Schrems II: What the Ruling Means for Businesses and Why It Is Relevant in 2026

On July 16, 2020, the European Court of Justice (ECJ) declared the EU-U.S. Privacy Shield invalid. The ruling in Case C-311/18, known as “Schrems II,” is one of the most far-reaching data protection decisions of recent years.
For companies that transfer personal data to the United States, or use U.S. services that do so, this ruling has changed the legal framework.
This article summarizes what the CJEU ruled, what the consequences of the ruling were, and why it remains relevant in light of the current Schrems III debate.
Note: This article is for informational purposes only and does not constitute legal advice. Legal counsel should be sought for a legal assessment in individual cases.
What Happened Before Schrems II? The Background
Safe Harbor (2000–2015)
Since 2000, EU companies have been able to transfer personal data to the United States under the Safe Harbor Agreement. The agreement was based on a decision by the European Commission that the United States ensured an adequate level of data protection.
On October 6, 2015, the European Court of Justice (ECJ) declared this agreement invalid in its ruling C-362/14—known as “Schrems I.” The case stemmed from a lawsuit filed by Austrian lawyer Max Schrems against Facebook Ireland. Schrems argued that the surveillance laws in effect in the United States—in particular Section 702 of the FISA and Executive Order 12333—do not provide a level of protection for personal data comparable to that under EU law.
The CJEU agreed with this reasoning.
Privacy Shield (2016–2020)
The EU-U.S. Privacy Shield came into effect in August 2016 as its successor. Among other things, it included assurances from the U.S. government that intelligence agencies’ access to European data would be limited to what was “necessary and proportionate.” In addition, an ombudsperson was appointed within the U.S. Department of State, to whom EU citizens could turn with complaints.
Over 5,300 U.S. companies obtained certification under the Privacy Shield.

What did the CJEU rule in Schrems II?
On July 16, 2020, the CJEU issued its ruling in Case C-311/18 (Data Protection Commissioner v. Facebook Ireland Ltd. and Maximilian Schrems). The key points of the ruling:
1. Privacy Shield Declared Invalid
The CJEU found that the U.S. intelligence agencies’ access to the personal data of EU citizens is not limited to what is “strictly necessary,” as required by the EU Charter of Fundamental Rights (paragraphs 178–185 of the judgment).
In the Court’s view, the Ombudsperson at the U.S. Department of State did not meet the requirements for an effective remedy, as she was neither independent nor empowered to issue binding decisions against intelligence agencies (paras. 195–197).
2. Standard Contractual Clauses (SCCs) Remain Valid in Principle
The CJEU declared that the Standard Contractual Clauses (SCCs) approved by the European Commission remain valid in principle. However, this is subject to one significant limitation:
Data exporters must assess on a case-by-case basis whether the law of the recipient country guarantees in practice the level of protection ensured by the SCCs (para. 134 of the judgment).
If this is not the case, “additional measures” are required to ensure a level of protection equivalent to that provided by EU law.
3. Obligations of Data Protection Supervisory Authorities
The CJEU also clarified that national data protection supervisory authorities must suspend or prohibit data transfers to third countries if they conclude that adequate protection is not guaranteed, even when SCCs are used (para. 121).

What were the consequences of the ruling?
Recommendations of the EDSA
In November 2020, the European Data Protection Board (EDPB) published Recommendation 01/2020 on supplementary measures for transfers to third countries. In it, the EDPB established a six-step assessment process:
- Identify data transfers – What data is being transferred, and where is it going?
- Assess the transfer mechanism – What legal basis is being used?
- Assess the legal situation in the third country – Are there laws that undermine protection?
- Identify supplementary measures—technical, organizational, contractual
- Implement measures—encryption, pseudonymization, etc.
- Review regularly – Ongoing assessment of the legal situation

Transfer Impact Assessments (TIAs)
In practice, the ruling meant that companies had to conduct so-called Transfer Impact Assessments (TIAs) before they could transfer personal data to the U.S. based on SCCs. These TIAs were intended to document whether the U.S. legal framework impairs the protection of the transferred data in practice.
New Standard Contractual Clauses (June 2021)
On June 4, 2021, the European Commission published new Standard Contractual Clauses that took into account the requirements of the Schrems II ruling. Companies were required to transition to the new SCCs by December 27, 2022.
What does Schrems II have to do with the Data Privacy Framework?
Following the ruling, the EU and the U.S. negotiated a new framework for data transfers. On October 7, 2022, U.S. President Biden signed Executive Order 14086, which, among other things:
- is intended to limit U.S. intelligence agencies’ access to European data to what is “necessary and proportionate”
- introduced a new appeals procedure—the Data Protection Review Court (DPRC)
On this basis, the European Commission adopted the Adequacy Decision for the EU-U.S. Data Privacy Framework (DPF) on July 10, 2023.
The DPF is the successor to the Privacy Shield, which was declared invalid by Schrems II. It is based on President Biden’s executive order and the oversight role of the U.S. Federal Trade Commission (FTC).
Regarding recent developments: On June 29, 2026, the U.S. Supreme Court ruled in Trump v. Slaughter that the FTC’s independence is unconstitutional. We analyze the implications of this for the DPF in our Schrems III article.

