The Saga of Schrems II and Data Transfers Between the EU and the United States

The Saga of Schrems II and Data Transfers Between the EU and the United States

Privacy rights, international data transfers, and Schrems II have become central topics in the discussion around digital rights. In this article, I have tried to summarize the history of the data transfer frameworks between the EU and the United States.

The protection of privacy and personal data is a fundamental right under European law. The EU has a strong regulatory framework, called the General Data Protection Regulation (GDPR), which regulates the processing of personal data and contains specific rules for transferring personal data from the EU/EEA to third countries.

In the United States, the approach to privacy is somewhat different. Historically, the United States has not had one unified, cross-sector federal privacy law equivalent to the GDPR. The U.S. privacy regime is based to a greater extent on a combination of federal sector-specific laws, state legislation, regulation, and enforcement by bodies such as the Federal Trade Commission. This difference in approach to privacy has long created challenges when it comes to transferring personal data between the EU and the United States.

Safe Harbor (2000)

In 2000, the European Commission adopted an adequacy decision for the so-called U.S.-EU Safe Harbor framework. The arrangement made it possible to transfer personal data to U.S. companies that had certified themselves under the Safe Harbor principles.

The goal of the agreement was to ensure secure data exchange between the EU and the United States. The Data Protection Directive already regulated transfers to third countries, but Safe Harbor established a special arrangement that made it easier to transfer personal data to participating U.S. companies. To solve this, the Safe Harbor framework was created, introducing a system in which U.S. companies could commit to privacy principles.

  1. Data transfer and protection
    Safe Harbor was established to enable the lawful transfer of personal data between the EU and the United States, based on U.S. companies committing to maintaining an adequate level of privacy protection.

  2. Self-certification
    U.S. companies could self-certify under Safe Harbor by following specific guidelines and complying with data protection standards that were considered adequate by the EU.

  3. Limited control and oversight
    The arrangement was based on self-certification, but also included control and enforcement mechanisms, including through the Federal Trade Commission and private dispute resolution mechanisms. Self-certification was not in itself contrary to EU law, but the system depended on effective mechanisms for control and enforcement. Later, concerns arose in particular around protection against U.S. authorities’ access to personal data.

Max Schrems Enters the Scene (2015)

In 2015, Max Schrems, an Austrian privacy activist, came to prominence through his central role in challenging the validity of Safe Harbor. Schrems had complained to the Irish data protection authority about Facebook Ireland’s transfer of his personal data to the United States. After the complaint was rejected, the case went to the Irish courts, which referred questions to the Court of Justice of the European Union. That year, the Court of Justice declared the Safe Harbor decision invalid.

Schrems’ actions exposed serious shortcomings in Safe Harbor, especially regarding the protection of European citizens against U.S. surveillance and interference with personal data. The Safe Harbor principles did not bind U.S. public authorities, and requirements related to matters such as national security and law enforcement could take precedence over the principles. The Court also found shortcomings regarding limitations on government interference and the possibility of effective judicial review. This court decision paved the way for the establishment of a new arrangement, Privacy Shield, and initiated a critical legal discussion. Max Schrems therefore had a significant influence on changes to privacy protection for Europeans in international data transfers.

Privacy Shield (2016)

The purpose of Privacy Shield was to ensure that personal data transferred to participating U.S. companies was processed with adequate protection and in accordance with European privacy standards.

  1. Strengthened oversight and enforcement
    Privacy Shield introduced stronger control by U.S. authorities to ensure that companies complied with the rules.
    Improvement from Safe Harbor: Privacy Shield retained the self-certification model, but strengthened government control of certification, recertification, and compliance. The arrangement also included an annual joint review between the EU and the United States.

  2. Requirements for data security and accountability
    U.S. companies had to meet stricter data security requirements, including measures for data integrity and specific requirements to inform users about their rights.
    Improvement from Safe Harbor: Privacy Shield had more concrete and detailed requirements for data processing, while Safe Harbor was more general and left companies more freedom in how they complied with the guidelines.

  3. Introduction of an ombudsperson for EU citizens
    Privacy Shield established a new ombudsperson mechanism within the U.S. Department of State for complaints related to U.S. signals intelligence. At the time of adoption, the European Commission considered that the mechanism provided independent oversight, but the Court of Justice later concluded in Schrems II that the arrangement did not provide an effective remedy with guarantees essentially equivalent to those required under EU law.
    Improvement from Safe Harbor: Safe Harbor lacked a corresponding control mechanism for this type of complaint.

  4. Strengthened right to complain and protection of individual rights
    Privacy Shield gave EU citizens clearer complaint mechanisms, with several opportunities to challenge data handling through companies, dispute resolution bodies, and relevant authorities.
    Improvement from Safe Harbor: Safe Harbor had fewer available complaint routes for individuals.

  5. Annual review between the EU and the United States
    Privacy Shield required an annual review of the arrangement, in which the EU and the United States would jointly evaluate how the arrangement was implemented and propose improvements.
    Improvement from Safe Harbor: Safe Harbor lacked such a regular joint review.

