# International Transfer — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/internationale-doorgifte
> Sources are cited per item. Verify against the official texts before relying on them.

Transfer of personal data outside the EU/EEA

## Overview

## Legal Framework

International transfers of personal data outside the EU/EEA are governed by Chapter V of the GDPR (Articles 44–50). Article 44 sets the general principle: any transfer—and any onward transfer from a third country to another—must comply with Chapter V so that the GDPR's level of protection is not undermined. Three transfer mechanisms dominate practice. First, under Article 45, the European Commission may adopt an adequacy decision finding that a third country ensures a comparable level of protection, permitting transfers without further safeguards. Second, absent such a decision, Article 46 requires the controller or processor to provide "appropriate safeguards" and ensure data subjects have enforceable rights and effective legal remedies—typically through Standard Contractual Clauses, Binding Corporate Rules, or approved certification mechanisms. Third, Article 49 provides derogations for specific situations, including explicit consent, though only as a last resort.

Transparency obligations reinforce these mechanisms. When collecting data directly, [Article 13(1)(f)](/laws/gdpr/art-13#par-1-pnt-f) requires controllers to inform data subjects of intended transfers and the existence or absence of an adequacy decision:

> "where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission"
> — [GDPR Art. 13(1)(f)](/laws/gdpr/art-13#par-1-pnt-f)

A parallel duty applies under [Article 14(1)(f)](/laws/gdpr/art-14#par-1-pnt-f) for data not obtained from the data subject. Upon request, the right of access under [Article 15](/laws/gdpr/art-15) extends to transfer-related information:

> "Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer."
> — GDPR Art. 15(2)

## Key Developments

The landmark ruling in *Schrems II* (C-311/18, 16 July 2020) invalidated the EU-US Privacy Shield adequacy decision and reshaped the transfer landscape. The Court of Justice emphasised that Chapter V must operate as a coherent protective regime:

> "Alle bepalingen van dit hoofdstuk worden toegepast opdat het door deze verordening voor natuurlijke personen gewaarborgde beschermingsniveau niet wordt ondermijnd."
> — [Schrems II ¶12](/posts/1#seg-12)

The Court confirmed that Standard Contractual Clauses remain valid but placed a duty on data exporters to assess, on a case-by-case basis, whether the law of the destination country undermines the contractual safeguards—particularly regarding government access for surveillance. Where the destination country's legal framework does not ensure essentially equivalent protection, the exporter must adopt supplementary measures or suspend the transfer.

Enforcement reflects this heightened scrutiny. The Italian DPA fined Character.AI €158,000 in connection with transfers to a US-based controller, and Sweden's IMY investigated the national police authority's border-control data transfers—both illustrating that supervisory authorities are actively examining whether transfers meet Article 46 standards.

## Status of the Debate

This topic is actively litigated and enforcement-led. *Schrems II* settled the legal architecture—adequacy decisions, Article 46 safeguards, and derogations remain the three-tier framework—but the operational question of when supplementary measures suffice remains contested. Courts and DPAs diverge on how to assess "essential equivalence" in practice, particularly for US transfers post-Schrems II and in the context of government access. The EDPB has issued guidance on contractual clauses and certification as transfer tools, but no court has definitively resolved what specific supplementary measures are sufficient across all scenarios. A future CJEU ruling on the EU-US Data Privacy Framework or on a specific supplementary-measures case would likely crystallise the boundaries.

## Practical Guidance

- **Map all transfers**: Identify every data flow to third countries or international organisations, including onward transfers by importers, and classify each under Article 45 (adequacy), Article 46 (safeguards), or Article 49 (derogations).
- **Conduct Transfer Impact Assessments**: For each non-adequacy transfer, assess the destination country's legal framework—especially government access powers—and determine whether supplementary measures (encryption, pseudonymisation, contractual overrides) are needed to achieve essential equivalence.
- **Implement SCCs and update them**: Use the European Commission's 2021 Standard Contractual Clauses and ensure they are correctly incorporated into processor and sub-processor agreements; verify that importers can honour them in practice.
- **Fulfil transparency duties**: Update privacy notices under Articles 13(1)(f) and 14(1)(f) to identify third-country recipients, the transfer mechanism, and how to obtain copies of safeguards.
- **Reserve Article 49 derogations for exceptional cases**: Explicit consent under Article 49 should be a last resort, not a routine basis. The EDPB treats explicit consent as appropriate only where "a high level of individual control over personal data is deemed appropriate"—a threshold that demands genuine, informed, and freely given consent.

## Legislation (full text of key provisions)

### Transfers on the basis of an adequacy decision

*Source: GDPR, gdpr-art-45-en, 2016-04-27 — https://overview.legal/posts/90855*

### Binding corporate rules

*Source: GDPR, gdpr-art-47-en, 2016-04-27 — https://overview.legal/posts/90900*

### International cooperation for the protection of personal data

*Source: GDPR, gdpr-art-50-en, 2016-04-27 — https://overview.legal/posts/90950*

In relation to third countries and international organisations, the Commission and supervisory authorities shall take appropriate steps to:

### Conformity assessment bodies of third countries

*Source: AI Act, aiact-art-39-en, 2024-06-12 — https://overview.legal/posts/92587*

Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.

### Relationship with previously concluded Agreements

*Source: GDPR, gdpr-art-96-en, 2016-04-27 — https://overview.legal/posts/91493*

International agreements involving the transfer of personal data to third countries or international organisations which were concluded by Member States prior to 24 May 2016, and which comply with Union law as applicable prior to that date, shall remain in force until amended, replaced or revoked.

