Legal jurisdiction

Schrems II

Schrems II is a 2020 EU court ruling. It found that standard tools for sending data to the US did not protect Europeans enough from US surveillance laws.

Schrems II is a 2020 ruling by the EU’s top court, named after privacy activist Max Schrems. The court found that the main legal tool for transferring data from the EU to the US, the “Privacy Shield” agreement, did not protect Europeans enough. US surveillance laws could still reach that data. The ruling did not ban EU-US data transfers outright. It pushed companies toward extra safeguards, like Standard Contractual Clauses are pre-approved legal contracts. Companies use them to send data outside the EU while still meeting GDPR requirements. Learn more → , and led to the newer The EU-US Data Privacy Framework is the current agreement that lets data flow from Europe to US companies that sign up to it. Learn more → . Schrems II is often cited as proof that US surveillance concerns are not hypothetical. A court confirmed them.

Frequently asked questions

What was the Schrems II ruling about?

In July 2020, the EU's top court ruled on a case about Facebook and user data. The case asked a simple question: does sending European data to the US actually protect that data? The court said no, not under the rules used at the time.

The ruling looked at Privacy Shield, the main legal tool companies used to move data from the EU to the US. The court found it did not protect Europeans from US surveillance law. So the court struck it down.

Why did Schrems II strike down the Privacy Shield agreement?

The court looked at US surveillance laws, like FISA 702. It found that these laws let US agencies collect data on Europeans without enough limits. Privacy Shield did not fix this problem.

The court also found no real way for Europeans to challenge US surveillance in court. Privacy Shield had an "ombudsperson" role meant to handle complaints. The court said this role was not independent enough to count as a real remedy.

What replaced Privacy Shield after Schrems II?

At first, no single agreement replaced Privacy Shield right away. Companies had to rely on a different tool: Standard Contractual Clauses. But the court said these clauses are not automatically enough on their own. Companies must check whether a country's laws actually let the clauses work in practice.

In 2023, the EU and US signed a new deal: the EU-US Data Privacy Framework. It adds new limits on US surveillance. It also creates a new way for Europeans to file complaints. The framework is meant to fix the problems Schrems II raised.

Who is Max Schrems?

Max Schrems is an Austrian privacy lawyer. In 2013, he filed a complaint against Facebook over how it sent his data to the US. That complaint led to two major EU court rulings, known as Schrems I and Schrems II.

Schrems also runs noyb, a European privacy organization. The name is short for "none of your business." The group continues to challenge how companies handle European data, including the newer EU-US Data Privacy Framework.

Is Schrems II still relevant today?

Yes. The reasoning behind Schrems II still shapes how EU courts judge data transfers to the US. Companies still need to check whether a destination country's laws actually protect European data, not just sign a standard contract.

The current EU-US Data Privacy Framework was built to answer the exact concerns Schrems II raised. Privacy groups, including noyb, continue to challenge it in EU courts. Whether it survives a future legal challenge is still an open question.