Schrems II
Schrems II is the common name for a July 2020 ruling by the Court of Justice of the European Union in a case brought over the transfer of personal data from the EU to the United States. The Court struck down the EU-US Privacy Shield, the arrangement that had allowed many companies to send personal data to the US. As a result, organisations that transfer personal data outside the EU generally need to take additional steps to check that the data will be adequately protected.
Schrems II refers to the judgment of the Court of Justice of the European Union (Grand Chamber) of 16 July 2020 in Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems. The ruling invalidated the EU-US Privacy Shield Framework as a valid mechanism for transferring personal data from the EU to the United States. While the judgment did not invalidate Standard Contractual Clauses as a transfer mechanism, it held that data exporters and importers relying on them must assess, on a case-by-case basis, whether the legal regime of the destination jurisdiction affords protection essentially equivalent to that guaranteed within the EU, and adopt supplementary measures where necessary. The decision concerns transfers of personal data governed by EU data protection law and is a court ruling with binding legal effect, not a voluntary standard; its practical application to specific transfers requires case-specific assessment. Readers should note that the surrounding transfer framework (including any successor US adequacy arrangements and updated clauses) has continued to evolve, and this entry does not address post-2020 developments in detail. Verify against the current official text of the judgment and subsequent authoritative guidance.
Why it matters
Schrems II reshaped how organisations approach international data transfers under EU data protection law. By invalidating the EU-US Privacy Shield Framework, the Court of Justice of the European Union removed a mechanism that many companies had relied on to move personal data from the EU to the United States. Organisations that had structured transatlantic data flows around Privacy Shield were left needing an alternative lawful basis for those transfers, and the ruling's binding legal effect meant compliance could not be treated as optional.
The judgment's significance extends beyond the specific arrangement it struck down. The Court held that where data exporters and importers rely on Standard Contractual Clauses, they must assess on a case-by-case basis whether the legal regime of the destination jurisdiction provides protection essentially equivalent to that guaranteed within the EU, and adopt supplementary measures where the assessment reveals gaps. This shifted a meaningful compliance burden onto individual organisations, which must now evaluate the laws of receiving jurisdictions rather than assume a single overarching framework resolves the question.
Because the case concerns transfers governed by EU data protection law and carries binding legal force, it remains a reference point for compliance officers and legal counsel handling cross-border data flows. Readers should note that the surrounding transfer landscape has continued to evolve since 2020, including through subsequent US adequacy arrangements and updated clauses, and any assessment of current obligations requires verification against the latest authoritative guidance rather than reliance on the 2020 position alone.
Who it's relevant to
Inside Schrems II
Common questions
Answers to the questions practitioners most commonly ask about Schrems II.