### International cooperation

*Source: NIS2, nis2-art-17-en, 2022-12-14 — https://overview.legal/posts/96119*

The Union may, where appropriate, conclude international agreements, in accordance with Article 218 TFEU, with third countries or international organisations, allowing and organising their participation in particular activities of the Cooperation Group, the CSIRTs network and EU-CyCLONe. Such agreements shall comply with Union data protection law.

### Recital 110 — binding corporate rules for group transfers

*Source: GDPR, gdpr-rec-110-en, 2016-04-27 — https://overview.legal/posts/91735*

A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate rules for its international transfers from the Union to organisations within the same group of undertakings, or group of enterprises engaged in a joint economic activity, provided that such corporate rules include all essential principles and enforceable rights to ensure appropriate safeguards for transfers or categories of transfers of personal data.

### Recital 73 — international cooperation agreements with third countries

*Source: NIS2, nis2-rec-73-en, 2022-12-14 — https://overview.legal/posts/96674*

The Union can, where appropriate, conclude international agreements, in accordance with Article 218 TFEU, with third countries or international organisations, allowing and organising their participation in particular activities of the Cooperation Group, the CSIRTs network and EU-CyCLONe. Such agreements should ensure the Union’s interests and the adequate protection of data. This should not preclude the right of Member States to cooperate with third countries on management of vulnerabilities and cybersecurity risk management, facilitating reporting and general information sharing in accordance with Union law.

### Recital 101 — personal data transfers to third countries

*Source: GDPR, gdpr-rec-101-en, 2016-04-27 — https://overview.legal/posts/91717*

Flows of personal data to and from countries outside the Union and international organisations are necessary for the expansion of international trade and international cooperation. The increase in such flows has raised new challenges and concerns with regard to the protection of personal data. However, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. In any event, transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.

### Recital 114 — Data transfer safeguards absent adequacy decision

*Source: GDPR, gdpr-rec-114-en, 2016-04-27 — https://overview.legal/posts/91743*

In any case, where the Commission has taken no decision on the adequate level of data protection in a third country, the controller or processor should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union once those data have been transferred so that that they will continue to benefit from fundamental rights and safeguards.

## Case law

### CJEU - C-311/18 - Facebook Ireland and Schrems

*Source: GDPRhub, 2026-07-17 — https://overview.legal/posts/125639 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-311/18_-_Facebook_Ireland_and_Schrems*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid. In its judgment on October 6th 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC. In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Article 7 CFR, Article 8 CFR, and Article 47 CFR. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU. In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Article 7 CFR and Article 8 CFR. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable. Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data. Dispute — The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes the relevant legislation for determining whether there has been a violation of individual rights how to assess the level of protection in a third country whether data transfers to the US violate the Charter whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy what level of protection is required to be afforded to personal data that is transferred under SCCs whether the SCCs can even be adequate as safeguards given they do not bind national authorities whether there is an obligation to suspend data flows if a data importer is subject to surveillance law what the relevance of the Privacy Shield decision is with regards to assessing safeguards whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects whether the SCCs violate the Charter Holding — The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes. In particular, the Court stressed that a transfer of data is not excluded from the scope of the GDPR for the reason that it may be processed by the national authorities of a third country. Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country. The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were not circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services. Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid. The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify prior to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23.

*Source: General Court, T-553/23, 2025-09-03 — https://overview.legal/posts/132137 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0553*

In Case T-553/23, French citizen Philippe Latombe sought annulment of the European Commission's Implementing Decision (EU) 2023/1795, which found that the United States ensures an adequate level of personal data protection under the EU-US Data Privacy Framework. Latombe challenged the adequacy decision on grounds including infringement of Articles 7 and 8 of the EU Charter, the right to an effective remedy, protections against solely automated decisions, and data security, arguing the framework failed to provide essentially equivalent protection to EU law. The General Court dismissed the action as unfounded, upholding the Commission's adequacy decision.

### Judgment of the General Court (Sixth Chamber, Extended Composition) of 8 January 2025.#Thomas Bindl v European Commission.#Processing of personal data – Protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies – Regulation (EU) 2018/1725 – Concept of ‘transfer of personal data to a third country’ – Transfer of data when visiting a website – EU Login – Action for annulment – Act not open to challenge – Inadmissibility – A

*Source: General Court, T-354/22, 2025-01-08 — https://overview.legal/posts/132155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022TJ0354*

In Case T-354/22, Thomas Bindl sought annulment of alleged personal data transfers to third countries by the European Commission when visiting the Conference on the Future of Europe website, a declaration of failure to act on his information request, and EUR 1,200 in damages for non-material harm under Regulation (EU) 2018/1725. The General Court found the annulment action inadmissible as the alleged transfers did not constitute a challengeable act, declared there was no need to adjudicate the failure-to-act claim since the Commission had subsequently responded, and dismissed the damages claim for lack of a sufficiently serious breach and causal link. No fine was imposed.

