Case Law · CJEU EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems
Schrems II
Schrems II
Judgment
Full text
summary
“[…] the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees that apply uniformly in all third countries to controllers and processors established in the European Union and, consequently, independently of the level of protection guaranteed in each third country. In so far as those standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contractual obligation to ensure compliance with the level of protection required under EU law, they may require, depending on the prevailing position in a particular third country, the adoption of supplementary measures by the controller in order to ensure compliance with that level of protection.” / “It is therefore, above all, for that controller or processor to verify, on a case-by-case basis and, where appropriate, in collaboration with the recipient of the data, whether the law of the third country of destination ensures adequate protection, under EU law, of personal data transferred pursuant to standard data protection clauses, by providing, where necessary, additional safeguards to those offered by those clauses.”(¶133&134)
“That validity depends, however, on whether, […], such a standard clauses decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law and that transfers of personal data pursuant to the clauses of such a decision are suspended or prohibited in the event of the breach of such clauses or it being impossible to honour them.” (¶137)
¶133 excerpt
It follows that the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees that apply uniformly in all third countries to controllers and processors established in the European Union and, consequently, independently of the level of protection guaranteed in each third country. In so far as those standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contractual obligation to ensure compliance with the level of protection required under EU law, they may require, depending on the prevailing position in a particular third country, the adoption of supplementary measures by the controller in order to ensure compliance with that level of protection.
¶134 excerpt
In that regard, as the Advocate General stated in point 126 of his Opinion, the contractual mechanism provided for in Article 46(2)(c) of the GDPR is based on the responsibility of the controller or his or her subcontractor established in the European Union and, in the alternative, of the competent supervisory authority. It is therefore, above all, for that controller or processor to verify, on a case-by-case basis and, where appropriate, in collaboration with the recipient of the data, whether the law of the third country of destination ensures adequate protection, under EU law, of personal data transferred pursuant to standard data protection clauses, by providing, where necessary, additional safeguards to those offered by those clauses.
excerpt
[…]
¶137 excerpt
That validity depends, however, on whether, in accordance with the requirement of Article 46(1) and Article 46(2)(c) of the GDPR, interpreted in the light of Articles 7, 8 and 47 of the Charter, such a standard clauses decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law and that transfers of personal data pursuant to the clauses of such a decision are suspended or prohibited in the event of the breach of such clauses or it being impossible to honour them.
How it connects
References
Related across sources
Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Feb 24, 2023 Certification International Transfer Processing Agreement
Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 May 25, 2018 Privacy Shield Lawful Basis Legitimate Interest
Guidelines 04/2021 Codes of Conduct as tools for transfers Guidelines on codes of conduct and monitoring bodies Feb 22, 2022 International Transfer Processing Agreement Codes of Conduct
Guidelines 2/2020 articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies Dec 15, 2020 Personal Data Processing Agreement Privacy Shield
Guidelines 05/2021 Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Feb 24, 2023 International Transfer Privacy Shield Processing Agreement
Guidelines 02/2022 application of Article 60 GDPR Mar 14, 2022 Supervision Supervisory Authorities Processors