On July 16, 2020, the Court of Justice of the European Union (CJEU) invalidated the EU-US Privacy Shield in its Schrems II judgment (Case C-311/18). If you relied on Privacy Shield to move personal data from the EU to the US, that legal basis is gone, with no grace period. Standard Contractual Clauses (SCCs) survived, but signing them is no longer enough. You now have to check, transfer by transfer, whether the destination country's laws let the recipient actually honor those clauses, and add safeguards where they don't.

That second part falls largely to security teams. Legal can draft contracts. You're the one who knows where the data flows, who can read it and who holds the keys.

This post explains the ruling and practical steps. It isn't legal advice, so confirm the specifics for your organization with counsel.

What did the CJEU decide in Schrems II?

The case started with a complaint by privacy campaigner Max Schrems to the Irish Data Protection Commissioner about transfers of his personal data to the US. The Irish regulator referred questions to the CJEU, which used the case to review both SCCs and Privacy Shield. You can read the Court's own summary in its press release of July 16, 2020.

Here's where the main transfer tools stand:

Transfer tool Status after July 16, 2020
EU-US Privacy Shield (Commission Decision 2016/1250) Invalid, with immediate effect
Standard Contractual Clauses (Commission Decision 2010/87/EU) Valid, but only with a case-by-case assessment of the destination country
Binding Corporate Rules (BCRs) Not ruled on directly; EU regulators say the same assessment applies
Article 49 GDPR derogations Still available, within their narrow limits

Why Privacy Shield fell

The Court found that US surveillance law doesn't give EU data protection that is "essentially equivalent" to what the GDPR guarantees. It looked at Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333. In the Court's view, the programs based on them aren't limited to what is strictly necessary, and EU individuals don't have rights they can enforce against US authorities before an independent body.

The Privacy Shield Ombudsperson didn't fix that. The Court held that it offers no cause of action before a body with guarantees equivalent to EU law and can't issue decisions that bind US intelligence services.

Why SCCs survived

The SCC decision itself contains mechanisms that can stop unlawful transfers. The importer has to tell the exporter if it can't comply with the clauses. The exporter then has to suspend the transfer or end the contract. And supervisory authorities must suspend or prohibit transfers where the clauses can't be complied with.

So the clauses are valid. The catch is that you now have to show they work in practice at the destination.

Is there a grace period for Privacy Shield transfers?

No. The European Data Protection Board (EDPB) adopted a set of frequently asked questions on the judgment on July 23, 2020. It states plainly that there is no grace period. The Court invalidated Privacy Shield without keeping its effects in place, so transfers still relying on it are unlawful.

On the US side, the Department of Commerce said on July 16 that it will keep administering the Privacy Shield program and that the ruling doesn't relieve participating organizations of their Privacy Shield obligations. If your company self-certified, keep honoring those commitments for the data you've already received. Just don't treat your certification as a lawful basis for new transfers from the EU.

What does "essentially equivalent" protection mean for SCCs?

Before a transfer under SCCs, the exporter, with help from the importer, has to verify whether the destination country's law allows the importer to meet its obligations under the clauses. The central question is whether public authorities there can access the data in ways that go beyond what EU law would allow.

According to the EDPB FAQ, there are three possible outcomes:

  1. The law of the destination country is fine. You can transfer under SCCs.
  2. The law isn't fine, but supplementary measures close the gap. You can transfer with those measures in place.
  3. Nothing closes the gap. You must suspend or end the transfer. If you intend to keep transferring anyway, you have to notify your supervisory authority.

This applies to transfers to any non-EEA country without an adequacy decision, not just the US. The EDPB says BCRs are subject to the same logic.

What the EDPB hasn't done yet is say what counts as a sufficient supplementary measure. The FAQ says the Board is analyzing the judgment and will provide more guidance on legal, technical and organizational measures. Until that guidance arrives, nobody has an official checklist.

Can you still use the Article 49 derogations?

Yes, but they're exceptions, not a replacement for Privacy Shield. Article 49 GDPR allows transfers in specific situations, such as with the individual's explicit consent, where the transfer is necessary for a contract with the individual, or for important reasons of public interest.

The EDPB's existing Guidelines 2/2018 on derogations say they have to be read restrictively and mostly suit occasional transfers. A standing arrangement with a US software vendor that processes your customer database every day doesn't fit that model.

What should security teams do now?

