Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Judgment C-311/18 (Schrems II)
Resources
Français (Belgique / France) English Nederlands (België / Nederland)
EU Legal Reference⚖️ Landmark CJEU Judgment⚖️ Binding Legal Force

CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU

Official CJEU Case Law · EU Regulation (EU) 2016/679 legal analysis

⚡ In 30 seconds:

In its landmark ruling C-311/18 Schrems II (16 July 2020), the CJEU invalidated the Privacy Shield and subjected transfers based on Standard Contractual Clauses (SCCs) to prior Transfer Impact Assessments (TIAs) and supplementary measures.

1. Background & Invalidation of the Privacy Shield

In its judgment of 16 July 2020 (C-311/18 - Schrems II, ECLI:EU:C:2020:559), the Court of Justice of the European Union invalidated the EU-US Privacy Shield adequacy decision due to US surveillance programs (notably Section 702 FISA and Executive Order 12333) failing to provide safeguards substantially equivalent to those required under the EU Charter of Fundamental Rights (lack of effective judicial redress for European data subjects).

2. Maintenance of SCCs & Requirement of Supplementary Measures

The Court confirmed the principle validity of Standard Contractual Clauses (SCCs), while establishing a rigorous obligation for the European data exporter:

  • Transfer Impact Assessment (TIA): The exporter must assess on a case-by-case basis whether the law of the third country allows the importer to comply with its SCC obligations.
  • Necessary supplementary measures: If third-country legislation permits disproportionate access by public authorities, the exporter must implement effective technical safeguards (such as end-to-end encryption with keys retained exclusively in the EU/EEA), contractual safeguards, or organisational measures.

Current regime for transfers to the United States: Not all transfers to the US are prohibited. Since July 2023, the EU-US Data Privacy Framework (DPF) constitutes a valid adequacy decision for participating American organizations adhering to the framework. For non-participating importers, relying on SCCs accompanied by a Transfer Impact Assessment (TIA) remains mandatory.

3. Compliance Approach for Data Exporters

Engaging any processor or hosting provider outside the EU requires mapping the transfer chain, verifying DPF participation status, or formalizing SCCs accompanied by a comprehensive legal analysis of local state surveillance powers.

4. SCCs Are Not the Sole Safeguard Under Article 46

While SCCs represent the most widespread mechanism, Article 46 also provides for Binding Corporate Rules (BCRs), instruments between public bodies, codes of conduct, and certification mechanisms backed by binding and enforceable commitments from the importer. Since 6 August 2026, the EDPB register includes the Europrivacy v82 extension as the first European Data Protection Seal usable as an Article 46(2)(f) transfer tool.

Certification is neither an adequacy decision nor a blanket transfer authorization. Consult the Article 46 permanent guide — appropriate safeguards to compare mechanisms and their operational criteria.

Verified Official Sources

⚖️ Binding Source
Schrems II (16 juil. 2020) · ECLI: ECLI:EU:C:2020:559

Invalidation du Privacy Shield, exigence d'évaluation d'impact des transferts (TIA) et mesures supplémentaires pour les CCT

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V

Transferts internationaux (Chapitre V), champ d'application Art. 3, critères d'exportation

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 02/2024 on the application of Article 48 of the GDPR · 2025-06-05

Injonctions de divulgation ou de transfert de données émanant de juridictions ou autorités de pays tiers (Art. 48), exigence d'accords d'entraide judiciaire (MLAT) ou d'exceptions du Chapitre V (version finale 2.1 adoptée le 5 juin 2025)

Consult official source →
💡 EDPB Art. 64 Opinion
Opinion 15/2026 on the Europrivacy certification criteria as a tool for transfers · 2026-04-15

Approbation des critères Europrivacy comme label européen de protection des données utilisable pour les transferts au titre des articles 42 et 46(2)(f) RGPD

Consult official source →
⚖️ Official Reference
Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · 2026-08-06

Critères v82 du label européen de protection des données pour les responsables ou sous-traitants hors EEE agissant comme importateurs de données — outil de transfert Art. 46(2)(f)

Consult official source →

See Also in the Legal Framework

Article 46 GDPR Official Text

Article 46 GDPR : Appropriate Safeguards for International Transfers

Comprehensive guide to Article 46 GDPR: SCCs, BCRs, codes of conduct, certification mechanisms, binding commitments, TIA...

View document
Article 6 GDPR Official Text

Article 6 GDPR: The Six Lawful Grounds for Lawful Processing

Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...

View document
CJEU KNLTB CJEU Case Law

CJEU C-621/22 KNLTB: Lawfulness of Commercial Interest Under Art. 6(1)(f)

Fundamental CJEU ruling of 4 October 2024 (ECLI:EU:C:2024:858): lawful commercial interest is not excluded as a legitima...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice