Schrems II
The ruling that redrew transatlantic data transfers. Schrems II struck down the EU-US Privacy Shield in 2020 and put Standard Contractual Clauses under a duty of assessment.
- Term
- Schrems II
- Is
- A 2020 Court of Justice of the EU ruling
- Struck down
- The EU-US Privacy Shield framework
- Upheld
- Standard Contractual Clauses, with conditions
Parts of speech & senses
- Schrems II is the July 2020 Court of Justice of the European Union ruling that invalidated the EU-US Privacy Shield and imposed stricter conditions on transferring personal data out of the EU. "After Schrems II, they re-papered their US transfers."
What Schrems II is
Schrems II is the shorthand name for a landmark 2020 judgment of the Court of Justice of the European Union that reshaped how personal data may move from the EU to countries outside it, above all the United States. Handed down on 16 July 2020 in Case C-311/18, it arose from a complaint by the Austrian privacy campaigner Max Schrems about Facebook's transfers of European users' data to the US. The Court reached two headline conclusions: it declared the EU-US Privacy Shield — the framework thousands of companies relied on to legitimize transatlantic data transfers — invalid, and it upheld Standard Contractual Clauses as a transfer mechanism, but only on conditions. In one ruling it removed a whole legal pathway and tightened the main alternative. This entry is descriptive and not legal advice.
The Court's reasoning turned on a clash between US surveillance law and EU fundamental rights. It found that US government access to data, and the lack of effective redress for EU individuals, meant the Privacy Shield did not guarantee a level of protection essentially equivalent to that required under EU law and the Charter of Fundamental Rights. Standard Contractual Clauses survived because they are, in principle, a valid tool — but the Court stressed that a contract alone cannot bind a foreign government's surveillance agencies. So exporters relying on the clauses must assess, case by case, whether the destination country actually offers adequate protection, and add 'supplementary measures' where it does not. The judgment did not spell out exactly what those measures are, which left companies to work it out.
Schrems II versus Schrems I
Schrems II is the sequel, and the numbering matters. Schrems I, decided in 2015, struck down the earlier transfer framework called Safe Harbor on similar grounds — the same campaigner, the same core concern that US surveillance undermined the protection EU data was supposed to keep. Safe Harbor was replaced by the Privacy Shield, negotiated to fix its predecessor's flaws. Schrems II then found that the replacement suffered from the very same defects and invalidated it too. So the two cases form a pattern: a transfer framework is agreed, a challenge argues it fails to protect EU data from US surveillance, and the Court agrees and strikes it down. Schrems I killed Safe Harbor; Schrems II killed the Privacy Shield. Each raised the bar the next arrangement would have to clear.
Beyond which framework fell, the rulings differ in reach. Schrems I dealt narrowly with Safe Harbor. Schrems II went further: it not only invalidated the Privacy Shield but also set out the conditions attached to Standard Contractual Clauses, effectively putting every clause-based transfer under a duty of assessment and, where needed, supplementary safeguards. That broader holding is why Schrems II caused more upheaval — it touched not one framework but the fallback nearly everyone used. The saga continued after it: the EU and US negotiated a further arrangement, the EU-US Data Privacy Framework, adopted in 2023 to address the Court's concerns, which itself faces the prospect of a future challenge. Understanding Schrems II means seeing it as the second act in an ongoing contest over transatlantic data, not a settled endpoint.
Working with Schrems II in practice
For organizations, Schrems II turned data transfers from a box-ticking exercise into a diligence obligation. In practice, businesses relying on Standard Contractual Clauses are expected to run a transfer impact assessment — examining the destination country's laws and the real risk of government access — and to add supplementary measures such as strong encryption, pseudonymization, or contractual and organizational safeguards where the country's protections fall short. Many mapped their data flows, identified which vendors moved EU data to the US, and re-papered those relationships. The later adoption of the EU-US Data Privacy Framework gave certified US companies a renewed adequacy route, but the underlying lesson of Schrems II endures: a transfer mechanism is only as good as the actual protection the destination provides. Organizations should take specific legal advice rather than treat this summary as guidance.
The traps are as much about complacency as complexity. Treating Standard Contractual Clauses as a self-executing fix, without the assessment Schrems II requires, misreads the ruling entirely — the Court's whole point was that the clauses are not enough on their own. Ignoring where data actually flows, so US sub-processors go unnoticed, leaves transfers unassessed. Assuming the 2023 Data Privacy Framework closed the matter for good underestimates the pattern the two Schrems cases established, since a further challenge is widely anticipated. And confusing Schrems II with Schrems I muddles which framework fell and why. The discipline is to know your data flows, assess your transfers, layer in safeguards, keep watching the legal landscape, and get qualified counsel. Schrems II is a moving area of law, not a solved one.
Synonyms & antonyms
Synonyms
Antonyms
Origin & history
The ruling is named for privacy campaigner Max Schrems, whose complaints produced two CJEU judgments — Schrems I (2015) and Schrems II (2020) — on EU-US data transfers.
Etymology: source.
Usage trends
Search interest for this term over the last five years:
Common questions
- What did Schrems II decide?
- In July 2020 the Court of Justice of the European Union invalidated the EU-US Privacy Shield because US surveillance law did not offer protection equivalent to EU standards, while upholding Standard Contractual Clauses on the condition that exporters assess each transfer and add safeguards. This is not legal advice.
- How is Schrems II different from Schrems I?
- Schrems I struck down the Safe Harbor framework in 2015; Schrems II struck down its replacement, the Privacy Shield, in 2020 and also set conditions on Standard Contractual Clauses. Both turned on US surveillance undermining the protection of EU personal data.
- Is the Data Privacy Framework the end of the story?
- Probably not. The EU-US Data Privacy Framework adopted in 2023 addresses the Court's concerns and gives certified US firms an adequacy route, but given the pattern of the two Schrems cases, a further legal challenge is widely expected. Take specific legal advice.
Resources & people to follow
- referenceRGM analysis — definitions, senses, and usage verified per term
Curated, non-competitor resources verified per term.
Related training
Disciplines
Areas of marketing where schrems ii is a core concern: