Data Protection HubCase Law

CJEU, judgment of 16 July 2020, C-311/18, Schrems II

The CJEU declares the EU-US Privacy Shield invalid and upholds the standard contractual clauses only on condition that the data exporter additionally assesses whether an equivalent level of protection is ensured in the third country. Basis of the obligation to carry out a transfer impact assessment.

In the case of Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, the CJEU (Grand Chamber) ruled on the requirements for transfers of data to unsafe third countries. The decision declares the EU-US Privacy Shield invalid and makes clear that the standard contractual clauses alone do not guarantee an adequate level of protection. It is the basis of the obligation to carry out a transfer impact assessment.

1. Facts

Maximillian Schrems challenged the transfer of the data collected about him by Facebook Ireland to the US parent company. He submitted that US law did not offer sufficient protection against access by state authorities. The Irish supervisory authority thereupon brought the matter before the High Court, which referred questions to the CJEU on the validity of the standard contractual clauses and of the Privacy Shield. At the heart of the case were the powers of access of the US intelligence services, in particular under Section 702 of the Foreign Intelligence Surveillance Act (FISA 702).

2. Decision

2.1 Privacy Shield invalid

The Court declared the adequacy decision on the EU-US Privacy Shield invalid. The possibilities of access available to the US intelligence services were not limited to what is necessary and proportionate, and the persons concerned lacked effective legal protection. That basis for data transfers to the United States thus ceased to exist.

2.2 Standard contractual clauses only with an additional assessment

The Court held the standard contractual clauses to be valid in principle. However, as a contract between the parties they cannot bind state authorities in the third country, and merely concluding them is therefore not sufficient. Before the transfer, the data exporter must assess whether a level of protection equivalent to that of the EU is actually ensured in the country of destination. Where the law or the practice in the country of destination stands in the way of this, supplementary protective measures are required; otherwise the transfer must be suspended.

3. Significance for practice

It follows from the judgment that, in addition to concluding the standard contractual clauses, a transfer impact assessment must always be carried out:

  • Concluding the standard contractual clauses alone is not sufficient.
  • The data exporter must assess the level of protection in the third country in the individual case, with particular regard to rights of access of state authorities.
  • For the United States, FISA 702 is to be classified as a problematic legal provision.
  • Where too high a risk remains despite supplementary protective measures, no transfer may take place.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn