Skip to main content

Schrems II.

Schrems II is the 2020 CJEU judgement that struck down the EU-US Privacy Shield and added the Transfer Impact Assessment requirement. Every transfer to a third country now needs a documented analysis of local surveillance law and supplementary measures. Replaced in practice by the EU-US Data Privacy Framework (2023), but the TIA discipline stuck.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyPrivacy & data protectionAll entries

The Cyber Academy take

Schrems II is the 2020 CJEU judgement that struck down the EU-US Privacy Shield and added the Transfer Impact Assessment requirement. Every transfer to a third country now needs a documented analysis of local surveillance law and supplementary measures. Replaced in practice by the EU-US Data Privacy Framework (2023), but the TIA discipline stuck.

What the judgement actually decided

Schrems II is the Court of Justice of the European Union ruling, handed down in July 2020 in the Data Protection Commissioner v Facebook Ireland and Maximillian Schrems case, that reshaped how personal data leaves the European Economic Area. Two things happened at once.

First, the Court invalidated the EU-US Privacy Shield, the adequacy arrangement that had let thousands of companies transfer data to certified US importers, because US surveillance law did not offer EU individuals protection essentially equivalent to that guaranteed inside the Union, and gave them no effective judicial redress. Second, and this is the part that endures, the Court did not strike down Standard Contractual Clauses. It kept them valid but added a condition: the exporter cannot just sign the clauses and walk away.

That condition is the heart of the matter. The Court said data exporters must verify, on a case-by-case basis, whether the law and practice of the destination country actually let the importer honour the contractual safeguards. Where it does not, the exporter has to add supplementary measures or stop the transfer. The contract alone is not enough if a foreign government can compel access in a way the clauses cannot prevent.

The Transfer Impact Assessment in practice

The discipline Schrems II created is the Transfer Impact Assessment, or TIA. It is the documented analysis that turns the ruling into a repeatable control. A practitioner running a TIA works through a recognisable sequence rather than a one-off legal opinion.

  • Map the transfer. Identify what data goes where, the categories of people affected, the importer, any onward transfers, and the legal mechanism relied on, usually SCCs.
  • Assess the destination law and practice. Look at the surveillance and government-access regime in the importing country and judge whether it undermines the protection the transfer tool is meant to provide. This is the surveillance-law analysis the Court demanded.
  • Identify supplementary measures. Where local law is problematic, decide what additional technical, contractual, or organisational safeguards close the gap. Strong encryption with keys held only in the EEA, pseudonymisation, and split processing are the technical measures regulators point to most.
  • Document and decide. Record the reasoning, conclude whether the transfer can proceed, and set a review trigger so the assessment is revisited when the law or the arrangement changes.

Where it sits today

In 2023 the European Commission adopted the EU-US Data Privacy Framework, a new adequacy decision that, for certified US organisations, restores a route to transfer data without a TIA for that specific corridor. It was built to answer the redress and proportionality concerns that sank Privacy Shield, including an independent review mechanism for EU individuals. So in day-to-day terms, the Privacy Shield gap Schrems II opened has been bridged for the United States, provided the importer is certified under the new framework and the transfer stays within its scope.

What did not go away is the broader method. Transfers to countries with no adequacy decision still rely on SCCs or other Article 46 tools, and each of those still needs a TIA. The European Data Protection Board guidance on supplementary measures remains the practical playbook. So the correct way to read Schrems II in 2026 is not as a dead Privacy Shield story but as the moment transfer risk became something you assess and evidence, transfer by transfer, rather than assume away by ticking an adequacy box.

Two neighbouring concepts are worth keeping distinct. An adequacy decision is the Commission saying a whole country offers equivalent protection, which removes the need for extra safeguards. SCCs are a contract-based tool you use when there is no adequacy decision, and Schrems II is precisely the ruling that said SCCs come with the homework of a TIA attached.

Frequently asked questions

01Did Schrems II ban data transfers to the United States?

No. It invalidated the Privacy Shield adequacy arrangement, but transfers could still proceed under SCCs with a Transfer Impact Assessment and supplementary measures. Since 2023 the EU-US Data Privacy Framework provides a fresh adequacy route for certified US importers.

02Are Standard Contractual Clauses still valid after Schrems II?

Yes. The Court upheld SCCs. What it added is a duty to check, case by case, whether the destination country actually lets the importer comply with them, and to add supplementary measures or stop the transfer where it does not.

03What is a Transfer Impact Assessment?

It is the documented analysis Schrems II made necessary: map the transfer, evaluate the surveillance and government-access law of the destination, decide what supplementary measures are needed, and record the conclusion. It is now a standard control in any transfer relying on SCCs.

04Does the EU-US Data Privacy Framework make Schrems II irrelevant?

Not for the wider obligation. The framework restores an adequacy route for certified US organisations, removing the TIA for that specific corridor, but transfers to any non-adequate country still require a TIA. The assessment discipline Schrems II created remains in force.

05What counts as a supplementary measure?

Technical, contractual, or organisational safeguards that close the gap left by weak destination law. Regulators most often point to strong encryption with keys kept in the EEA, pseudonymisation, and split or multi-party processing as effective technical measures.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.