Skip to main content
The state of ai impact assessment
Category: Cross-Border Transfers

Schrems II

Also known as: Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems, Case C-311/18
Simply put

Schrems II is the common name for a July 2020 ruling by the Court of Justice of the European Union in a case brought over the transfer of personal data from the EU to the United States. The Court struck down the EU-US Privacy Shield, the arrangement that had allowed many companies to send personal data to the US. As a result, organisations that transfer personal data outside the EU generally need to take additional steps to check that the data will be adequately protected.

Formal definition

Schrems II refers to the judgment of the Court of Justice of the European Union (Grand Chamber) of 16 July 2020 in Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems. The ruling invalidated the EU-US Privacy Shield Framework as a valid mechanism for transferring personal data from the EU to the United States. While the judgment did not invalidate Standard Contractual Clauses as a transfer mechanism, it held that data exporters and importers relying on them must assess, on a case-by-case basis, whether the legal regime of the destination jurisdiction affords protection essentially equivalent to that guaranteed within the EU, and adopt supplementary measures where necessary. The decision concerns transfers of personal data governed by EU data protection law and is a court ruling with binding legal effect, not a voluntary standard; its practical application to specific transfers requires case-specific assessment. Readers should note that the surrounding transfer framework (including any successor US adequacy arrangements and updated clauses) has continued to evolve, and this entry does not address post-2020 developments in detail. Verify against the current official text of the judgment and subsequent authoritative guidance.

Why it matters

Schrems II reshaped how organisations approach international data transfers under EU data protection law. By invalidating the EU-US Privacy Shield Framework, the Court of Justice of the European Union removed a mechanism that many companies had relied on to move personal data from the EU to the United States. Organisations that had structured transatlantic data flows around Privacy Shield were left needing an alternative lawful basis for those transfers, and the ruling's binding legal effect meant compliance could not be treated as optional.

The judgment's significance extends beyond the specific arrangement it struck down. The Court held that where data exporters and importers rely on Standard Contractual Clauses, they must assess on a case-by-case basis whether the legal regime of the destination jurisdiction provides protection essentially equivalent to that guaranteed within the EU, and adopt supplementary measures where the assessment reveals gaps. This shifted a meaningful compliance burden onto individual organisations, which must now evaluate the laws of receiving jurisdictions rather than assume a single overarching framework resolves the question.

Because the case concerns transfers governed by EU data protection law and carries binding legal force, it remains a reference point for compliance officers and legal counsel handling cross-border data flows. Readers should note that the surrounding transfer landscape has continued to evolve since 2020, including through subsequent US adequacy arrangements and updated clauses, and any assessment of current obligations requires verification against the latest authoritative guidance rather than reliance on the 2020 position alone.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for lawful international data transfers must understand that Privacy Shield is no longer a valid basis and that reliance on Standard Contractual Clauses now generally requires a case-by-case assessment of the destination jurisdiction, together with supplementary measures where the protection is not essentially equivalent to that guaranteed within the EU.
Legal counsel and compliance officers
Advisers handling cross-border data flows governed by EU data protection law should treat Schrems II as binding case law with direct practical consequences. Application to specific transfers requires professional judgment, and the surrounding transfer framework has continued to evolve since 2020, so current obligations should be verified against the latest authoritative guidance.
Organisations transferring personal data from the EU to the United States or other non-EU jurisdictions
Businesses that move personal or sensitive data out of the EU are directly affected, as the ruling underscores the need to ensure such data remains adequately protected and may require additional steps beyond the transfer mechanism previously in place.
Auditors and assessors reviewing transfer arrangements
Professionals evaluating an organisation's data transfer practices need to check whether reliance on invalidated mechanisms has been remediated and whether case-by-case transfer impact assessments and supplementary measures are documented where applicable.

Inside Schrems II

Invalidation of the Privacy Shield
The decision struck down the EU-US Privacy Shield framework as a valid mechanism for transferring personal data from the EU/EEA to the United States, on the basis that it did not provide protection essentially equivalent to that guaranteed within the EU. Note that a successor arrangement (the EU-US Data Privacy Framework) was subsequently adopted; readers should verify the current status of transatlantic transfer mechanisms against the latest official sources.
Continued validity of Standard Contractual Clauses (SCCs)
The ruling upheld SCCs as a lawful transfer tool in principle, but conditioned their use on a case-by-case assessment. Reliance on SCCs alone is generally not sufficient where the law or practice of the destination country undermines the protections the clauses promise.
Transfer impact assessment obligation
The decision effectively requires data exporters to evaluate whether the legal regime of the recipient country—particularly government access to data for surveillance purposes—prevents the SCCs from being honored in practice. Where it does, exporters must consider supplementary measures or suspend the transfer.
Supplementary measures
Where a destination country's protections fall short, exporters may need additional technical, contractual, or organizational safeguards to raise protection to an essentially equivalent level. The adequacy of any given measure is fact-specific and interpretation continues to evolve through regulator guidance.
Essential equivalence standard
The benchmark applied is not identical protection but protection 'essentially equivalent' to that afforded under EU law, including the Charter of Fundamental Rights. This assessment covers both the destination country's substantive protections and the availability of effective redress for data subjects.
Scope and legal character
Schrems II is a judgment of the Court of Justice of the European Union interpreting the GDPR and EU primary law; it is binding as an authoritative interpretation of EU law rather than a standalone regulation. It concerns transfers of personal data out of the EU/EEA and is most commonly discussed in the EU-US context, though its reasoning extends to transfers to any third country.

Common questions

Answers to the questions practitioners most commonly ask about Schrems II.

Did Schrems II ban all transfers of personal data from the EU to the United States?
No. Schrems II did not impose a blanket prohibition on EU–US data transfers. The judgment invalidated the EU–US Privacy Shield framework as a valid transfer mechanism, but it expressly upheld Standard Contractual Clauses (SCCs) as a mechanism that can, in principle, still be used. The key qualification is that parties relying on SCCs or other Article 46 GDPR mechanisms must assess, on a case-by-case basis, whether the law and practice in the destination country provide protection essentially equivalent to that guaranteed within the EU, and must implement supplementary measures where that assessment identifies gaps. Whether a given transfer is lawful therefore depends on the specific circumstances rather than on the destination country alone.
Do Standard Contractual Clauses on their own guarantee that a data transfer is lawful after Schrems II?
No. A common misconception is that executing SCCs is sufficient in itself. Schrems II clarified that SCCs are a contractual instrument binding only on the parties that sign them and cannot, by themselves, bind public authorities in a third country or override that country's surveillance laws. The data exporter (and, where relevant, the importer) is generally expected to evaluate whether the destination legal framework undermines the protections in the clauses and, if so, to adopt supplementary measures or refrain from the transfer. SCCs are a starting point that must be accompanied by a substantive assessment, not a self-executing guarantee of compliance.
What is a transfer impact assessment and when is it generally expected?
A transfer impact assessment (sometimes called a TIA) is the documented evaluation an organisation generally undertakes to determine whether personal data transferred to a third country will receive protection essentially equivalent to that required under EU law. It typically considers the transfer mechanism relied upon, the nature and sensitivity of the data, the laws and practices of the destination country (including government access and surveillance powers), and whether any supplementary measures are needed. Such an assessment is generally expected whenever an organisation relies on Article 46 GDPR transfer tools, such as SCCs, for transfers to countries not covered by an adequacy decision. The exact form is not prescribed in detail, so organisations should follow current guidance from the relevant supervisory authorities and verify against the latest official sources.
What kinds of supplementary measures might an organisation consider following Schrems II?
Supplementary measures are generally grouped into technical, contractual, and organisational categories. Technical measures may include strong encryption or pseudonymisation configured so that the data importer or third-country authorities cannot access the data in intelligible form. Contractual measures may include additional commitments regarding transparency, challenge of access requests, and notification. Organisational measures may include internal policies, access controls, and documented handling of government access requests. The appropriate combination depends on the outcome of the transfer impact assessment, and regulatory guidance has emphasised that contractual and organisational measures alone may be insufficient where destination-country law permits problematic access. Because supervisory authority guidance in this area continues to evolve, readers should verify current expectations against the latest authoritative sources.
How does Schrems II affect an organisation's choice between different transfer mechanisms?
Schrems II removed reliance on the EU–US Privacy Shield and reinforced that the essential-equivalence assessment applies across Article 46 GDPR mechanisms, including SCCs and binding corporate rules. As a practical matter, organisations generally cannot treat the mere selection of a mechanism as the end of their analysis; they must also assess the destination legal environment and supplementary measures. Where an adequacy decision covers the destination country or a specific framework, transfers may proceed on that basis without the case-by-case assessment required for Article 46 tools, though adequacy decisions themselves can be subject to legal challenge and change over time. The suitability of any mechanism is fact-specific and should be verified against the current legal framework.
What documentation and accountability steps are generally advisable in response to Schrems II?
Consistent with the accountability principle in the GDPR, organisations are generally advised to maintain records of their transfer mapping, the mechanism relied upon for each transfer, the transfer impact assessments performed, and the supplementary measures adopted or the reasoning where none were considered necessary. Keeping this documentation current supports the ability to demonstrate compliance to supervisory authorities and to respond to challenges. Because enforcement practice and guidance in this area continue to develop and may differ across EU supervisory authorities, the specific documentation expectations should be confirmed against the latest official guidance. This description is informational and applying it to particular transfers requires professional judgment.

Common misconceptions

Schrems II banned all data transfers from the EU to the United States.
It invalidated the Privacy Shield but did not prohibit US transfers outright. Transfers remained possible under other mechanisms such as SCCs, subject to a case-by-case assessment and, where necessary, supplementary measures. A successor framework has since been adopted, so practitioners should confirm the currently available mechanisms.
Signing Standard Contractual Clauses is by itself enough to make a transfer lawful after Schrems II.
The judgment kept SCCs valid in principle but made clear that exporters must assess whether the destination country's laws and practices actually allow the clauses to be honored. Where they do not, additional safeguards may be required or the transfer may need to be suspended.
Schrems II is a regulation that imposes fixed compliance steps.
It is a court judgment interpreting existing EU data protection law, not a new regulation with a prescribed checklist. The obligations it clarifies are fact-specific, and the practical expectations continue to develop through subsequent regulator guidance and enforcement practice.

Best practices

Maintain an inventory of international personal data transfers, identifying the destination country, the transfer mechanism relied upon, and the categories of data involved.
Conduct and document a transfer impact assessment for transfers to third countries, evaluating whether local laws and practices could prevent the chosen mechanism from being honored.
Where a destination country's protections may fall short, evaluate supplementary technical, contractual, and organizational measures, and document the reasoning behind their selection or the decision to suspend a transfer.
Reassess the transfer mechanisms you rely on in light of the evolving landscape, including successor arrangements to the Privacy Shield, and verify their current validity against the latest official sources.
Keep records of assessments and safeguards to demonstrate accountability, recognizing that regulator expectations and enforcement practice in this area continue to develop.
Engage qualified data protection and legal professionals for transfers involving higher-risk data or jurisdictions, since application of Schrems II to specific circumstances requires professional judgment.
Promotional banner for the Penetration Report Template Kit