What the court decided
On 16 July 2020 the Court of Justice of the European Union delivered its judgment in Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximilian Schrems. Two findings, in opposite directions.
The EU-US Privacy Shield was invalidated, with immediate effect. More than five thousand American companies had been relying on it to receive personal data from Europe. On that morning it stopped being a lawful basis, with no transition period.
Standard contractual clauses survived - conditionally. These are pre-approved contract terms that an exporter and an importer of data sign. The court held they remain valid in principle, but attached a requirement that changed what signing one means: the exporter must assess, case by case, whether the law of the recipient country actually guarantees in practice the level of protection the clauses promise. A contract between two companies cannot bind a government that is not party to it, so the exporter has to look at the government.
That is why this is a security article and not only a legal one. The court moved the question from "have we signed the right paperwork" to "what can the state where this data lands compel the recipient to do". That is a technical and architectural question, and it is answered with system design rather than with signatures.
The reasoning, which is a security assessment
Strip away the legal vocabulary and the judgment reads like a threat model.
The court examined United States surveillance authorities - section 702 of the Foreign Intelligence Surveillance Act, Executive Order 12333, and Presidential Policy Directive 28 - and concluded that programmes based on them could not be regarded as limited to what is strictly necessary, which is the standard the EU Charter of Fundamental Rights requires. It found that the limitations on protection arising from American domestic law were not circumscribed in a way that satisfies requirements essentially equivalent to those under EU law.
It then looked at redress. The Privacy Shield had offered an Ombudsperson at the State Department. The court found that this person was neither independent of the executive nor empowered to issue binding decisions against the intelligence agencies - so a European whose data had been collected had, in practice, nowhere to go.
And one factual finding deserves particular attention from readers of this catalogue. The Irish High Court had established, and the CJEU noted, that Executive Order 12333 permits the National Security Agency to access submarine cables and to collect and retain data before it arrives in the United States.
That is the Room 641A infrastructure, described in a European judgment as a finding of fact. The EFF spent sixteen years litigating over that splitter without a court ever ruling on whether the programme was lawful. A different court, in a different jurisdiction, took the same facts and used them to invalidate a trade framework. The Crypto Wars article traces the same question through policy; this is what happens when it reaches a bench that is willing to answer it.
The mistake practitioners make
The common reading is "keep the data in an EU region and the problem goes away". That is not what the judgment says, and the gap is worth understanding precisely.
The court's concern is who can be compelled, not where the disk is. A provider subject to a jurisdiction's compulsory process can be ordered to produce data it holds or can obtain, including from infrastructure it operates elsewhere. Selecting a European region on a console does not by itself change which government can serve an order on the company operating the console.
Which produces the question that actually determines the answer: who holds the keys, and can they be compelled to use them? If the provider can decrypt, then the provider's jurisdiction is in scope. If the customer holds keys the provider genuinely cannot obtain, the analysis changes - and this is exactly the exceptional access argument arriving from the commercial side rather than the political one. Clipper was about whether a government could be given a key. is about what follows, legally, from a provider having one.
The clean case the judgment leaves open is the one with no transfer at all: personal data processed by a provider established in the union and processed entirely within it. Then there is no third country and the analysis does not begin.
Why this belongs on a practitioner's reading list
It is a configuration question with legal force. For anyone deploying a cloud-delivered security service - the broker in a zero-trust architecture, a cloud access broker, a secure web gateway - the tenant's region, the location of the inspection point, whether logs leave the region, and who holds the decryption keys are all settings. After Schrems II they are also legal positions, and the person who configures them is making a compliance decision whether or not anyone told them so.
It rewards knowing what your product actually does with data. The assessments the judgment requires cannot be completed from a datasheet. They need answers to questions like where metadata is processed, whether support engineers in another country can view customer data, where backups replicate to, and what happens during a failover. Those are questions a practitioner can answer and a lawyer cannot.
And it is not settled. A successor framework, the EU-US , came into force in July 2023 on the basis of a further American executive order. Its durability is contested, and reporting in mid-2026 noted that a United States Supreme Court decision questioning the independence of the Federal Trade Commission - which has a central supervisory role in the framework - had put its standing under discussion. Anyone designing a system on the assumption that this is finished should notice that the same question has now been litigated three times and has produced two invalidations.
For readers under Brazil's , the structure is familiar rather than identical: a regime with its own chapter on international transfers, modelled on the European approach, with its own authority deciding what counts as adequate. The specifics differ and change; the underlying question - whose law reaches this data, and what does that law permit - is the same one, and it is answered by architecture.
This article describes what a court decided and what follows technically. It is not legal advice, and the assessments the judgment requires are the kind that need a lawyer as well as an engineer.
Sources
- Norton Rose Fulbright, detailed analysis: on 16 July 2020 the CJEU published its decision in Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximilian Schrems; the EU-US Privacy Shield was completely invalidated while the standard contractual clauses remain valid but with strict conditions; the judgment is not clear as to how satisfactory compliance should be achieved, and organisations were advised to map international data flows and existing transfer mechanisms carefully
- Bird & Bird, quoting the judgment: the CJEU noted the Irish High Court's finding that Executive Order 12333 allows the NSA to access submarine cables and to collect and retain data before it arrives in the US; the court concluded that section 702 FISA, EO 12333 and PPD-28 do not correlate to the minimum safeguards, with the consequence that surveillance programmes based on those provisions cannot be regarded as limited to what is strictly necessary; the limitations on the protection of personal data arising from United States domestic law are not circumscribed in a way that satisfies requirements essentially equivalent to those required under EU law
- On the paragraph-level findings and the current position: the CJEU found that US intelligence access to EU citizens' personal data is not limited to what is strictly necessary as required by the Charter (paras 178-185); the Ombudsperson at the US Department of State did not meet the requirements for an effective remedy, being neither independent nor empowered to issue binding decisions against intelligence agencies (paras 195-197); the standard contractual clauses remain valid in principle subject to the limitation that data exporters must assess case by case whether the law of the recipient country guarantees in practice the level of protection ensured by the clauses (para 134); the successor Data Privacy Framework entered into force in July 2023 based on Executive Order 14086, and in June 2026 the US Supreme Court questioned the independence of the FTC, which plays a central supervisory role in the framework, with the effect on its validity under discussion; where a provider is established in the EU and carries out all processing within it, no transfer to a third country takes place
- IAPP: the decision invalidates the European Commission's adequacy decision for the EU-US Privacy Shield Framework, on which more than 5,000 US companies relied to conduct transatlantic trade in compliance with EU data protection rules; while it upholds the validity of standard contractual clauses, it requires companies and regulators to conduct case-by-case analyses to determine whether foreign protections concerning government access to transferred data meet EU standards
- Hogan Lovells: the court found the clauses valid in principle, pointing out that their validity is not called into question by the mere fact that standard data protection clauses are not directly binding on the authorities of the third country; for transfers to the US it is especially relevant to what extent the data recipient is subject to Section 702 FISA and EO 12333; service providers with processing operations in the US and elsewhere should consider how to facilitate the verification task placed on their European customers
- GDPR Summary: the Privacy Shield was invalidated with immediate effect on 16 July 2020; the clauses remained valid as a transfer mechanism in principle but required additional work; the activist group behind the judgment subsequently brought complaints against 101 European companies over their use of Google Analytics and Facebook Connect integrations, on the basis that the provider relies on the clauses for onward transfer to the US