Skip to content
Guidance · EDPB ·asked-questions-on-the-judgment-of-the-court-of-justice-of-the EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Frequently Asked Questions on the judgment of the Court of Justice of the European Union in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems

Summary

1 F requently Asked Questions on the judgment of the Court of Justice of the European Union in Case C - 311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems Adopted on 23 July 2020 This document aims at presenting answers to some frequently asked questions received by supervisory authorities (“SAs”) and will be developed and complemented along with further analysis, as the EDPB continues to examine and assess the judgment of the C our t of J ustice of the E…

How it connects

12 of 12 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 12 sections

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

1 F requently Asked Questions on the judgment of the Court of Justice of the European Union in Case C - 311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems Adopted on 23 July 2020 This document aims at presenting answers to some frequently asked questions received by supervisory authorities (“SAs”) and will be developed and complemented along with further analysis, as the EDPB continues to examine and assess the judgment of the C our t of J ustice of the E uropean U nion (the “ Court ”) . The judgment C - 311/18 can be found here , and the press release of the Court may be found here . 1) What did the Court rule in its judgment?  In its judgment, the Court examined the validity of the Europ ean Commission’s D ecision 2010/87/EC on Standard Contractual Clauses ( “ SCCs ” ) and considered it is valid. Indeed, the validity of that decision is not called into question by the mere fact that the standard data protection clauses in that decision do not, given that they are contractual in nature, bind the authorities of the third country to which data may be transferred.

§

However, that validity, the Court added, depends on whether the 2010/87/EC D ecision includes effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection essentially equivalent to that guaranteed within the EU by the GDPR and that transfers of personal data pursuant to such clauses are suspended or prohibited in the event of the breach of such c lauses or it being impossible to honour them. In that regard, the Court points out, in particular, that the 2010/87/EC D ecision imposes an obligation on a data exporter and the recipient of the data (the “data importer”) to verify, prior to any transfer, and taking into account the circumstances of the transfer , whether that level of protection is respected in the third country concerned , and that the 2010/87/EC D ecision requires the data importer to inform the data exporter of any inability to comply wit h the standard data protection clauses , and where necessary with any supplementary measures to those offered by those clause, the data exporter then being, in turn, obliged to suspend the transfer of data and/or to terminate the contract with the data impo rter 2  The Court also examined the validity of the Privacy Shield D ecision (Decision 2016/1250 on the adequacy of the protection provided by the EU - U .

§

S . ”) . S. S. S. for national security purposes, result in limitations on the protection of personal data which are not circu mscribed in a way that satisfies requirements that are essentially equivalent to those required under EU law 1 , and that this legislation does not grant data subjects actionable rights before the courts against the U . S . authorities. As a consequence of such a degree of interference with the fundamental rights of persons whose data are transferred to that third country, the Court declared the Privacy Shield adequacy D ecision invalid. 2) Does the Court ’s judgment have implications on transfer tools other than the Privacy Shield?  In general, for third countries , the threshold set by the Court also applies to all appropriate safeguards under Article 46 GDPR used to transfer data from the EEA to any third country. S. law referred to by the Court (i . S. via electronic means that falls under the scope of this legislation , regardless of the transfer tool used for the transfer 2 .

§

3) Is there any grace period during which I can keep on transferri ng data to the U . S . without assessing my legal basis for the transfer? S. law assessed by the Court does not provide an essentially equivalent level of protection to the EU . This as sessment has to be taken into account for any transfer to the U . S. 4) I was transferring data to a U . S . data importer adherent to the Privacy Shield, w hat should I do now?  Transfers on the basis of this legal framework are illegal. , you would need to check whether you can do so under the conditions laid down below. 5) I am using SCCs with a data importer in the U . S . , what should I do? S. , Section 702 FISA and EO 12333) does not ensure an essentially equivalent level of protection. S. S. S. authorities, or the existence of guarantees for potentially targeted non - US persons. 4; b)) . 3 Whether or not you can transfer personal data on the basis of SCCs will depend o n the result of your assessment, taking into account the circumstances of the transfers, and supplementary measures you could put in place.

§

S. law does not impinge on the adequate level of protection they guarantee. If you come to the conclusion that, taking into account the circumstances of the transfer and possible supplementary measures, appropriate safe guards would not be ensured, you are required to suspend or end the transfer of personal data. However , if you are intending to keep transferring data despite this conclusion , you must notify your competent SA 3 . 6) I am using Binding Corporate Rules (“BCRs”) with an entity in the U . S . , what should I do? S. with the fundamental rights of persons whose data are transferred to th at third country , and the fact that the Privacy Shield was also designed to bring guarantees to data transferred with other tools such as BCRs, the Court’s assessment applies as well in the context of BCRs , since U . S . law will also have primacy over th is t ool. Whether or not you can transfer personal data on the basis of BCRs will depend on the result of your assessment, taking into account the circumstances of the transfers, and supplementary measures you could put in place.

§

S. law does not impinge on the adequate level of protection they guarantee. If you come to the conclusion that, taking into account the circumstances of the transfer and possible supplementary measures, appropriate safeguards would not be ensured, you are required to suspend or end the transfer of personal data. However if you are intending to keep transferring data despite this conclusion , you must notify your competent SA 4 . 7) What about other transfer tools under Article 46 GDPR ?  The EDPB will assess the consequences of the judgment on transfer tools other than SCCs and BCRs . The j udgement clarifies that the standard for appropriate safeguards in A rticle 46 GDPR is that of “ essential equivalence ” . As underlined by the Court, it should be noted that that A rticle 46 appears in Chapter V GDPR, and, accordingly, must be read in the light of Article 44 GDPR , which lays down that “ all provisions in that chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by that regulation is not undermined ” .