### Cour Administrative - 49701C

*Source: Administrative Court of the Grand-Duchy of Luxembourg, 2024-12-12 — https://overview.legal/posts/158440 — original: https://gdprhub.eu/index.php?title=Cour_Administrative_-_49701C*

Facts — On 19 May 2020, a Luxembourg bank informed the complainant that, by 30 June 2020, they would transmit the complainant's bank account information to the Luxembourg fiscal authorities. Afterwards, by latest the 30th September 2020, the Luxembourg fiscal authorities will share this information with the US fiscal authorities. The complainant, a French and American citizen connected to the association for the protection of civil rights ASBL, turned to the Luxembourg direct Tax Office (hereinafter: ACD), explaining that the data to be transferred on the basis of the FATCA concern identification, financial and economic data, i.e. personal data as defined in the GDPR. Thus, the complainant requested the ACD to erase the personal data and immediately discontinue the exchange of information between the ACD and the American fiscal authorities. The director of the ACD rejected this request, stating that the ASBL is not a data subject and the processing of the personal data of the complainant was necessary to respect the Luxembourg FATCA Agreement law to which the ACD is subject, Thus, in their view the request to restrict processing is not justified. The complainant turned to the Luxembourg Administrative Tribunal, which rejected the injunctive request to suspend the information sharing with the US fiscal authorities. The Tribunal also declared itself entitled neither to decide on the decision of the ACD, nor to invalidate it. As to the merit, the Tribunal found the request for invalidation unfounded, rejecting the request for a reimbursement and ordering the complainant to pay the costs. The ACD challenged the receivability of appeal. Holding — In relation to the GDPR-related questions, the court held the following. Whether the GDPR was applicable to the data transfer With regards to the applicability of the GDPR and the law of the 1st August 2018 about the organisation of the Commission Nationale pour la Protection des Données (CNPD, the Luxembourg data protection supervisory authority) and the implementation of Regulation (EU) 2016/679 replacing Directive 95/46 EC and the law of the 2nd August 2002 about the implementation of said directive. The subject of the case is neither direct prevention, detection and prosecution of criminal activities (when Directive (EU) 2016/680 would apply), nor is it within the area of the Common Foreign and Security Policy (which is exempt from the application of the GDPR), therefore the GDPR applies. In respect of the prevention, detection and prosecution of criminal activities, Directive (EU) 2016/680 would only apply if the data controller were a competent authority. These authorities are only authorities of law enforcement, and the tax office is not one of them. The processing in question in the case at hand concerns the exercise of the rights of Member States in the area of taxation, in particular the mutual cooperation in tax matters through the automatic exchange of information. Whether the FATCA Agreement was valid in the light of the GDPR In interpreting the GDPR related to the case, the court found furthermore, that Article 96 GDPR applies, i.e. as an existing international treaty, the FATCA Agreement is valid even if it contradicts the GDPR. As the FATCA Agreement was signed the 28th March 2014 and enacted by the law of the 24th July 2015, it was concluded before the GDPR entered into force and is thus covered by Article 96 of the GDPR. There is also no stipulation which would require – contrary to what the appellants state – to modify the FATCA Agreement in view of the GDPR. The primacy of international law over the national law, which is enshrined in Luxembourg law, in case when there is a conflict between rules of an international treaty and those in national law, even a posteriori (i.e. when the rules of national law are adopted after the entry in force of the international treaty), the international norm has precedence over the national norm. Thus, in case of a hypothetical contradiction with the law of the 2nd August 2002, the FATCA Agreement would prevail. Whether the transfer of personal data to the US should have been preceded by a Transfer Impact Assessment and whether the transfer to the US was lawful Concerning the further two questions proposed to be asked from the CJEU, the court was of the opinion that these were not necessary to decide the present case. Given that Article 96 GDPR applies, the legality the decision of the director of ACD of the 22nd March 2021, having refused to stop the transfer of the personal data provided by the Luxembourg financial institutions through the automatic exchange of information to the fiscal administration of the United States in the framework of the FATCA Agreement has thus to be examined exclusively in the light of the Directive 95/46 EC, as this directive remains in force (due to Article 96 GDPR) as the only legal reference to judge the lawfulness of the measure, as no withdrawal or modification of FATCA Agreement was necessary. Articles 25 and 26 of Directive 95/46 EC are the rules to be taken into account as specific rules as the automatic exchange of information according to FATCA Agreement is a transfer of personal data to third countries, and these rules are part of chapter IV of Directive 95/46 EC, entitled “transfer of personal data to third countries”. The appellants claim that in this respect, ACD should have investigated the adequate level of protection in the US. However, in Mémorial (the Luxembourg official journal), series A n° 156 of the 10th August 2015 (p. 3796) establishes that "the conditions of entry into force of the agreement about the exchange of notes indicated above (i.e. the exchange of notes regarding FATCA Agreement, signed the 31st March and 1st April 2015) being fulfilled the 29th July 2015, the said acts entered into force between the Contracting Parties the 28th July 2015, according to Article 10 of the Agreement. Thus, the State had sufficient elements of information to conclude that the exchanged data remain confidential, will be used for fiscal purposes and will be processed by infrastructures which ensure such confidentiality. Thus, the State did not find any elements to doubt in this regard at that point. Article 26 (1), point d Directive 95/46 authorises Member States to foresee or authorise transfers of personal data to a third country also when the legal system of this latter does not ensure an adequate level of protection, namely in the case when this transfer is necessary for the concerned Member State to preserve an important public interest. This stipulation has to be understood as giving Member States a certain freedom of manoeuvre concerning the content of the notion of important public interest which they consider justifying the transfer of personal data to third countries which do not guarantee an adequate level of protection, given that the interests which merit protection are not entirely the same in the different Member States. In general, the State rightly argues that the CJEU recognised the fight against aggressive tax planning and the prevention of risk of tax avoidance and tax fraud as objectives in the general interest recognised by the Union which can justify the restriction of rights guaranteed in the Charter of Fundamental Rights (judgment of the 8th December 2022, case C-694/20, Orde van Vlaamse Balies e.a. and of the 29th July 2024, case. C-623/22, Belgian Association of Tax Lawyers). The transfer of information serves this objective. The appellants contest nevertheless this analysis, referring to the Guidelines 2/2020 the EDPB according to which the derogations should be interpreted narrowly and concern mainly occasional and on-repetitive transfers but cannot justify transfers on a large scale, as foreseen in the FATCA Agreement. This restriction does not, however, stem from Article 26 (1), point d of Directive 95/46 EC, neither from the relevant Recitals of Directive 95/46 EC. Even if the EDPB has a certain role in the harmonised application of the Directive 95/46 EC and afterwards of the GDPR by all member States, its analysis in its guidelines is not binding. The appellants also claim that there should be a similar provision of information from the US fiscal authorities to the European authorities. Nevertheless, such a requirement of reciprocity is not required neither from Article 26 (1), point d), nor from the recitals of Directive 95/46 EC. Even when such a reciprocity corresponds a certain logic of cooperation, such a logic is in political domain but does not influence the interpretation of a rule of Union law. Based on the above considerations, the court considers that the execution of the FATCA Agreement and of the law of the 24th July 2015 by the ACD is lawful based on Article 26 (1) point d), of Directive 95/46 EC, even when the US does not guarantee and adequate protection of personal data pursuant to Article 25 (1), of Directive 95/46 EC. Therefore, the arguments of the appellants to the contrary have to be rejected. This analysis is also sufficient to support that there is no need to request a preliminary ruling from the CJEU. Therefore, the Administrative Court of Luxembourg rejected the appeal.

### Judgment of the Court (Grand Chamber) of 21 June 2022.#Ligue des droits humains ASBL v Conseil des ministres.#Request for a preliminary ruling from the Cour constitutionnelle.#Reference for a preliminary ruling – Processing of personal data – Passenger Name Record (PNR) data – Regulation (EU) 2016/679 – Article 2(2)(d) – Scope – Directive (EU) 2016/681 – Use of PNR data of air passengers of flights operated between the European Union and third countries – Power to include data of air passengers

*Source: Court of Justice of the European Union, C-817/19, 2022-06-21 — https://overview.legal/posts/132311 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0817*

In a preliminary ruling referred by the Belgian Constitutional Court in Ligue des droits humains v. Conseil des ministres (Case C-817/19), the CJEU Grand Chamber assessed the validity of the PNR Directive (EU) 2016/681 and its interplay with the GDPR and the API Directive in light of Articles 7, 8, and 52(1) of the EU Charter of Fundamental Rights. The Court upheld the PNR Directive's validity, finding that the collection, retention, and automated processing of passenger name record data for combating terrorist offences and serious crime constitutes a justified and proportionate limitation on fundamental rights to privacy and data protection, provided the directive's safeguards are strictly observed. No fine was imposed, as the ruling solely provides interpretive guidance on EU law validity and scope for the referring national court.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6121 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6121*

“although not requiring a third country to ensure a level of protection identical to that guaranteed in the EU legal order, the term ‘adequate level of protection’ must […] be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of the regulation, read in the light of the Charter.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

### CJEU - C-362/14 - Schrems I

*Source: GDPRhub, 2015-06-10 — https://overview.legal/posts/122860 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-362/14_-_Schrems_I*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. Some of Mr. Schrems personal data had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the US. Personal data transferred by undertakings such as Facebook Ireland to their parent company established in the US can be accessed by the NSA and other US security agencies in the course of a mass and indiscriminate surveillance. EU citizens have no effective rights to be heard on question of surveillance and interception of their data by the NSA and other US security agencies. The Commission had declared data transfers to the US legal under Article 25(6) of the Data Protection Directive 95/46 (Directive 95/46) when complying with safe-harbor regime by Decision 2000/520 (the Adequacy Decision), finding the US's protection of personal data adequate in Article 1 of the decision, if the recipients adhered to so called safe harbor privacy principles. These included derogations from data protection principles for US national interests. In Article 3 of the decision the Commission heightened the threshold for DPAs to take action within the scope of Article Article 25 of Directive 95/46. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers, claiming that the US did not have an adequate level of protection. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, asking in essence whether Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 CFR, must be interpreted to mean that an Adequacy Decision prevents a DPA from examining the claim of a data subject regarding transfer of personal data to that third country when it contends that the law and practices in force in the third country do not ensure an adequate level of protection. The Advocate General's Opinion — The AG opined, that the derogations provided for in the Adequacy Decision enabling access by US authorities to data transferred to US organisations within the safe harbor regime are too general and not limited to what strictly necessary to adequately protect data from EU based persons. Thus, the AG found the US intelligence services’ access to the transferred data interfering with fundamental rights. The AG considered, that EU citizens using Facebook are not informed that their personal data will be generally accessible to US security agencies and EU citizens have no effective right to be heard on the surveillance and interception of their data. While the AG found that there is an oversight of the US Foreign Intelligence Surveillance Court, the proceedings before it are secret and ex parte, which, in the AG’s opinion, is an interference with the rights of citizens to an effective remedy protected by Article 47 CFR. The AG found it “extremely doubtful” that the limitations at issue may be regarded as respecting the essence of Article 7 or 8 EUCFR as they do not define grounds for the derogations by sufficient precision. Thus, the AG opined that Decision 2000/520 must be declared invalid. The AG stated, that neither private dispute resolution mechanisms or the Federal Trade Commission can challenge access by the US intelligence services to personal data transferred from the EU and that there is no independent authority capable of verifying that the implementation of the derogations is limited to what strictly necessary. Therefore the AG found, that the Commission exceeds the limits imposed by compliance with the principle of proportionality in light of Articles 7, 8 and 52(1) EUCFR. The Adequacy Decision, according to the AG, must therefore be declared invalid since it does not ensure an adequate level of protection of the personal data transferred from the EU to the US under that scheme. The Courts Decision — The CJEU held that the Commission's Safe Harbour decision did not prevent the DPC from examining whether the transfer of user data to the USA by Facebook should be suspended. The court found that DPAs do not have powers on the basis of Article 28 Directive 95/46 regarding processing carried out in a third country. However, the court held, that having personal data transferred from a Member State to a third country constitutes, in itself, processing of personal data and thus found the DPAs vested with the power to check whether a data transfer to a third country complies with the requirements laid down by Directive 95/46. The court found that until a Commission's decision is declared invalid by the it, DPAs cannot adopt measures contrary to that decision as it is in principle presumed to be lawful until withdrawn, annulled or declared invalid. However the court found that Decision 2000/520 cannot prevent persons whose personal data has been or could be transferred to a third country from lodging with the DPA a claim concerning the protection of their rights and freedoms. If, the court reasoned, the DPA rejects it, the complainant must, in the light of Article 47 CFR, have access to judicial remedies. If however the DPA considers the complaint well founded, the court held, it must in accordance with Article 28(3) of Directive 95/46, read in the light in particular of Article 8(3) CFR, be able to engage in legal proceedings. Thus, according to the court, the national legislature must provide for legal remedies enabling the concerned DPA to put forward the objections before the national courts which may make a reference for a preliminary ruling. Thus the court held that Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 CFR, must be interpreted as meaning that an Adequacy Decision, does not prevent a DPA from examining the claim of a data subject that the law and practices in force in the third country do not ensure an adequate level of protection. Furthermore, the court found that Article 25(6) of Directive 95/46 required for the level of data protection offered a third country to be considered "adequate" it should be “essentially equivalent” to that of the EU as otherwise circumvention of Directive 95/46 would be too easy. The court held, that the Commission is obliged to assess whether a third country's domestic law or international commitments and its compliance practice afford an essentially equivalent protection and check periodically if this assessment is still correct. The court found that the Adequacy Decision in stating that ‘national security, public interest, or law enforcement requirements’ have primacy over the safe harbor principles enables interference with the fundamental rights of the persons whose personal data is or could be transferred to the US. Regarding the derogations and limitations within the Adequacy Decision the court stated - drawing on C‑293/12 and C‑594/12 - that they must apply only in so far as is strictly necessary, which is not the case where legislation generally authorises storage of all the personal data transferred from the EU to the US without any differentiation, limitation or exception. In particular, the court found that legislation permitting the public authorities' access on a generalised basis to the content of electronic communications compromises the essence of the fundamental right to respect for private life, as guaranteed by Article 7 CFR. Likewise, the court held, that legislation not providing for an individual to pursue legal remedies to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 CFR. Consequently, the court held that in including such derogations within its decision the Commission could not state that the US ‘ensures’ an adequate level of protection. Thus the court invalidated Article 1 of the Adequacy Decision, declaring the level of protection in the US adequate. Additionally, the court found, that Article 25(6) of Directive 95/46 does not empower the Commission to eliminate or restrict the powers of the DPAs, thus Article 3 of the Adequacy Decision in restricting the DPAs to act where a data subject calls into question whether an Adequacy Decision is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals was exceeding the Commissions powers. Therefore the court invalidated Article 3 of the decision. In conclusion, the court held, that as Article 1 and 3 of the decision are inseperably linked it invalidates the decision as a whole.

### Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per

*Source: Court of Justice of the European Union, C-288/12, 2014-04-08 — https://overview.legal/posts/132371 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0288*

The European Commission brought an infringement action against Hungary before the Court of Justice (Grand Chamber) under Article 258 TFEU, alleging that Hungary violated Article 28(1) of Directive 95/46/EC by adopting national legislation that prematurely terminated the term of its existing data protection supervisory authority and appointed a new head. The Court ruled that Hungary had failed to fulfil its obligations, holding that the independence of supervisory authorities under Article 28(1) requires that their term of office cannot be brought to an end without legitimate justification, and that a Member State may not reduce the originally established term of office through general legislation without respecting the conditions previously governing the termination of that term. No fine was imposed in this judgment.

## Guidance

### EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries

*Source: EDPB, edpb-edps-joint-opinion-22021-on-standard-contractual-clauses-for-the-en, 2021-01-14 — https://overview.legal/posts/126083 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22021-on-standard-contractual-clauses-for-the_en*

Adopted 1 EDPB - EDPS Joint Opinion 2 /2021 on the European Commission’s Implementing Decision on standard contractual clauses for the transfer of personal data to third countries for the matters referred to in Article 46(2)(c) of Regulation (EU) 2016/679 Adopted 2 Adopted 4 The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of 23 October 2018 on the protection of natural persons with regard to the processing…

### Guidelines 07/2022 on certification as a tool for transfers

*Source: EDPB, edpb-guidelines-on-certification-as-a-tool-for-transfers, 2023-02-24 — https://overview.legal/posts/38131 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072022-on-certification-as-a-tool-for-transfers_en*

The GDPR requires in its Article 46 that data exporters shall put in place appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by data exporters under Article 46 for framing transfers to third countries by introducing, amongst others, certification as a new transfer mechanism (Articles 42 (2) and 46 (2) (f) GDPR). These guidelines provide guidance as to the applicati...

