Skip to main content
Data Protection / GDPR

Schrems II

Schrems II is the Court of Justice of the European Union's judgment of 16 July 2020 in Case C-311/18, which invalidated the EU-US Privacy Shield and made the use of standard contractual clauses conditional on a case-by-case assessment of third-country law.

Schrems II is the common shorthand for the judgment handed down by the Grand Chamber of the Court of Justice of the European Union on 16 July 2020 in Case C-311/18 (Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems). The case originated in a complaint by the Austrian lawyer Max Schrems about transfers of his data to the United States; in 2015 the same litigant had already brought down the Safe Harbor arrangement with the Schrems I judgment (Case C-362/14). In Schrems II the Court declared the adequacy decision underpinning the EU-US Privacy Shield (Implementing Decision (EU) 2016/1250) invalid with immediate effect and without any transition period. The standard contractual clauses (Decision 2010/87/EU), by contrast, were upheld as valid in principle - but only subject to markedly stricter conditions of use.

The decisive reason for striking down the Privacy Shield was the access powers of US intelligence agencies, in particular under Section 702 FISA and Executive Order 12333. The Court held that these interferences were not limited to what is strictly necessary and therefore failed the proportionality test of Article 52(1) of the EU Charter of Fundamental Rights. In addition, data subjects in the EU had no effective remedy before an independent tribunal; the Privacy Shield ombudsperson did not satisfy the requirements of Article 47 of the Charter. The central yardstick of the ruling is that a third country must offer protection essentially equivalent to that guaranteed within the EU - regardless of which transfer instrument the export relies on.

In practice this creates a standing duty to assess every international transfer. Anyone relying on standard contractual clauses or binding corporate rules must establish beforehand whether the law and practice of the recipient country undermine the contractual safeguards and, where they do, adopt supplementary technical, organisational or contractual measures - otherwise the transfer must be suspended. This exercise has become known as the transfer impact assessment; the European Data Protection Board fleshed it out in Recommendations 01/2020, and in 2021 the Commission adopted the new modular standard contractual clauses (Implementing Decision (EU) 2021/914). Politically, Schrems II led via Executive Order 14086 and the newly created Data Protection Review Court to the adequacy decision for the EU-U.S. Data Privacy Framework of 10 July 2023. That framework remains contested: in September 2025 the General Court dismissed an action for annulment against the decision (Case T-553/23), but a final ruling by the Court of Justice is still outstanding. Organisations should therefore document their transfers carefully and plan for fallback scenarios.

Legal Basis

CJEU, judgment of 16 July 2020, Case C-311/18 (Schrems II); Articles 44 to 49 GDPR, in particular Article 45 and Article 46(2)(c) GDPR; Articles 47 and 52(1) of the EU Charter of Fundamental Rights; EDPB Recommendations 01/2020

Practical Example

A mid-sized machinery manufacturer runs its ticketing system with a US provider whose support teams access the data from several countries. The data protection officer first checks whether the provider is certified under the EU-U.S. Data Privacy Framework. Because only the US parent company is certified and not the group subsidiary in India that actually staffs support, the transfer is based on the standard contractual clauses and backed by a documented transfer impact assessment in the spirit of Schrems II: the officer records the categories of data transferred, assesses the relevant government access powers in the recipient country, reviews the provider's transparency report, and adds supplementary measures - encryption with keys held exclusively by the company and a contractual duty to notify any government access request without delay. The outcome is filed with the record of processing activities and scheduled for annual review.

FAQ

Yes - the Court expressly confirmed that the clauses remain valid. Signing them is not enough, however: the data exporter must assess in each case whether the law and practice of the third country allow the agreed safeguards to be effective. Where gaps in protection emerge, supplementary measures are required or the transfer must be suspended.
Only in part. Transfers to companies certified under the framework have been covered by an adequacy decision again since 10 July 2023, so no additional transfer instrument is needed. For every other recipient and for other third countries the Schrems II assessment duty still applies, and the judicial review of the decision has not been concluded definitively.
It documents the specific transfer with its data categories, recipients and destination country, evaluates the government access powers and legal remedies available there, and draws a conclusion from that analysis. If the level of protection falls short, supplementary measures such as strong encryption, pseudonymisation or contractual commitments must be defined. The assessment has to be reviewed and updated regularly.

How preeco supports you

Learn how our software supports you with this topic.

Learn more