Timeline: From Safe Harbor to Today
| Date | Event |
|---|---|
| July 26, 2000 | EU Commission Approves Safe Harbor |
| October 6, 2015 | ECJ Declares Safe Harbor Invalid (Schrems I, C-362/14) |
| July 12, 2016 | EU-U.S. Privacy Shield enters into force |
| July 16, 2020 | ECJ Declares Privacy Shield Invalid (Schrems II, C-311/18) |
| November 10, 2020 | EDSA Publishes Recommendations 01/2020 |
| June 4, 2021 | EU Commission Publishes New Standard Contractual Clauses |
| October 7, 2022 | U.S. President Biden Signs Executive Order 14086 |
| July 10, 2023 | EU Commission Adopts Adequacy Decision for the DPF |
| September 3, 2025 | EU Court dismisses Latombe’s lawsuit against the DPF (T-553/23) |
| October 31, 2025 | Latombe files an appeal with the CJEU (C-703/25 P) |
| June 29, 2026 | U.S. Supreme Court rules in Trump v. Slaughter |
What Companies Can Learn from Schrems II
The Schrems II ruling has shown that adequacy decisions by the European Commission can be overturned by the European Court of Justice if the legal basis in the third country proves to be insufficient. Two adequacy decisions—Safe Harbor and Privacy Shield—have already been declared invalid.
According to many data protection experts, this raises the following considerations for companies that process personal data:
- Document the legal basis: The basis on which data transfers to third countries take place should be documented.
- Assess reliance on individual legal frameworks: Companies that rely exclusively on an adequacy decision bear the risk that it will be annulled—as happened with Safe Harbor and Privacy Shield.
- Evaluate European alternatives: Where personal data is processed, choosing a provider based in the EU that also processes data there can reduce the legal burden—since no transfer to a third country takes place.
- Monitor developments: The legal landscape for transatlantic data transfers has undergone several fundamental changes since 2015. Regular review is advisable.

European Data Processing as an Alternative
When no data is transferred to a third country, the issues raised by Schrems II do not arise.
Passcreator Passcreator processes all data exclusively in Germany, in data centers operated by a German provider. Since is not a U.S. company and is not subject to U.S. law, there is no basis for the U.S. Cloud Act or comparable disclosure obligations.
For companies that use digital cards and passes for Apple Wallet or Google Wallet—such as digital loyalty cards, digital insurance cards, membership cards, or access credentials—this means that data protection issues related to transfers to third countries do not apply.

→ Learn more about Passcreator as a European wallet platform
Frequently Asked Questions (FAQ)
What does the Schrems II ruling say?
On July 16, 2020, the European Court of Justice (ECJ) declared the EU-U.S. Privacy Shield invalid (Case C-311/18). The Court found that U.S. surveillance laws do not provide a level of protection for personal data comparable to that under EU law, and that the remedies provided for in the Privacy Shield do not meet the requirements of the EU Charter of Fundamental Rights.
Are Standard Contractual Clauses (SCCs) still valid under Schrems II?
The CJEU has generally declared SCCs valid but clarified that data exporters must assess on a case-by-case basis whether the law of the recipient country ensures effective protection. If not, additional measures are required.
What is the difference between Schrems I and Schrems II?
Schrems I (2015) concerned the Safe Harbor Agreement and led to its invalidation. Schrems II (2020) concerned its successor, the Privacy Shield, and also led to its invalidation. In both cases, the CJEU found that the U.S. legal framework does not provide adequate protection for personal data from the EU.
What is the Data Privacy Framework (DPF)?
The DPF is the successor to the Privacy Shield, which entered into force in July 2023. It is based on Executive Order 14086 issued by U.S. President Biden. In June 2026, the U.S. Supreme Court questioned the independence of the FTC, which plays a central supervisory role in the DPF. How this affects the validity of the DPF is currently under discussion.
How can data transfers to the U.S. be avoided?
By having personal data processed by providers that are based in the EU and also carry out all data processing entirely within the EU. In this case, no transfer to a third country takes place, and the requirements of the Schrems II ruling do not apply.
Sources
- ECJ, Judgment of July 16, 2020, C-311/18 – EUR-Lex
- ECJ, Judgment of October 6, 2015, C-362/14 – EUR-Lex
- European Commission, Adequacy Decision on the DPF, July 10, 2023 – EUR-Lex
- European Commission, New Standard Contractual Clauses, June 4, 2021 – EUR-Lex
- EDSA, Recommendations 01/2020 – EDPB
- BfDI, Implications of the Schrems II Judgment – bfdi.bund.de
This article is for informational purposes only and reflects the views of Passcreator. It does not constitute legal advice. Legal counsel should be sought for a legal assessment in individual cases.
