CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU
In its landmark ruling C-311/18 Schrems II (16 July 2020), the CJEU invalidated the Privacy Shield and subjected transfers based on Standard Contractual Clauses (SCCs) to prior Transfer Impact Assessments (TIAs) and supplementary measures.
1. Background & Invalidation of the Privacy Shield
In its judgment of 16 July 2020 (C-311/18 - Schrems II, ECLI:EU:C:2020:559), the Court of Justice of the European Union invalidated the EU-US Privacy Shield adequacy decision due to US surveillance programs (notably Section 702 FISA and Executive Order 12333) failing to provide safeguards substantially equivalent to those required under the EU Charter of Fundamental Rights (lack of effective judicial redress for European data subjects).
2. Maintenance of SCCs & Requirement of Supplementary Measures
The Court confirmed the principle validity of Standard Contractual Clauses (SCCs), while establishing a rigorous obligation for the European data exporter:
- Transfer Impact Assessment (TIA): The exporter must assess on a case-by-case basis whether the law of the third country allows the importer to comply with its SCC obligations.
- Necessary supplementary measures: If third-country legislation permits disproportionate access by public authorities, the exporter must implement effective technical safeguards (such as end-to-end encryption with keys retained exclusively in the EU/EEA), contractual safeguards, or organisational measures.
Current regime for transfers to the United States: Not all transfers to the US are prohibited. Since July 2023, the EU-US Data Privacy Framework (DPF) constitutes a valid adequacy decision for participating American organizations adhering to the framework. For non-participating importers, relying on SCCs accompanied by a Transfer Impact Assessment (TIA) remains mandatory.
3. Compliance Approach for Data Exporters
Engaging any processor or hosting provider outside the EU requires mapping the transfer chain, verifying DPF participation status, or formalizing SCCs accompanied by a comprehensive legal analysis of local state surveillance powers.
4. SCCs Are Not the Sole Safeguard Under Article 46
While SCCs represent the most widespread mechanism, Article 46 also provides for Binding Corporate Rules (BCRs), instruments between public bodies, codes of conduct, and certification mechanisms backed by binding and enforceable commitments from the importer. Since 6 August 2026, the EDPB register includes the Europrivacy v82 extension as the first European Data Protection Seal usable as an Article 46(2)(f) transfer tool.
Certification is neither an adequacy decision nor a blanket transfer authorization. Consult the Article 46 permanent guide — appropriate safeguards to compare mechanisms and their operational criteria.
Verified Official Sources
Invalidation du Privacy Shield, exigence d'évaluation d'impact des transferts (TIA) et mesures supplémentaires pour les CCT
Consult official source →Transferts internationaux (Chapitre V), champ d'application Art. 3, critères d'exportation
Consult official source →Injonctions de divulgation ou de transfert de données émanant de juridictions ou autorités de pays tiers (Art. 48), exigence d'accords d'entraide judiciaire (MLAT) ou d'exceptions du Chapitre V (version finale 2.1 adoptée le 5 juin 2025)
Consult official source →Approbation des critères Europrivacy comme label européen de protection des données utilisable pour les transferts au titre des articles 42 et 46(2)(f) RGPD
Consult official source →Critères v82 du label européen de protection des données pour les responsables ou sous-traitants hors EEE agissant comme importateurs de données — outil de transfert Art. 46(2)(f)
Consult official source →See Also in the Legal Framework
Article 46 GDPR : Appropriate Safeguards for International Transfers
Comprehensive guide to Article 46 GDPR: SCCs, BCRs, codes of conduct, certification mechanisms, binding commitments, TIA...
Article 6 GDPR: The Six Lawful Grounds for Lawful Processing
Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...
CJEU C-621/22 KNLTB: Lawfulness of Commercial Interest Under Art. 6(1)(f)
Fundamental CJEU ruling of 4 October 2024 (ECLI:EU:C:2024:858): lawful commercial interest is not excluded as a legitima...