Schrems II
The 2020 Court of Justice of the European Union decision in Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems (C-311/18). The ruling invalidated the EU-US Privacy Shield framework, finding that US surveillance law (FISA 702, EO 12333) did not provide adequate protection by EU standards.
What the court decided
The court found that Privacy Shield's protections were not "essentially equivalent" to GDPR's, because US surveillance programs allow bulk collection of data from US-based providers without judicial review by EU-recognised standards. The ruling did not invalidate Standard Contractual Clauses (SCCs) entirely, but required controllers to assess whether the destination country's surveillance regime renders the SCCs ineffective.
The TIA framework that emerged
The European Data Protection Board's June 2021 guidance (Recommendation 01/2020) introduced the Transfer Impact Assessment. For every SCC-based transfer, controllers must assess the third country's legal regime and determine whether supplementary measures — technical, contractual, organisational — are needed.
The TIA process has become a substantial operational burden. Most legal teams produce templated TIAs that gesture at supplementary measures without specifying what would actually work — because contractual and organisational measures cannot defeat a foreign surveillance regime. Only technical measures can.
The EU-US Data Privacy Framework
In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), succeeding Privacy Shield. The DPF introduces a Data Protection Review Court and additional limitations on signals intelligence — but the same FISA 702 mechanisms remain, and the redress court is an executive-branch body. Most experts now expect a Schrems III challenge within 18-36 months.
The architectural answer
For organisations transferring personal data to the US (or to US-controlled providers wherever physically located), the practical advice is: do not architect assuming the DPF survives. Architect assuming it doesn't.
Technical supplementary measures that actually defeat foreign surveillance regimes require end-to-end encryption with keys held outside the third country, and where the third-country provider literally cannot derive the decryption key. Zero-knowledge architecture combined with multi-cloud erasure coding makes the TIA mechanically straightforward.
Related terms
See also
Posts that mention Schrems II
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read → Regulation · 8 min readWhat a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read →