  6. Increased transparency regarding government access
    Privacy Shield contained more extensive U.S. explanations and commitments regarding which rules, limitations, control mechanisms, and complaint options applied to government access to data. This provided greater institutional transparency than under Safe Harbor, but did not create a general right for individuals to know whether U.S. intelligence authorities had accessed their data.
    Improvement from Safe Harbor: Safe Harbor did not contain comparable extensive explanations of the rules and control mechanisms surrounding government access.

Schrems II: Privacy Shield Declared Invalid (2020)

The Privacy Shield decision was declared invalid by the Court of Justice of the European Union on July 16, 2020. This decision came as a result of the Schrems II case, brought by Max Schrems.

In the Schrems II case, Max Schrems argued that the privacy of European citizens was still not adequately protected when personal data was transferred to the United States. He claimed that U.S. law allowed authorities to access and process personal data in a way that was incompatible with European privacy standards.

The Court of Justice shared Schrems’ concerns and declared the Privacy Shield decision invalid. The ruling was based on two central problems. First, the Court found that the limitations on U.S. intelligence authorities’ access to personal data did not provide protection essentially equivalent to that required under EU law, including in light of the requirements of necessity and proportionality. Second, the Court found that data subjects did not have sufficiently effective and enforceable remedies against U.S. authorities. The Privacy Shield ombudsperson could not remedy these shortcomings.

This decision meant that the Privacy Shield framework could no longer be used as a valid mechanism for transferring personal data between the EU and the United States. It created significant uncertainty around international data transfers, but other transfer mechanisms under the GDPR remained available.

After Schrems II in 2020, Privacy Shield could no longer be used as a transfer basis. Organizations therefore had to base transfers to the United States on other mechanisms under the GDPR, including standard contractual clauses or binding corporate rules where the conditions were met. The Schrems II case was therefore an important reminder of the need to safeguard privacy rights in international data transfers and to facilitate more robust and secure practices in this area.

The Schrems II Judgment

The Schrems II case challenged the transfer of personal data from the EU to the United States and aimed to assess the validity of standard contractual clauses, which are a common mechanism for such transfers. The Court of Justice decided the case in 2020 and confirmed that standard contractual clauses could still be used to transfer personal data to third countries.

However, the Court pointed out that organizations relying on standard contractual clauses for transfers had to assess whether the laws and practices of the recipient country could undermine the protection the clauses were intended to provide. If the standard contractual clauses alone did not ensure a level of protection essentially equivalent to the European level, the organization had to assess effective supplementary measures. If sufficient protection could not be achieved, the transfer had to be suspended.

The Schrems II case therefore had a major impact on international data transfers and emphasized the need for a thorough assessment of privacy risks when transferring personal data to third countries, with particular attention paid to the third country’s legal rules and practices, public authority access, remedies, and the possibility of maintaining the safeguards in the transfer mechanism.

In 2021, the European Commission adopted a new set of standard contractual clauses for the transfer of personal data to third countries. The new clauses were adapted to the GDPR and the legal situation that followed, among other things, from Schrems II.

New U.S. Safeguards (2022)

After Schrems II, the United States introduced new safeguards for U.S. signals intelligence through Executive Order 14086. Among other things, new requirements relating to necessity and proportionality were introduced, as well as a new two-step system for handling complaints.

The new system includes the Civil Liberties Protection Officer at the Office of the Director of National Intelligence and, subsequently, the Data Protection Review Court (DPRC). The system was among the measures intended to address the criticism from Schrems II, particularly regarding the remedies individuals have against U.S. authorities’ access to personal data.

The European Commission considered these changes central when it later assessed whether the United States could once again offer an adequate level of protection for certain data transfers.

EU-U.S. Data Privacy Framework (2023)

On July 10, 2023, the European Commission adopted a new adequacy decision for the EU-U.S. Data Privacy Framework (DPF).

The arrangement means that personal data can be transferred from the EU/EEA to U.S. commercial organizations participating in the DPF without standard contractual clauses or other safeguards under Article 46 of the GDPR having to be used as the transfer basis itself.

The United States has therefore not received a general adequacy decision covering all U.S. companies. The DPF is based on qualified U.S. organizations certifying that they comply with the DPF principles. The Department of Commerce maintains a public list of participating organizations, which must recertify annually.

For U.S. recipients that are not covered by the DPF, there must still be another valid transfer basis under Chapter V of the GDPR.

The DPF remains in force. However, the arrangement is subject to ongoing review. The first review of the framework was conducted in 2024, and European data protection authorities have, among other things, recommended continued monitoring of developments in U.S. intelligence legislation. In September 2025, the EU General Court dismissed a lawsuit against the DPF decision.

The history of data transfers between the EU and the United States therefore did not end with Schrems II. After Safe Harbor and Privacy Shield were declared invalid, the United States and the EU attempted to establish a third framework that responds to the criticism from the Court of Justice. The European Commission has concluded that the new U.S. safeguards meet the requirements for an adequate level of protection for organizations covered by the DPF. Whether this framework will prove more robust than its predecessors remains to be seen.