### Information note on data transfers under the GDPR to the United Kingdom after the transition period

*Source: EDPB, information-note-on-data-transfers-under-the-gdpr-to-the-united-kingdom-en, 2020-12-15 — https://overview.legal/posts/126093 — original: https://www.edpb.europa.eu/documents/other-guidance/information-note-on-data-transfers-under-the-gdpr-to-the-united-kingdom_en*

Adopted 1 Information n ote on data transfers under the GDPR to the United Kingdom after the transition period Adopted on 15 December 2020 T he transition period for the United Kingdom’s withdrawal from the European Union will end on 31 December 2020 . This means that as of 1 January 2021, the UK will no longer apply the GDPR to the processing of personal data and a separate legal framework reg arding data protection will be in force in the UK . Consequently, as of 1 January 2021 , all…

### Information note on data transfers under the GDPR in the event of a no-deal Brexit

*Source: EDPB, information-note-on-data-transfers-under-the-gdpr-in-the-event-of-a-no-en, 2019-02-12 — https://overview.legal/posts/126244 — original: https://www.edpb.europa.eu/documents/other-guidance/information-note-on-data-transfers-under-the-gdpr-in-the-event-of-a-no_en*

Information n ote on data transfers under the GDPR in the event of a no - deal Brexit Adopted on 12 February 2019 Updated on 4 October 2019 Introduction In the absenc e of an agreement between the EEA and the UK ( n o - deal Brexit), the UK will become a third country from 00.00 am CET on 1st November 2019 . This means that the transfer of personal data to the UK has to be based on one of the following instruments 1 as of 1st November 2019 : - Standard or ad hoc Data Protection Clauses -…

### Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR

*Source: EDPB, guidelines-052021-on-the-interplay-between-the-application-of-article-3-and-the-en, 2023-02-24 — https://overview.legal/posts/125866 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052021-on-the-interplay-between-the-application-of-article-3-and-the_en*

Adopted 1 Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Version 2.0 Adopted on 14 February 2023 Adopted 2 Version history Version 2.0 14 02 2023 Adoption of the Guidelines after public consultation Version 1.0 18 11 2021 Adoption of the Guidelines for public consultation Adopted 3 EXECUTIVE SUMMARY The GDPR does not provide for a legal definition of the notion “transfer of personal data to a…

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

### Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data

*Source: EDPB, recommendations-012020-on-measures-that-supplement-transfer-tools-to-en, 2021-06-18 — https://overview.legal/posts/126015 — original: https://www.edpb.europa.eu/documents/recommendation/recommendations-012020-on-measures-that-supplement-transfer-tools-to_en*

Adopted 1 Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data Version 2.0 Adopted on 18 June 202 1 Adopted 2 Version history Version 2.0 18 June 2021 Adoption of the Recommen dations after public consultation Version 1.0 10 November 2020 Adoption of the Recommendations for public consulation Adopted 3 Executive summary The EU General Data Protection Regulation (GDPR) was adopted to serve a d ual - purpose:…

## Enforcement decisions

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

### Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)

*Source: Datatilsynet (Denmark), 2022-09-28 — https://overview.legal/posts/6313 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2020-431-0061_(Helsingor_decision_no._4)*

Facts — This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor municipality, the controller, has been using Google Chromebooks and Workspace for Education in violation of several GDPR requirements, as detailed in the first decision of September 2021, the second decision of 14 July 2022 and the third decision of 18 August 2022. Following the third decision, the municipality submitted more documentation and also requested a consultation with the DPA as per Article 36 GDPR. Holding — The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also ordered the municipality to: Change the data processing agreement with Google so that the DPA's remarks in their 14 July and 18 August decisions, are implemented. This includes, at a minimum, a clarification of where and if Google acts as a sole controller and any uncertainties that may entail that Google acts beyond their role as a processor, see Article 28(3)(a) GDPR. Document that all transfers of personal data to insecure third countries, are in line with the GDPR. Describe all data flows and identify the personal data that are shared with the vendor, and clarify when the vendor acts as a sole or joint controller. This documentation must include the whole technology stack used by the municipality (for this processing activity). Update their data protection impact assessment based on all identified risks. Consult the DPA if the DPIA shows any high risks the municipality is not able to mitigate. If any processing activities are still not in line with the GDPR before the DPA's deadline 3 November 2022, present a final plan for bringing them in line with the GDPR.

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

### CNPD (Portugal) - Deliberação 2019/494

*Source: CNPD (Portugal), 2019-09-03 — https://overview.legal/posts/122872 — original: https://gdprhub.eu/index.php?title=CNPD_(Portugal)_-_Deliberação_2019/494*