You can't wait for final guidance before doing anything. The work below is useful whatever the regulators eventually say.

1. Map your transfers

You can't assess transfers you don't know about. Build or update an inventory that records, for each flow:

  • The categories of personal data and whose data it is (customers, employees, prospects)
  • The exporter and importer, and their roles (controller or processor)
  • The destination country and where the data is stored and accessed
  • The transfer tool relied on today (Privacy Shield, SCCs, BCRs, a derogation)
  • Any subprocessors further down the chain
  • Whether the importer can see the data in clear text

Don't forget remote access. A support engineer or administrator outside the EEA viewing data stored inside it can amount to a transfer, even when the servers never leave Europe.

2. Review vendors and subprocessors

Pull the data processing agreements for vendors that handle EU personal data. Flag any that cite Privacy Shield as the transfer basis, since those need replacing. For each vendor, ask:

  • What transfer tool they now rely on
  • Which countries data is processed or accessed from, including by subprocessors
  • Whether they fall under laws that permit government access to customer data
  • What technical controls stop them, or their staff, from reading your data

Keep the answers. They feed straight into your assessment.

3. Prioritize by risk

You probably can't assess every flow at once. Start with the transfers that involve sensitive data, large volumes, or importers most likely to receive government access requests. Section 702, one of the laws the Court examined, compels "electronic communication service providers" to assist the US government, a category that may include many cloud and communications companies. Whether a particular vendor falls within it is a question for your lawyers, but it's a sensible way to rank your list.

4. Evaluate technical supplementary measures

This is where security teams add the most value. With formal guidance still pending, treat these as candidates to evaluate, not guaranteed fixes.

Measure What it can do Limits
Encryption with keys held in the EU Keeps data unreadable to the importer and anyone compelling it, if keys never leave the exporter's control Doesn't help when the importer must process data in clear text
Pseudonymization Lets the importer work with data it can't tie back to a person, if the re-identification key stays in the EU Weak if the remaining fields still identify people
Data minimization Removes fields or records the importer doesn't need Reduces exposure but doesn't remove it
Encryption in transit Protects data on the way Does nothing about access at the destination
Access controls and logging Limits and records who at the importer can see data Doesn't stop legally compelled access

The measures that change the picture most are the ones that leave the importer unable to read the data at all. Encryption at rest where the provider also manages the keys may be useful for other reasons, but it probably doesn't answer the Court's concern about access at the destination.

5. Document every decision

For each transfer, record what you assessed, what you found, which measures you applied and why you decided to continue, change or stop. Supervisory authorities are required to act on transfers that can't meet the standard. A written, reasoned assessment is your best evidence that you took the ruling seriously.

6. Plan for change

Some transfers may have to stop or move. Work with procurement and IT on options such as EU-hosted services, EU-based support or restructuring flows so less data leaves the EEA. Revisit your decisions once the EDPB publishes its guidance on supplementary measures.

Frequently asked questions

Does Schrems II affect transfers to countries other than the US?

Yes. Any transfer based on SCCs or BCRs to a country without an adequacy decision now needs the same assessment of local law and, where needed, supplementary measures. The existing adequacy decisions for other countries weren't at issue in this case.

Can we keep using a US cloud provider?

Possibly. The ruling doesn't ban transfers to US providers. It requires you to assess them. Your answer will depend on the data involved, where it's stored and accessed, the provider's legal exposure and the technical measures you can put in place.

Is encryption enough on its own?

It depends on who holds the keys and whether the provider has to see the data in clear to deliver the service. Encryption where you alone control the keys is a strong candidate. Encryption the provider can undo is much weaker. The EDPB's promised guidance on supplementary measures should help settle the question.

We only use SCCs. Are we fine?

Not automatically. SCCs remain valid, but the Court made clear that exporters must verify they can be complied with in practice. If you haven't assessed the destination country's law, that work is still ahead of you.

Next steps

  • Stop relying on Privacy Shield for new transfers from the EU.
  • Build a transfer inventory that includes vendors, subprocessors and remote access.
  • Ask vendors what transfer tool they use and what stops them from reading your data.
  • Rank transfers by sensitivity and exposure, and assess the highest-risk ones first.
  • Evaluate encryption with EU-held keys, pseudonymization and minimization as supplementary measures.
  • Document each assessment and decision, and revisit them when the EDPB publishes further guidance.