. Digital Rights Ireland is seen as proof of the Charter’s real force. After the ruling, Member States had to revisit their retention laws, and EU data protection rules were further strengthened, feeding directly into the 2018 GDPR and consolidating a “privacy-first EU legal order.”

Criticism and Academic Debate

Reactions were mixed. Some argued the Court applied unduly strict scrutiny despite growing security threats. Others hailed the decision as a “constitutional victory” sounding the alarm against mass surveillance in the digital age.

Perspective Main Argument
Critical Overly constrains crime-fighting and security measures, reducing effectiveness
Supportive Affirms privacy as a top value and protects citizens from mass surveillance

Contemporary Significance and Takeaways

Today, Digital Rights Ireland remains a core reference in EU debates on digital governance. It is frequently cited in discussions on big data, AI, and national-security surveillance systems. Key takeaways include:

Frequently Asked Questions (FAQ)

Q What is Digital Rights Ireland?

An Irish NGO challenged the EU’s Data Retention Directive, which required the collection and storage of communications metadata for the entire population, alleging violations of fundamental rights.

Q What was the legal issue?

Whether security-driven data collection infringed Articles 7 and 8 of the Charter—respect for private life and protection of personal data.

Q How did the Court rule?

The CJEU annulled the directive for violating proportionality by mandating general and indiscriminate retention that intruded excessively on personal data.

Q Why is the case significant?

It demonstrated the real bite of the Charter, prioritised privacy in the security-freedom balance, and influenced subsequent regulation, including the GDPR.

Q What criticisms were made?

Some said the ruling hampered responses to threats; others praised it for checking mass surveillance.

Q Does it still have impact today?

Yes. It directly shaped stronger EU data-protection rules like the GDPR and remains central to debates on surveillance in the digital era.

In Closing

Digital Rights Ireland (2014) moves beyond the false binary of “security versus freedom” and reaffirms the constitutional principle that both must be protected. For application: check (1) whether the measure is generalised/indiscriminate, (2) whether the scope and duration are clearly delimited, (3) whether there is independent judicial control and oversight, and (4) whether there are minimisation and security safeguards such as encryption/anonimisation. Fit these into a proportionality frame and the contours of judgment in similar cases become clearer. If you have real-world scenarios or research projects, share them. We can map out the follow-up case law (e.g., Tele2 Sverige, La Quadrature du Net) together. 🙂

Thursday, November 27, 2025

Laval (2007): The Clash Between the Freedom to Provide Services and Workers’ Right to Collective Action

Laval (2007): The Clash Between the Freedom to Provide Services and Workers’ Right to Collective Action

“The freedom to provide services is a right; collective action is a right. So what happens when they collide?” Laval is a leading case where the EU’s freedom to provide services directly clashed with labour rights in the internal market.


Laval (2007): The Clash Between the Freedom to Provide Services and Workers’ Right to Collective Action

Hello! Today I’m introducing the Laval (2007) judgment. The dispute arose when a Latvian construction company posted workers to Sweden. As Swedish trade unions launched robust collective action over pay and working conditions, the company countered that its freedom to provide services had been infringed. This case made me revisit the question: “How far are labour rights protected, and how far do EU freedoms extend?” Let’s walk through the background, the judgment, and the takeaways.

Background and Facts

Latvian construction company Laval posted workers to Sweden to carry out a building project. Swedish trade unions considered that Laval did not apply wages and working conditions at the level of Swedish collective agreements and launched picketing and other collective action. Laval was effectively prevented from operating and argued that these measures infringed its freedom to provide services (Article 49 EC), bringing proceedings.

At its core, the case asked which principle prevails when the freedom to provide services conflicts with the right to collective action. The freedom to provide services is a cornerstone of the EU internal market, while the right to collective action has the character of a fundamental right.

Issue Freedom to Provide Services Right to Collective Action
Legal basis Article 49 EC ILO conventions; EU Charter of Fundamental Rights
Claim Guarantee cross-border freedom to provide services Protect workers and prevent deterioration of conditions
Concern Excessive collective action may restrict that freedom Market freedoms may weaken social rights

The Court’s Judgment and Reasoning

The CJEU acknowledged that the right to collective action is a fundamental right, but held it cannot be exercised so as to unduly restrict the freedom to provide services. In particular, the Swedish unions’ blockade was found to violate the principle of proportionality. Key points:

  • The right to collective action is fundamental but not absolute.
  • Even with the aim of worker protection, measures that excessively restrict services freedom will infringe EU law.
  • Proportionality review is required to balance labour rights and economic freedoms.

Impact on the EU Legal Order

Laval starkly exposed the collision between social rights and internal-market freedoms. While recognising the right to collective action, the CJEU effectively prioritised economic freedom by holding that it cannot be excessively restricted. Together with Viking, the case heightened the tension between “Social Europe” and “Economic Europe” within labour law.

Criticism and Academic Debate

The judgment drew criticism for subordinating workers’ rights to market freedoms, especially for allegedly pushing posted workers’ protection behind the freedom to provide services—seen as weakening “Social Europe.” Others take a more positive view, seeing an attempt to recognise both sets of rights and to apply proportionality.

Perspective Main Argument
Critical Collective action was subordinated to services freedom, weakening social rights
Supportive The Court considered both labour rights and market freedoms and applied proportionality

Contemporary Significance and Takeaways

Laval remains frequently cited where posted workers’ protection, the freedom to provide services, and collective action intersect. It is often labelled a case where economic freedoms trumped social rights, and it is a key reference when considering the balance between labour law and internal-market regulation. Key takeaways:

  • A leading precedent on the clash between services freedom and labour rights
  • Exposed limits of worker-protection tools and spurred debate on EU social policy
  • With Viking, a core authority in the “Social Europe” debate

Frequently Asked Questions (FAQ)

Q What was Laval about?

A Latvian construction company posted workers to Sweden; Swedish unions blockaded worksites over pay and conditions, triggering a clash between the freedom to provide services and the right to collective action.

Q What was the core issue?

Which right should prevail when the freedom to provide services conflicts with the right to collective action.

Q How did the Court rule?

It recognised the right to collective action but found the Swedish blockade disproportionately restricted the freedom to provide services, thus breaching proportionality.

Q Why is the case significant?

It is often taken to show that, in the internal market, economic freedoms can take precedence over social rights.

Q What were the main criticisms?

That the ruling subordinated workers’ rights to market freedoms and thus weakened “Social Europe,” particularly for posted workers.

Q Does it still matter today?

Yes. Laval, alongside Viking, is a must-cite when discussing the balance between EU social policy and internal-market regulation.

In Closing

Laval (2007) posed the tough question of “services freedom vs. labour rights,” and the Court’s proportionality analysis tipped the scale somewhat toward economic freedom. In practice, apply the four steps—legitimate aimsuitabilityless restrictive alternativesoverall balance. Also be specific about what counts as the “core working conditions” under the Posting of Workers Directive. If you have real-world scenarios or moot court topics, share them—I'll help you map arguments around Laval and link them to Viking. 🙂

Tuesday, November 25, 2025

Kadi (2008): Clash Between UN Sanctions and the EU Legal Order

Kadi (2008): Clash Between UN Sanctions and the EU Legal Order

“Even a UN Security Council resolution cannot override the EU’s protection of fundamental rights.” The Kadi judgment is a landmark in which the CJEU asserted the primacy of the EU’s constitutional order amid tensions with international law.


Kadi (2008): Clash Between UN Sanctions and the EU Legal Order


Hello! Today we examine Kadi (2008), a case that dramatically exposed the friction between international law and the EU legal order. When I first met this judgment, I wondered, “Can the EU really claim primacy over a UN Security Council resolution?” The CJEU boldly prioritized the autonomy of the EU’s constitutional order and the protection of fundamental rights. Beyond sanctions, the case raised big themes: the hierarchy between international and regional law, constitutional identity, and fundamental rights protection.