Facts — In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of the national legislator to a set of provisions that could potentially violate EU law, particularly the GDPR. The DPA emphasized the primacy of EU law as outlined in the EU treaties, particularly reflecting on Article 288 of the Treaty on the Functioning of the European Union (TFEU) and reinforced by the jurisprudence of the CJEU, which has consistently stated that national laws cannot obstruct the direct applicability of EU regulations and must comply with EU law to ensure uniform implementation across the Member States. However, Law 58/2019 came into force without incorporating all of the DPA's recommendations. The DPA explains that the decision to not apply some of its provisions aims to ensure legal certainty, reinforcing the importance of consistent GDPR application without being hindered by conflicting national rules. Holding — The DPA has decided to disapply the following provisions of Law 58/2019, in cases of personal data processing under its review due to their conflict with the GDPR: Article 2(1)(2): This article broadens the territorial scope of the GDPR to encompass all personal data processing within national territory and processing linked to national establishments outside the territory. The DPA believes this contradicts Article 3 and Article 56 of the GDPR, which outlines the applicable law in cross-border situations. Additionally, it undermines the one-stop-shop mechanism and fails to address instances where the GDPR applies, such as in Portuguese embassies, consulates, ships, and aircraft. Article 20(1): This article states that the right to be informed and the right of access cannot be exercised when a duty of secrecy is imposed on the data controller/processor. In the view of the DPA, this article lacks legal relevance in relation to the GDPR, as it merely repeats provisions already present in the GDPR, particularly concerning the possibility of restricting the data subject's right to information in cases where data collection is indirect and a legal duty of confidentiality exists. Regarding the possibility of restricting the right to information when collecting data directly from the data subject, this right can only be restricted under the provisions of Article 23 GDPR, and Law58/2019 does not meet the requirements therein, thus contradicting the norms of the GDPR and the Charter of Fundamental Rights. Article 23: This article allows public authorities to reuse personal data for any public interest without ensuring compliance with principles of purpose limitation and data minimization (Article 5 GDPR) and could lead to potential misuse of personal data and a violation of individuals’ rights, as it does not ensure that the reuse of data serves the original purpose for which it was collected nor respecting the requirements imposed in Article 23 GDPR. Article 28(3)(a): The employee's consent cannot be the legal basis if the processing results in a legal or economic advantage for the employee. The Portuguese DPA considers it to be a contraction of the doctrine established by European institutions, which accepts employee consent in situations where the act of giving or refusing consent does not, in itself, have negative consequences for the employee. The DPA therefore believes that this provision does not protect the dignity, fundamental rights, and legitimate interests of employees, and thus fails to meet the requirements set forth in Article 9 (2) (b) and Article 88 GDPR. Regime of Administrative Offenses – Articles 37, 38, and 39: The DPA notes that some of the violations outlined in the law contradict the exhaustive list provided in the GDPR (Article 83). The DPA also criticizes the distinction in sanctioning frameworks based on the size of companies and the collective or individual nature of the entities conducting data processing, as the impact on personal data does not depend on those characteristics but rather on the nature of the activity being carried out. Article 61(2) states that "if the expiration of consent is the reason for terminating a contract in which the data subject is a party, the processing of data is lawful until this occurs." The DPA notes that this provision is incongruent, conflating two types of legal basis: consent and contract execution. The contract in which the data subject is a party is sufficient to justify the processing of the data necessary for its execution. Regarding the reasons that led to publish this decision, the Portuguese DPA clarifies that it did so in order to ensure the transparency of its future decision-making processes and, in this regard, contribute to legal certainty and security. It also clarifies that the non-application, in future specific cases, of the legal provisions listed above results in the direct application of the GDPR provisions that were manifestly restricted, contradicted, or compromised in their useful effect.

### IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border

*Source: IMY (Sweden), 2026-07-03 — https://overview.legal/posts/57263 — original: https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_IMY-2024-2904*

Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of the personal data of travellers arriving from third countries (the data subjects). During border control, the controller scanned the data subjects’ passports, and some travellers were required to provide fingerprints. The data collected was then possibly checked against various border control systems, such as the Schengen Information System (SIS) and the Visa Information System (VIS). There were no signs, brochures, or other written information on the processing of personal data available directly in the arrival hall. The only information available could be found on the controller’s website. Holding — The DPA issued the controller a reprimand for the infringement of Article 13 GDPR. It held that the controller had not provided the data subjects sufficient information about the processing of personal data during border controls. According to the DPA, the data subjects had not been able to easily access information regarding, among other things, what personal data is collected, how it is processed, and what rights data subjects have. The DPA took into account that not all travellers arriving from third countries could be expected to know which national authority is responsible for border controls, let alone be able to find and understand the information on the controller’s website without any guidance in the arrivals hall. It concluded that the lack of easily accessible information on this matter constituted a significant shortcoming: the border control operations included the processing of sensitive data, including biometric data, of a large number of travellers on a daily basis. On the other hand, the investigation was limited to one arrivals hall. The controller had also obtained signs with tailored information regarding the processing of personal data during border control since the beginning of the investigation. Based on an overall assessment, the DPA held that the lack of information required by Article 13 in the arrivals hall constituted a minor GDPR violation.

### Boete LocateFamily.com. Het Woo-verzoek ging ook over algemene beleidsstukken over de omgang met dataverwerkers in derde landen. (afgewezen)

*Source: Enforcement, 2025-07-10 — https://overview.legal/posts/51002 — original: https://autoriteitpersoonsgegevens.nl/documenten/woo-besluit-boete-locatefamilycom*

Boete LocateFamily.com. Het Woo-verzoek ging ook over algemene beleidsstukken over de omgang met dataverwerkers in derde landen.

### Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden, 2023-06-30 — https://overview.legal/posts/48052 — original: https://www.enforcementtracker.com/ETid-1937*

The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses, as no adequacy decision had been issued by the EU Com

## Recent developments

### US Supreme Court just blew up EU-US Data Transfers

*Source: noyb - European Center for Digital Rights, 2026-06-29 — https://overview.legal/posts/53122 — original: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers*

Data Transfers On Monday, the US Supreme Court decided in Trump v. Slaughter that the US Federal Trade Commission (“FTC”) may not be independent anymore. Since 2000, the EU has relied on the “independent” FTC as the enforcer of EU-US deals on personal data. According to EU treaty law, such oversight must be independent. In the current EU-US deal, the European Commission relies on the independent FTC 259 (!) times. Max Schrems: “Given that there are no independent authorities in the US anymore, w

### TikTok, AliExpress, SHEIN & Co surrender Europeans’ data to authoritarian China

*Source: noyb - European Center for Digital Rights, 2025-01-16 — https://overview.legal/posts/53166 — original: https://noyb.eu/en/tiktok-aliexpress-shein-co-surrender-europeans-data-authoritarian-china*