§

3 See in particular r ecital 145 of the Court’s judgment, and C lause 4 (g) Commission d ecision 2010/87/EU , as well as C lause 5 ( a ) Commission Decision 2001/497/EC and Annex Set II (c) of Commission Decision 2004/915/EC. 4 See in particular r ecital 145 of the Court’s judgment and C lause 4 (g) of Com mission Decision 2010/87/EU . item_id=614110 ) . 4 8) Ca n I rely on one of the derogations of Article 49 GDPR to transfer data to the U . S .  It is still possible to transfer data from the EEA to the U . S . on the basis of derogations foreseen in Article 49 GDPR provided the conditions set forth in this Article apply. The EDPB refers to its guidelines on this provision 5 . In particular, it should be recalled that when transfers are based on the consent of the data subject , it should be :  explicit,  specific for the particular data transfer or set of transfers (meaning that the data exporter must make sure to obtain specific consent before the transfer is put in place even if this occurs after the collection of the data has been made) , and  informed, particularly as to the possible risks of the transfer (meaning the data subject should also informed of the specific risks resulting from the fact that their data will be transferred to a country that does not pro vide adequate protection and that no adequate safeguards aimed at providing protection for the data are being implemented).

§

With regard to transfers necessary for the performance of a contract between the data subject and the controller , it should be borne in mind that personal data may only be transferred when the transfer is occasional. It would have to be established on a case - by - case basis whether data transfers would be determined as “occasional” or “non - occasional”. In any case , this derogation can on ly be relied upon when the transfer is objectively necessary for the performance of the contract. In relation to transfers necessary for important reasons of public interest (which must be recognized in EU or Member State s ’ 6 law), the EDPB recalls that the essential requirement for the applicability of this derogation is the finding of an important public interest and not the nature of the organi s ation, and that although this derogation is not limited to data transfers that a re “occasional”, this does not mean that data transfers on the basis of the important public interest derogation can take place on a large scale and in a systematic manner.

§

Rather, the general principle needs to be respected according to which the derogati ons as set out in Article 49 GDPR should not become “the rule” in practice, but need to be restricted to specific situations and each data exporter needs to ensure that the transfer meets the strict necessity test. 9) Can I continue to use SCCs or BCRs to tra nsfer data to another third country than the U . S . S. applies for any third country . The same g oes for BCRs . The Court highlighted that it is the responsibility of the data exporter and the data importer to assess whether the level of protection required by EU law is respected in the third country concerned in order to determine if the guarantees p rovided by the SCCs or the BCRs can be complied with in practice. If this is not the case, you should assess whether you can provide supplementary measures to ensure an essentially equivalent level of protection as provided in the EEA , and if the law of th e third country will not impinge on these supplementary measures so as to prevent their effectiveness.

applies Art. 49
§

3 . 6 Refer ences to “Member States” should be understood as references to “EEA Member States”. 5 You can contact your data importer to verify the legislation of its country and collaborate for i t s assessment. Should you or the data importer in the third country determine that the data transferred pursuant to the SCCs or to the BCRs are not afforded a level of protection essentially equivalent to that guaranteed within the EEA , you should immediately suspend the transfers. In case you do not , you must notify your competent SA 7 .  Although, as underlined by the Court, it is the primary responsibility of data exporters and data importers to assess themselves that the legislation of the third country of destination enables the data importer to compl y with the standard data protection clauses or the BCRs , before transferring personal data to that third country, the SAs will also have a key role to play when enforcing the GDPR and when issuing further decisions on transfers to third countries.

§

As invi ted by the Court, in order to avoid divergent decisions, they will thus further work within the EDPB in order to ensure consistency, in particular if transfers to third countries must be prohibited. 10) What kind of supplementary measures can I introduce if I am using SCCs or BCRs to transfer data to third countr ies ?  The supplementary measures you could e nvisage where necessary would have to be provided on a case - by - case basis , taking into account all the circumstances of the transfer and following the assessment of the law of the third country , in order to check if it ensures an adequate level of protection. The Court highlighted that it is the primary responsibility of the data exporter and the data importer to make this assessment , and to provide necessary supplementary measures . The EDPB is currently analysing the Court’s judgment to determine the kind of supplementary measures that could be provided in addition to SCCs or BCRs , whether legal, technical or organisational measures, to t ransfer data to third countries where SCCs or BCRs will not provide the sufficient level of guarantees on their own.

§

 The EDPB is looking further into what these supplementary measures could consist of and will provide more guidance. S. or to another third country? 3 GDPR must provide whe ther transfers are authori s ed or not (it should be borne in mind that even providing access to data from a third country, for instance for administration purposes, also amounts to a transfer).  Authorization has also to be provided concerning processors to entrust sub - processors to transfer data to third countries. , for storage or maintenance purposes). 7 See in particular r ecital 145 of Court’s judgment . In relation to SCCs, see C lause 4 (g) Commission Decision 2010/87/EU , as well as C lause 5 ( a ) Commission Decision 2001/497/EC and Annex Set II (c) Commission Decision 2004/915/EC . 01 ( endorsed by the EDPB) . S. or to another third country? S. S. S . S.  If your data may be transferred to another third country, you should also verify t he legislation of that third country to check if it is compliant with the requirements of the Court , and with the level of protection of personal data expected. If no suitable ground for transfers to a third country can be found, personal data should not b e transferred outside the EEA territory and all processing activities should take place in the EEA. For the European Data Protection Board The Chair Andrea Jelinek