Background and Facts

The case began when Saudi businessman Yusuf Kadi was listed as a terrorism supporter under a UN Security Council resolution and became subject to sanctions. The UN required Member States to impose strong measures such as asset freezes, and the EU adopted regulations to implement them. As a result, Kadi’s assets were frozen and his economic activity curtailed. He brought an action before the EU courts alleging a violation of fundamental rights. The key question: what status does a UN Security Council resolution have within the EU legal order—and can the EU prioritize fundamental rights protection over it?

The central issue was whether the UN Security Council resolution outranks EU law. If so, the EU would have to prioritize implementation over fundamental rights; if not, it would confirm the stronger autonomy of the EU’s constitutional order.

Issue Primacy of UN Resolution Primacy of EU Constitutional Order
Status in International Law UNSC resolutions have absolute force for international peace and security The EU constitutional order is autonomous and independent
Fundamental Rights Rights may be limited to achieve international security goals Protection of fundamental rights is a core EU value warranting strict review
Practical Consequence The EU must accept UN sanctions unconditionally Even a UN resolution can be set aside within the EU if it violates fundamental rights

The Court’s Judgment and Reasoning

The CJEU boldly emphasized the autonomy of the EU constitutional order and ruled in Kadi’s favor. The Court did not deny the UN resolution itself; rather, it held that EU measures implementing that resolution must respect fundamental rights. Key points:

  • Even UN resolutions must comply with fundamental rights to have effect within the EU legal order.
  • The EU legal order is autonomous and does not recognize an automatic primacy of international law.
  • Protection of fundamental rights forms the EU’s core constitutional identity.

Impact on the EU Legal System

Kadi entrenched the autonomy of the EU legal order and protection of fundamental rights as paramount values. More than safeguarding an individual, it declared the EU an autonomous constitutional community vis-à-vis international law. Since then, EU institutions must build in fundamental-rights procedures and judicial review when adopting sanctions—strengthening the EU’s rule-of-law identity even under geopolitical pressure.

Criticism and Academic Debate

The ruling also drew criticism for potentially undermining the unity of international law and the authority of the UN Security Council. Some scholars asked whether the EU had adopted a kind of regional “constitutional isolationism.” Others praised the EU for strengthening human-rights protections and contributing to the development of international law.

Perspective Main Argument
Critical Weakens UNSC authority; disrupts coherence of international law; regionalist approach
Supportive Strengthens EU autonomy, deepens rights protection, and advances international human-rights law

Contemporary Significance and Takeaways

Today Kadi is widely seen as the emblem of the EU’s “constitutional autonomy.” The stance that fundamental rights take priority even when international law points the other way has deeply influenced later case law and sanctions policy. Key takeaways:

  • Even UN sanctions have limited effect within the EU if they violate EU fundamental rights
  • Positions the EU as an independent constitutional community
  • Sparks ongoing scholarly debate on the relationship between international and regional law

Frequently Asked Questions (FAQ)

Q What was the Kadi case about?

Saudi businessman Yusuf Kadi was listed under UN sanctions, leading to an EU asset freeze; he sued alleging violations of fundamental rights.

Q What was the core issue?

Whether UN Security Council resolutions prevail over the EU legal order, or whether the EU’s protection of fundamental rights takes priority.

Q How did the CJEU rule?

It did not deny the UN resolution itself, but held that for EU measures implementing it to have effect, they must comply with EU fundamental rights.

Q Why is the judgment significant?

It affirmed the autonomy of the EU constitutional order and prioritized fundamental rights over conflicting international obligations within the EU.

Q How do academics assess it?

Some criticize a risk of regional isolationism and weakened UNSC authority; others praise the strengthening of rights and contributions to international law.

Q Does it still matter today?

Yes. Kadi remains a central reference point for debates on EU constitutional autonomy and its relationship with international law.

In Closing

Kadi (2008) sends the message that “fundamental rights are the anchor in the rough seas of geopolitics.” When I study the case, I keep two keywords in view: the autonomy of the EU constitutional order and procedural and substantive rights review. Even where the goal of sanctions is legitimate, without safeguards like notice, a right to be heard, judicial remedies, and proportionality review, such measures have no place within the EU. If you’re working through sanctions or external-relations hypotheticals, share the facts and we can map out the argument in the Kadi framework together. 🙂

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right “How far can the state look into your body, your data, and your choi...