Data Transfers Today, noyb has filed GDPR complaints against TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi for unlawful data transfers to China. While four of them openly admit to sending Europeans’ personal data to China, the other two say that they transfer data to undisclosed “third countries”. As none of the companies responded adequately to the complainants’ access requests, we have to assume that this includes China. But EU law is clear: data transfers outside the EU are only allowed

### Strengthening data protection worldwide: EDPB meets with the countries and organisation with an adequacy decision

*Source: European Data Protection Board, 2025-12-03 — https://overview.legal/posts/49123 — original: https://www.edpb.europa.eu/news/news/2025/strengthening-data-protection-worldwide-edpb-meets-countries-and-organisation_en*

Brussels, 3 December - As part of its December’s plenary meeting, the European Data Protection Board (EDPB) held yesterday an online meeting with Commissioners and representatives of Data Protection Authorities (DPAs) from the countries and the organisation with an EU adequacy decision. This meeting marked the second of its kind, following the first gathering in October 2024. An adequacy decision is a key-mechanism in EU data protection legislation which allows free flow of personal data from Eu

### Versterking van de gegevensbescherming wereldwijd: Het Europees Comité voor de Bescherming van Persoonsgegevens (EDPB) komt samen met de landen en organisaties die een adequaatheidsbesluit hebben.

*Source: EDPB, 2025-12-03 — https://overview.legal/posts/51712*

Brussel, 3 december - Tijdens de plenaire vergadering van december heeft het Europees Comité voor gegevensbescherming (EDPB) gisteren een online bijeenkomst gehouden met commissarissen en vertegenwoordigers van nationale autoriteiten voor gegevensbescherming (DPAs) uit de landen en de organisatie die een besluit hebben over voldoende bescherming binnen de EU. Deze bijeenkomst was de tweede van dit soort, na de eerste bijeenkomst in oktober 2024. Een besluit over voldoende bescherming is een belangrijk instrument in de EU-wetgeving inzake gegevensbescherming, dat de vrije uitwisseling van persoonsgegevens mogelijk maakt vanuit de EU.

### Companies can't say how they comply with CJEU ruling

*Source: noyb - European Center for Digital Rights, 2020-09-25 — https://overview.legal/posts/53344 — original: https://noyb.eu/en/companies-cant-say-how-they-comply-cjeu-ruling*

Data Transfers Opening Pandora’s Box: Companies can't say how they comply with CJEU ruling Following the Court’s judgment in Case-C-311/18 (“Schrems II”) on the Privacy Shield and Standard Contractual Clauses, the noyb team and some of our members reached out to 33 companies and services that they use on a personal basis to ask them how they were approaching international data transfers. The responses that we received ranged across the spectrum: from good, to bad, to shocking. We’ve now compiled

## Literature

### International personal data transfer: An analysis of Brazil’s legal system and new LGPD under the adequacy standard of the EU GDPR

*Source: Journal of Data Protection Privacy, 2021-06-01 — https://overview.legal/posts/132549 — original: https://doi.org/10.69554/msqx9692*

The international transfer of personal data is an issue of fundamental importance in data protection. The General Data Protection Regulation (GDPR) has conditioned all data flow to third countries to stringent alternative requirements, the most important of which being the existence of an adequacy decision made by the European Commission finding the level of data protection afforded by that third country to be equivalent to the one provided by the GDPR. This study aims to apply the adequacy stan

### European Union ∙ EDPB Opinion 14/2019 on Standard Contractual Clauses for Processors under Article 28(8) GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132531 — original: https://doi.org/10.21552/edpl/2019/4/10*

### The transfer of personal data to third countries under the GDPR: when does a recipient country provide an adequate level of protection?

*Source: International Data Privacy Law, 2018-07-02 — https://overview.legal/posts/132550 — original: https://doi.org/10.1093/idpl/ipy008*

### Territorial Scope and Data Transfer Rules in the GDPR: Realising the EU’s Ambition of Borderless Data Protection

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132547 — original: https://doi.org/10.2139/ssrn.3827850*

### Data Protection Regulation and International Arbitration: Can There Be Harmonious Coexistence (with the GDPR Requirements Concerning Cross-Border Data Transfer)?

*Source: Legal Issues in the Digital Age, 2021-07-27 — https://overview.legal/posts/132548 — original: https://doi.org/10.17323/2713-2749.2021.2.21.48*

Recent global trends are producing powerful growth in the digital environment, and its spread is prompting adoption of strict and comprehensive regulation to ensure data protection. This results in a number of difficulties, one of which is lack of consistency between data protection regulation and the regulatory regimes applicable to specific industries and institutions. That inconsistency is particularly evident in the field of international arbitration — one of the most widely used and conveni

## Tools

### European Commission adequacy decisions

*Source: European Commission, 2026-07-17 — https://overview.legal/posts/125629 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en*

The authoritative list of third countries the European Commission has recognised as providing adequate protection under Article 45 GDPR (and its LED equivalent), with links to each adequacy decision and its review status — the first stop for any transfer analysis.

### Standard Contractual Clauses (SCCs) for international transfers

*Source: European Commission, 2026-07-04 — https://overview.legal/posts/53805 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en*

The European Commission's modernised standard contractual clauses (2021) for transfers of personal data to third countries under Article 46(2)(c) GDPR, plus the controller-processor SCCs under Article 28(7). Includes the official Word/PDF templates for all four transfer modules.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processors** — https://overview.legal/topics/processors
  Entities that process data on behalf of controllers

---
Generated by overview.legal · https://overview.legal/topics/internationale-doorgifte · 2026-08-22
