Showing posts with label SCCs. Show all posts
Showing posts with label SCCs. Show all posts

Thursday, December 4, 2025

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

“If EU citizens’ data goes to the United States, will it still receive GDPR-level protection?” Schrems II rewrote the balance between global data flows and fundamental rights.


Schrems II (2020): The Crossroads of Data Transfers and Privacy Protection

Hello! Today we look at Schrems II (2020). Brought by Austrian privacy activist Max Schrems, the case centered on concerns that personal data transferred from the EU to the U.S. could be exposed to large-scale surveillance by U.S. intelligence agencies. In particular, the constitutionality—better, the validity—of the Privacy Shield framework (adopted after Safe Harbor was invalidated) was back under scrutiny. Studying this judgment made me realize that the idea of “data borders” is anything but abstract.

Background and Facts

The case began with Austrian privacy advocate Max Schrems suing Facebook Ireland. Schrems argued that when EU citizens’ data is transferred to the United States, it may be subject to extensive surveillance by U.S. intelligence agencies (notably the NSA). In his view, this fails to meet the GDPR’s requirement of an “essentially equivalent” level of protection. After the 2015 Schrems I ruling had already invalidated Safe Harbor, this case targeted its successor, the EU-U.S. Privacy Shield.

The question was whether the Privacy Shield framework meets the level of protection required by the GDPR. The breadth of U.S. surveillance programs and the lack of adequate judicial redress for EU citizens were central concerns.

Issue Problems with Privacy Shield GDPR Requirements
Scope of surveillance Allows large-scale collection by U.S. government Only necessary and proportionate surveillance allowed
Judicial redress EU citizens lack effective remedies in U.S. courts Remedies must be effective and accessible
Level of protection Not equivalent to the EU level Protection essentially equivalent to (or exceeding) GDPR

The Judgment and Reasoning

The CJEU held that Privacy Shield is invalid. However, it deemed Standard Contractual Clauses (SCCs) valid in principle, while emphasizing that national supervisory authorities must assess the level of protection in each particular case. The reasoning:

  • U.S. surveillance programs do not satisfy necessity and proportionality.
  • EU citizens lack effective judicial redress in the United States.
  • SCCs remain valid, but controllers/processors and supervisory authorities must verify case-by-case whether equivalent protection is ensured.

Impact on the EU Legal System

Schrems II brought sweeping changes to EU-U.S. data transfers. Privacy Shield was invalidated immediately, confronting thousands of companies with legal uncertainty. In response, the EU and the U.S. negotiated a new framework—the EU-U.S. Data Privacy Framework—and supervisory authorities took on stricter oversight of SCCs. The ruling strengthened the global effect of the GDPR and amplified worldwide debates on data sovereignty.

Criticism and Academic Debate

While hailed for strengthening privacy, Schrems II has also been criticized for imposing heavy practical burdens on companies and regulators.

Perspective Main Argument
Critical Greater uncertainty for data transfers; potential chill on global business
Supportive Firmly protects EU citizens’ fundamental data rights and elevates the GDPR’s global standing

Contemporary Significance and Takeaways

Schrems II remains a reference point for governing international data flows—not only for the EU-U.S. relationship but also for legislation in India, Brazil, Korea, and beyond. Key takeaways:

  • Exposes the fragility of transfer frameworks (e.g., Privacy Shield) and calls for new models of international cooperation
  • Reinforces the GDPR’s global standard-setting effect, influencing foreign legislation
  • Emphasizes the shared responsibility of companies and regulators to verify “concrete protective measures”

Frequently Asked Questions (FAQ)

Q What is the core of Schrems II?

The validity of the EU-U.S. Privacy Shield, the applicability of SCCs, and the role of supervisory authorities (DPAs) in overseeing transfers.

Q How did the CJEU rule on Privacy Shield?

It invalidated Privacy Shield due to the breadth of U.S. surveillance and insufficient redress mechanisms.

Q What happened to SCCs?

They remain valid in principle, but DPAs must verify in each transfer whether an equivalent level of protection is ensured.

Q What should companies do after the ruling?

Use SCCs together with a Transfer Impact Assessment (TIA), implement supplementary measures (encryption, pseudonymization), and review local surveillance laws.

Q What is its significance today?

Schrems II strengthened the GDPR’s international influence and spurred debates on data sovereignty and surveillance reform.

In Closing

Schrems II (2020) makes clear that data flows are not merely technical—they are tied directly to fundamental rights. For exams and practice, structure your analysis around ① Privacy Shield invalid, ② SCCs valid with conditional verification, and ③ surveillance programs and redress gaps. Emphasizing the Transfer Impact Assessment (TIA) and supplementary measures will align you with current GDPR enforcement trends. This case convinced me that “data is the new border.” The topic will only heat up—so keep a close eye on cases and controversies. 🙂

Sunday, November 30, 2025

Schrems I (2015): The Invalidation of Safe Harbor and Protecting Personal Data Across Borders

Schrems I (2015): The Invalidation of Safe Harbor and Protecting Personal Data Across Borders

“When personal data crosses the Atlantic, does its protection cross with it?” Schrems I shook the foundations of EU–US data-transfer arrangements.


