# CJEU, judgment of 6 October 2015, C-362/14, Schrems (Safe Harbor)

The CJEU declares the Safe Harbor agreement invalid and strengthens the independent power of examination of the national supervisory authorities. The start of the chain of US adequacy decisions and the basis of the requirements for data transfers to the United States.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.51-eugh-schrems-i
> Sprache: en



In the case of Maximillian Schrems v Data Protection Commissioner, the CJEU (Grand Chamber) declared the European Commission's Safe Harbor decision invalid. The decision was still handed down under the earlier Data Protection Directive 95/46/EC; its standards continue to shape the requirements for transfers to third countries under the GDPR and mark the start of the later US adequacy decisions, the Privacy Shield and the Data Privacy Framework.

## 1. Facts [#1-facts]

Maximillian Schrems lodged a complaint with the Irish supervisory authority against the transfer of the data collected about him by Facebook Ireland to the US parent company. Referring to the Snowden revelations, he submitted that US law did not offer effective protection against access by the security authorities. The authority rejected the complaint by reference to the European Commission's Safe Harbor decision (Decision 2000/520), by which the United States had been classified as a safe third country. The Irish High Court, before which the matter was brought, referred questions to the CJEU on the extent of the powers of the national supervisory authorities and on the validity of the Safe Harbor decision.

## 2. Decision [#2-decision]

### 2.1 Independent power of examination of the supervisory authorities [#21-independent-power-of-examination-of-the-supervisory-authorities]

The Court made clear that an adequacy decision of the Commission does not prevent the national supervisory authorities from examining a complaint independently. Where an authority considers a transfer to be incompatible with the protection of the data, it must be able to bring legal proceedings so that the validity of the Commission decision can be reviewed by the courts and, ultimately, by the CJEU.

### 2.2 Safe Harbor decision invalid [#22-safe-harbor-decision-invalid]

The Court declared the Safe Harbor decision invalid. The Commission had confined itself to an examination of the Safe Harbor principles without assessing, by way of an overall appraisal, the protection of the data against access by state authorities and the effectiveness of legal protection. The program expressly treated its principles as subordinate to national security requirements, the public interest and US law. Access on a generalized basis and without any suspicion to the content of electronic communications compromises the essence of the fundamental right to respect for private life; the absence of a legal remedy compromises the essence of the right to effective judicial protection.

## 3. Significance for practice [#3-significance-for-practice]

* An adequacy decision requires a level of protection that is essentially equivalent and that also encompasses access by state authorities and legal protection.
* It follows from the judgment that the Commission is under an obligation to keep adequacy decisions under continuous review.
* The judgment marks the beginning of a chain of US arrangements: Safe Harbor was followed by the Privacy Shield (declared invalid in 2020) and by the EU-US Data Privacy Framework (2023).

<Cards>
  <Card title="EU-US Data Privacy Framework" href="/docs/dsgvo-hub/einzelthemen/drittlandsuebermittlung/1.3.13.3-data-privacy-framework" description="The current adequacy decision for certified US recipients and the history of the US arrangements." />

  <Card title="CJEU, Schrems II (C-311/18)" href="/docs/dsgvo-hub/rechtsprechung/1.4.50-eugh-schrems-ii" description="Invalidity of the Privacy Shield and basis of the obligation to carry out a transfer impact assessment." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.