What the court decided

On 16 July 2020 the Court of Justice of the European Union delivered its judgment in Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximilian Schrems. Two findings, in opposite directions.

The EU-US Privacy Shield was invalidated, with immediate effect. More than five thousand American companies had been relying on it to receive personal data from Europe. On that morning it stopped being a lawful basis, with no transition period.

Standard contractual clauses survived - conditionally. These are pre-approved contract terms that an exporter and an importer of data sign. The court held they remain valid in principle, but attached a requirement that changed what signing one means: the exporter must assess, case by case, whether the law of the recipient country actually guarantees in practice the level of protection the clauses promise. A contract between two companies cannot bind a government that is not party to it, so the exporter has to look at the government.

That is why this is a security article and not only a legal one. The court moved the question from "have we signed the right paperwork" to "what can the state where this data lands compel the recipient to do". That is a technical and architectural question, and it is answered with system design rather than with signatures.

The reasoning, which is a security assessment

Strip away the legal vocabulary and the judgment reads like a threat model.

The court examined United States surveillance authorities - section 702 of the Foreign Intelligence Surveillance Act, Executive Order 12333, and Presidential Policy Directive 28 - and concluded that programmes based on them could not be regarded as limited to what is strictly necessary, which is the standard the EU Charter of Fundamental Rights requires. It found that the limitations on protection arising from American domestic law were not circumscribed in a way that satisfies requirements essentially equivalent to those under EU law.

It then looked at redress. The Privacy Shield had offered an Ombudsperson at the State Department. The court found that this person was neither independent of the executive nor empowered to issue binding decisions against the intelligence agencies - so a European whose data had been collected had, in practice, nowhere to go.

And one factual finding deserves particular attention from readers of this catalogue. The Irish High Court had established, and the CJEU noted, that Executive Order 12333 permits the National Security Agency to access submarine cables and to collect and retain data before it arrives in the United States.

That is the Room 641A infrastructure, described in a European judgment as a finding of fact. The EFF spent sixteen years litigating over that splitter without a court ever ruling on whether the programme was lawful. A different court, in a different jurisdiction, took the same facts and used them to invalidate a trade framework. The Crypto Wars article traces the same question through policy; this is what happens when it reaches a bench that is willing to answer it.

The mistake practitioners make

The common reading is "keep the data in an EU region and the problem goes away". That is not what the judgment says, and the gap is worth understanding precisely.

The court's concern is who can be compelled, not where the disk is. A provider subject to a jurisdiction's compulsory process can be ordered to produce data it holds or can obtain, including from infrastructure it operates elsewhere. Selecting a European region on a console does not by itself change which government can serve an order on the company operating the console.

Which produces the question that actually determines the answer: who holds the keys, and can they be compelled to use them? If the provider can decrypt, then the provider's jurisdiction is in scope. If the customer holds keys the provider genuinely cannot obtain, the analysis changes - and this is exactly the exceptional access argument arriving from the commercial side rather than the political one. Clipper was about whether a government could be given a key. is about what follows, legally, from a provider having one.

The clean case the judgment leaves open is the one with no transfer at all: personal data processed by a provider established in the union and processed entirely within it. Then there is no third country and the analysis does not begin.

Why this belongs on a practitioner's reading list

It is a configuration question with legal force. For anyone deploying a cloud-delivered security service - the broker in a zero-trust architecture, a cloud access broker, a secure web gateway - the tenant's region, the location of the inspection point, whether logs leave the region, and who holds the decryption keys are all settings. After Schrems II they are also legal positions, and the person who configures them is making a compliance decision whether or not anyone told them so.

It rewards knowing what your product actually does with data. The assessments the judgment requires cannot be completed from a datasheet. They need answers to questions like where metadata is processed, whether support engineers in another country can view customer data, where backups replicate to, and what happens during a failover. Those are questions a practitioner can answer and a lawyer cannot.

And it is not settled. A successor framework, the EU-US , came into force in July 2023 on the basis of a further American executive order. Its durability is contested, and reporting in mid-2026 noted that a United States Supreme Court decision questioning the independence of the Federal Trade Commission - which has a central supervisory role in the framework - had put its standing under discussion. Anyone designing a system on the assumption that this is finished should notice that the same question has now been litigated three times and has produced two invalidations.

For readers under Brazil's , the structure is familiar rather than identical: a regime with its own chapter on international transfers, modelled on the European approach, with its own authority deciding what counts as adequate. The specifics differ and change; the underlying question - whose law reaches this data, and what does that law permit - is the same one, and it is answered by architecture.

This article describes what a court decided and what follows technically. It is not legal advice, and the assessments the judgment requires are the kind that need a lawyer as well as an engineer.

Sources