Schrems I (2015): The Invalidation of Safe Harbor and Protecting Personal Data Across Borders

Hello! Today we’re unpacking Schrems I (2015). Brought by Austrian lawyer and privacy activist Max Schrems, the case raised fundamental doubts about how US companies handle EU residents’ data. In particular, it questioned whether the Safe Harbor framework could protect Europeans against large-scale surveillance by US intelligence agencies such as the NSA. The ruling went far beyond striking down a single framework—it reset the legal baseline for international data transfers in the digital age.

Background and Facts

Austrian law student turned lawyer Max Schrems argued that his Facebook data, transferred to the United States, could be subject to surveillance by US intelligence services such as the NSA. At the time, the EU–US Safe Harbor framework permitted transfers of personal data to the US. Schrems contended that the framework failed to ensure the protection of personal data guaranteed by the EU Charter of Fundamental Rights. When the Irish Data Protection Authority rejected his complaint, the matter was referred to the CJEU.

The central question: Did Safe Harbor ensure a sufficient level of protection for EU personal data? In particular, given potential access by US authorities engaged in large-scale surveillance, was the framework still valid?

Issue Safe Harbor Framework Data Protection
Legal basis EU–US Safe Harbor Framework EU Charter of Fundamental Rights, Arts. 7 & 8
Argument International mechanism enabling data transfers Mass surveillance undermines effective protection
Concern Lack of meaningful limits on US authorities’ access Risks to private life and data sovereignty

The Judgment and Reasoning

The CJEU held that Safe Harbor did not ensure adequate protection for EU citizens’ personal data and declared it invalid. In the context of broad potential access by US authorities, the framework did not satisfy the Charter. Key points:

  • Safe Harbor failed to guarantee a level of protection that is “essentially equivalent” to that in the EU.
  • Generalised access for US authorities breached the principles of proportionality and necessity.
  • National Data Protection Authorities (DPAs) must safeguard fundamental rights and are not stripped of their powers by an EU adequacy decision.

Impact on the EU Legal Order

Schrems I fundamentally reset the criteria for international data transfers in EU law, affirming that data protection is a constitutional fundamental right, not a mere technical issue. After Safe Harbor was invalidated, the EU and US adopted the Privacy Shield, which was later struck down in Schrems II. Schrems I strengthened the notion of data sovereignty and became a key reference point in regulating global big tech.

Criticism and Academic Debate

While praised for strengthening privacy, the ruling also triggered significant uncertainty for transatlantic data flows. In practice and in scholarship, views diverged as follows:

Perspective Main Argument
Critical Created legal uncertainty for international data transfers; placed heavy burdens on businesses
Supportive Delivered real protection for EU citizens and set a new global regulatory benchmark

Contemporary Significance and Takeaways

Schrems I remains central to discussions on cross-border data transfers and big-tech regulation. Under the GDPR, it informs interpretation of Chapter V on transfers to third countries. Key takeaways:

  • Confirms that data transfers are directly tied to constitutional fundamental-rights protection
  • Establishes continuity: Safe Harbor invalidation → Privacy Shield → Schrems II
  • A watershed moment for strengthening accountability of global tech firms

Frequently Asked Questions (FAQ)

Q What is Schrems I?

A 2015 CJEU judgment invalidating the EU–US Safe Harbor framework on the ground that transfers to the US did not ensure adequate protection for EU personal data.

Q Who brought the case?

Max Schrems, then a law student and privacy activist from Austria, in a complaint related to Facebook.

Q What was the core holding?

Safe Harbor did not provide an “essentially equivalent” level of protection as required by the EU Charter and EU law.

Q Why was it invalidated?

Because US authorities could engage in indiscriminate surveillance, meaning EU citizens’ data could not be effectively protected.

Q What happened next?

There was a regulatory gap in transatlantic transfers, leading to the Privacy Shield—later invalidated in Schrems II.

Q Is it still relevant today?

Yes. Schrems I set the stage for Schrems II and continues to guide the interpretation of GDPR rules on third-country transfers.

In Closing

Schrems I (2015) overturned the old assumption that “when data travels, rights don’t.” For practical analysis, check: ① essentially equivalent protection under the adequacy decision, ② the scope and control of state surveillance, and ③ availability of legal redress. If any of these are weak, a third-country transfer is a red flag. In practice, Standard Contractual Clauses (SCCs), supplementary measures, and a Transfer Impact Assessment (TIA) can mitigate risks—but structural surveillance issues can still unsettle an entire framework. If you have a scenario or need help drafting a TIA, share the facts and we’ll build a checklist together. 🙂

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right

Puttaswamy (Privacy) (India, 2017): Privacy Is a Fundamental Right “How far can the state look into your body, your data, and your choi...