Schrems II
loreprivacygovernance & risk
The 2020 EU court ruling that struck down the EU-US Privacy Shield: one Austrian law student's complaints, twice, reshaped transatlantic data law.
Max Schrems challenged Facebook's transfers over US surveillance reach; the CJEU agreed, twice - Safe Harbor fell in 2015, Privacy Shield in 2020.
Schrems II is the 2020 decision in which the Court of Justice of the European Union invalidated the Privacy Shield framework governing transfers of personal data from the EU to the United States, on the grounds that US surveillance law did not provide protection equivalent to European standards.
The practical consequence was immediate and awkward. Thousands of organizations were relying on that framework, the alternative contractual mechanisms remained valid but now required a case-by-case assessment of whether the destination country's law would undermine them, and the honest answer for the US was frequently no. It made a routine compliance question into a genuine legal analysis.
It is worth understanding as a technology issue rather than a legal one, because the responses are architectural. Data residency requirements, regional processing, encryption where the provider cannot access the keys, and confidential computing all became commercially significant as answers to a court decision. It is also the second such invalidation, following Safe Harbour, brought by the same litigant, which suggests the underlying tension between surveillance powers and data protection has not been resolved so much as repeatedly renegotiated.
Also known as: privacy shield, schrems
Sources
- CJEU judgment C-311/18 (Schrems II), 2020-07-16
- CJEU judgment C-362/14 (Schrems I), 2015-10-06